Ask HN: Is trusted client compute possible?
I'm wondering if I can have a client build some artifact and upload the artifact to a cache server that redistributes it. Of course the problem is that a malicious client could upload something evil, so I would need some way of proving that the client built the thing it was supposed to. Is it possible to trust client computation?
4 comments
[ 0.29 ms ] story [ 21.6 ms ] threadApple also has something for iOS called "App Attestation", where you could publish an app to do the building, and then if your server receives an upload from a successfully-signed app instance, you would know that the app code itself was not modified: https://developer.apple.com/documentation/devicecheck/establ...
This is all assuming you can't just do the build yourself to verify what they did. (If you could, why would you need them to upload it?)
https://github.com/BOINC/boinc/wiki/JobReplication
https://boinc.n-helix.com/trac/wiki/ValidationSummary
--------
Unrelated, there is also https://en.wikipedia.org/wiki/Homomorphic_encryption