Gothenburg 2026 - Day 2 - Social aspects of Reproducible Builds

social

Android world: Users trust the developer more. Open source world: trust in developers is even greater because of the anti-large-corp sentiment.

Is this package really from the developer?

Have a builder available to verify it, hosted by other people? Analogy with Tor nodes hosted by universities, community, …

Old apps are signed by the developer, Google signs it on top before 2021. F-droid started with signing (breaks reproduciblity).

Key management would be simplified if it can be shown that the built APK is directly from the source code. “Smentically equivalent”? Can be viewed as integrity being broken.

.jar -> compare the .zip inside the file. Building on different distro’s changes the .zip structure.


Rebuilding something from 30 years ago, there’s mechanisms to show the changes are minimal. Maintenance vs security?

What do people care about?

Security

Caching

Long term maintance

Why not do RB?

How to help

Accademia

Some submissions have different criteria:

  1. It exists
  2. It builds
  3. It runs
  4. It is reproducible

The incentive for submission of papers contrasts open source.

Case for “rebuilders”

Hosting a rebuilder as a 3rd-party