I would not consider this trustless. It is more like "trust GitHub".
Well, actually, not too much. Attestation code is open source itself. And you can download attested artifacts and verify them locally with a third party tool that you trust.
reply
might as well get the best security running yourself locally at that point
reply
You do you. For 99% of Bitcoin users hosting own Boltz frontend is unfeasible. And does not solve centralization problem.
reply
True. But we already trust GitHub to host all our Bitcoin code. And git to clone it unadulterated.
reply
Reproducible builds eliminate the need to trust GitHub.
reply
Sure they do, but to use such a frontend one needs to run his own server.
reply
Why not make it a desktop app?
reply
For all operating systems and mobile platforms, repeat the functionality of browsers? Too much hassle. If Boltz will do such a feat, we will fork it again to decentralize.
We make minimal adjustments to their Web App to be able to pull upstream changes and stay fully compatible with their backend. They both keep evolving, we don't want to stay behind like Diamond Hands fork.
reply