Have rebuilderd instances verify Tails reproducibility
Tails is reproducible. While everyone could check that, our process relies on having Trusted Reproducers.
Meanwhile, @jvoisin used rebuilderd to verify Tails. So now it's quite feasible to run it.
We might be interested in collaborating with third parties that audit this aspect. I think this has potential for;
- reducing our reliance on trusted "internal" people
- fundraising opportunities maybe?
- good for promoting? as in "Tails build are verified by X, Y and Z organizations, which have a very high reputation"
Usually the main blocker for running rebuilderd instances is high resource usage. But that's only true if you want to reproduce something as big as the Debian archive. Building Tails is comparatively quite lightweight.