upvote
There are actual methods to do this though just not sure anyone does it yet.

1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods.

Another way is to open source it and repeat 2/3/4

The way around that requires either a backdoor in attested hardware which would be wild if discovered because it's the same tech protecting companies and governments most sensitive info so they're all incentivised to audit that.

reply
I seem to recall that Apple provided an audit
reply
How would that work for closed source apps like iMessage and WhatsApp?
reply
"3rd party audit"
reply