{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Full Time Nix","title":"Trust in Nix with Martin Schwaighofer","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/1b29c1cf\"></iframe>","width":"100%","height":180,"duration":5593,"description":"https://fulltimenix.com/episodes/martin-schwaighofer-steering-committee-candidate\nhttps://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf\nhttps://github.com/NixOS/nixpkgs\nhttps://oxide.computer/\nhttps://github.com/nix-community/lanzaboote\nhttps://en.wikipedia.org/wiki/UEFI#Secure_Boot\nNixCon2024 rebuilding builders instead of trusting trust\nhttps://youtu.be/UlJUpUQc9Lc?si=_EebfQszx062M2mR\nExtending cloud build systems to eliminate transitive trust:\nhttps://discourse.nixos.org/t/extending-cloud-build-systems-to-eliminate-transitive-trust/50841\nhttps://scored.dev/\nhttps://reproducible-builds.org/\nBuild systems à la carte: Theory and practice\nhttps://www.cambridge.org/core/journals/journal-of-functional-programming/article/build-systems-a-la-carte-theory-and-practice/097CE52C750E69BD16B78C318754C7A4?utm_campaign=shareaholic&utm_medium=copy_link&utm_source=bookmark\nImplementing a content-addressed Nix, 2 December 2021 — by Théophane Hufschmitt\nhttps://www.tweag.io/blog/2021-12-02-nix-cas-4/\nhttps://github.com/nix-community/trustix\nhttps://nixos.org/research/\n00:00 Introduction and Background\n01:28 Martin's Journey in Computer Science\n02:57 Compiler Construction Course Insights\n04:20 The Concept of Self-Compiling Compilers\n07:10 Hiding stuff in the compiler\n08:47 Trusting Trust: Compiler Security Issues\n09:58 Nix and Build Process Management\n12:09 Bootstrapping and Auditing in Nixpkgs\n13:21 Trust in Software and Hardware Security\n18:01 Secure Boot and Its Implications\n20:39 Scenario: Government Agency Targeting\n22:15 More on boot security\n28:09 The Role of Secure Boot and Measured Boot\n29:52 Measured boot\n35:13 Democratizing Trust with Remote Attestation\n36:11 Raising the bar on security\n39:31 Research Directions in Supply Chain Security\n47:34 Enhancing Nix for Security and Efficiency\n50:20 Understanding Reproducibility in Build Processes\n53:13 Navigating Trust and Threat Models in Nix\n53:22 Identifying Gaps in Nix's Trust Mechanisms...","thumbnail_url":"https://img.transistorcdn.com/7NFFun166T66lu_dSbdoELdq995G1yBDX3YdgBqa9Ik/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81NDUw/YzMwNjE0NjA4NGIx/NzMyZWIwYTVlYzU2/YjFhNi5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}