Why this exists
A sufficiently capable quantum computer breaks Ed25519, RSA and ECDSA. On that day every classically-signed package becomes forgeable: an attacker can mint a fresh, perfectly valid signature over a package you did not want. Signatures made after that point prove nothing.
The defensive form of harvest now, decrypt later is sign now, verify later. A post-quantum signature is only worth anything if it already existed before the transition — which is why these attestations are being produced today, well ahead of any need for them.
A rebuilder is unusually well placed to be useful here. Its claim does not depend on any distributor's keys: “I rebuilt this from these inputs and got this output hash.” Attach a post-quantum signature to that claim and it survives the transition intact.
Latest results
Artifacts shown
—
Reproduced
—
Not reproduced
—
With attestation
—
| Artifact | Version | Arch | Built | Status | Attestation |
|---|---|---|---|---|---|
| Loading… | |||||
The public key
This is the key to archive. Verification after the transition is only meaningful against a key you already held — a key fetched afterwards over a classically-protected connection can be substituted along with everything else.
ML-DSA-65 post-quantum
DownloadLoading…
Ed25519 classical
DownloadLoading…
Kept for compatibility with existing tooling. It is the signature that stops meaning anything after the transition.
Verifying a package yourself
Now, while it still costs nothing
Archive the key and the attestations you care about.
curl -o rebuilderd.pqc.pub …
rebuildctl pkgs attestation --name anarchism > attestation.json
Later, after the transition
Verify offline. No network, no daemon, and no classical cryptography anywhere in the trust path.
rebuildctl verify-artifact anarchism_15.3-5_all.deb \
--attestation attestation.json \
--pqc-key rebuilderd.pqc.pub \
--require-pqc
A pass means the file you hold is bit-identical to what an independent rebuilder produced from the recorded inputs, and that binding rests on a signature a quantum adversary cannot forge. The distributor's own signature is never consulted.
What this does not prove
-
That the source is honest. The attestation binds inputs
to outputs. Confirming the source genuinely produces that binary means
rebuilding it yourself, which needs the
.buildinfo— check it against the signedmaterialshash, then build. - That this instance is trustworthy. One rebuilder agreeing with itself proves little. The value comes from several independent rebuilders reaching the same answer.
- That the key is ours. Nothing here establishes that — the key's authority comes entirely from you having obtained it early, through a channel you trusted at the time.