Trusting-Trust Attack against an Entire Linux Distribution (via the strip utility)

https://arxiv.org/abs/2607.24888

"Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not." A few weeks ago I came across this https://www.teamten.com/lawrence/writings/coding-machines/ : it's clearly fictional (and furthermore is "pre-AI" in that it was written in 2009) but is interesting in that it raises the question of whether one or more computers could- without "intention" embed code meeting the "trusting trust" criteria in GCC. Comments

7 points · 1 comments · view on lemmy.world

1 Comments

frankenswine@lemmy.world · 1 pts · 5d

that's why we bootstrap the pajeezuz out of our code over at GNU Guix