[HN Gopher] Ken Thompson on the bug that exposed his compiler tr...
___________________________________________________________________
Ken Thompson on the bug that exposed his compiler trojan (2021)
Author : throwawaylinux
Score : 96 points
Date : 2023-06-19 11:08 UTC (11 hours ago)
(HTM) web link (www.tuhs.org)
(TXT) w3m dump (www.tuhs.org)
| mike_hock wrote:
| Lesson learned: It can't show up in the symbol table.
| clueless wrote:
| previously: https://news.ycombinator.com/item?id=33008519
| codetrotter wrote:
| That is so neat! I never did read the paper itself on trusting
| trust or whatever it was called, so I always thought this was
| mainly a theoretical kind of thing. Didn't know that the man
| actually made a real-life proof-of-concept for that exploit!
| bigdict wrote:
| So to clarify, they recompiled the compromised compiler using the
| compromised compiler and it kept growing in size with each
| iteration?
|
| (See Reflections on Trusting Trust if you are completely confused
| what this is about.)
| saagarjha wrote:
| > the extra byte was my bug.
|
| Well, the one that broke it at least. Attacks of this nature are
| inherently brittle.
___________________________________________________________________
(page generated 2023-06-19 23:00 UTC)