stop playing telephone and start distributing trust with laut

It's easier to trust things more, when you have to trust them less.

At NixCon in 2024, in rebuilding builders instead of trusting trust, I talked about gaps in the Nix signature format that makes us trust the people and systems that feed our caches more than we should have to. Build results can travel from point to point, "trusted" along the way but not attributed, like in a game of telephone.

This year I present laut, my project for tackling those limitations, which is ready for its first users now. It ships as a secondary binary alongside Nix and is more pedantic about where things come from. Claims are designed to be more precise and signed by whoever made them, so laut can aggregate from original sources, like a journalist. This lets you pick who you trust independently from everyone else and change your mind about it over time, with even more paranoid features still on the horizon.

Martin Schwaighofer

Martin Schwaighofer works at the intersection between Nix and supply chain security, trying to prove the link between source code and output artifacts.