dannybuntu's avatar
dannybuntu
dannybuntu@walletscrutiny.com
npub1r709...sf7d
Open Source contributor to FOSS project walletscrutiny.com and nostr.info
dannybuntu's avatar
dannybuntu 10 months ago
Hearts race, restless dreamsβ€” softly, longing slips away, stillness fills the air.
dannybuntu's avatar
dannybuntu 10 months ago
Thinking out loud: 'list framework, language and other dependencies for apps" With the verifications we have produced, we now have access to data that can be utilized to compare apps. Some are reproducibile, others are not. what frameworks do reproducible apps use? Although not exhaustively the source of non-reproducibility - these provide vital clues. Yes, corellation isn't causation. But we have to start somewhere to help other app developers get their app reproducible.
dannybuntu's avatar
dannybuntu 11 months ago
βœ… We verified that @nunchuk_io io.nunchuk.android v1.68.0 is reproducible! Despite minor expected diffs in AndroidManifest.xml & resources.arsc (e.g. Crashlytics ID, Google Play metadata), no functional changes were found. #ReproducibleBuilds #FOSS #Android
dannybuntu's avatar
dannybuntu 11 months ago
βœ… Just verified that Phoenix Wallet (Mainnet) v2.6.0 is reproducible! Built from source and matched Play Store APK byte-for-byte. πŸ”’ No signed tag/commit, but the build checks out. Full verification:
dannybuntu's avatar
dannybuntu 11 months ago
πŸ” Verified: @nunchuk_io Desktop v1.9.46 is fully reproducible Built on Ubuntu 22.04 using their official Docker-based guide βœ… ZIP & AppImage SHA256 match official release πŸ›  Build: CMake + Qt + Docker πŸ“¦ Result: Byte-for-byte identical #ReproducibleBuilds #Bitcoin #OpenSource
dannybuntu's avatar
dannybuntu 11 months ago
πŸ” Just verified the Bitcoin Knots v28.1 (Linux x86_64) binary as reproducible! πŸ§ͺ Build matched byte-for-byte. πŸ” Signatures validated from Luke Dashjr & other Knots builders. πŸ“Ž Full details on WalletScrutiny: #Bitcoin #ReproducibleBuilds #FOSS
dannybuntu's avatar
dannybuntu 11 months ago
βœ… Reproducibility confirmed for it.airgap.vault v3.32.7 (68124) πŸ” APK hash: 5ae0a8...9c25 🧬 Matches source at commit 3ec5c79... πŸ› οΈ Built using test.sh & Docker πŸ“„ Verified report: #ReproducibleBuilds #Android #OpenSource #WalletSecurity
dannybuntu's avatar
dannybuntu 11 months ago
πŸ”Ž Check out this asset information I registered on WalletScrutiny: βœ… Reproducible Electrum Windows Standalone Executable (v4.5.8) Full verification and report available here: Independent reproducibility strengthens open-source security. πŸ” #ReproducibleBuilds #OpenSource #Electrum #WalletScrutiny
dannybuntu's avatar
dannybuntu 11 months ago
πŸš€ Successfully reproduced and verified Electrum 4.5.8 from source! πŸ”’ Full PGP verification passed β€” signatures from Thomas Voegtlin, Emzy, and SomberNight were βœ… ultimate trust βœ…. πŸ“œ SHA256 matched: dd8595a138132dee87cee76ce760a1d622fc2fd65d3b6ac7df7e53b7fb6ea7e8 πŸ”Ž See the full asset registered at WalletScrutiny: πŸ‘‰ #Bitcoin #OpenSource #ReproducibleBuilds #Electrum #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
πŸ” Verified: Keystone3 Pro Firmware v2.0.4 (Cypherpunk, Modern) is reproducible βœ… Unsigned binary matches local build byte-for-byte. Signed hash differs (as expected due to signature). πŸ“„ Asset registered on WalletScrutiny: #ReproducibleBuilds #FirmwareIntegrity #Bitcoin
dannybuntu's avatar
dannybuntu 1 year ago
πŸ” Verified! Keystone3 Pro Firmware v2.0.4 (Multi-Coin, Modern) is reproducible πŸ§ͺβœ… Our build perfectly matches the unsigned official binary. Signed binary differs (expected due to signature). Tested with: keystone3pro.sh 2.0.4 multicoin modern πŸ”— #ReproducibleBuilds #Bitcoin #FirmwareIntegrity #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
πŸ” Tried to build Nunchuk Desktop from source β€” but hit a wall. ❌ Missing submodule libnunchuk (404 GitLab link) breaks the build. πŸ§ͺ Tested on both local Ubuntu & remote Debian. πŸ” Not reproducible in current state. πŸ“¦ SHA-256: (build failed β€” no binary to hash) πŸ”— #Bitcoin #ReproducibleBuilds #WalletScrutiny
dannybuntu's avatar
dannybuntu 1 year ago
πŸ” Just verified a reproducible build of Nunchuk v1.67.0 (io.nunchuk.android)! βœ… The APK from my phone matches the one built from source (tag: android.1.67) πŸ” Signing excluded, but the code checks out byte-for-byte. πŸ“¦ SHA-256: 41a66972d53121db4c77fd54bd79202822074fea6db35059b3049bfb5571bb73 πŸ”—
dannybuntu's avatar
dannybuntu 1 year ago
πŸ§ͺ Verified the BitBanana v0.9.4 Android app is functionally reproducible! πŸ“¦ Official split APKs were compared to those built from source. 🧾 Only minor binary diffs in AndroidManifest.xml & resources.arsc. πŸ”—
dannybuntu's avatar
dannybuntu 1 year ago
πŸ” Just verified a reproducible build of Blockstream Green v4.1.8! βœ… The APK from my phone matches the one built from source. πŸ” Signing was missing, but the code checks out. πŸ“¦ SHA-256: e2b842...50f89 πŸ”—
↑