Post B9AAe5dWoP6Dbvg2s4 by jas@fosstodon.org
 (DIR) More posts by jas@fosstodon.org
 (DIR) Post #B96X5XW8gG0MG9sKki by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation by @zacchiro et al: https://arxiv.org/pdf/2607.24888
       
 (DIR) Post #B9AAe5dWoP6Dbvg2s4 by jas@fosstodon.org
       0 likes, 0 repeats
       
       @ariadne @zacchiro That is a great paper! To unlock wizard mode: achieve the same but don’t rely on a modified strip binary, but place the payload in obfuscated source code that everyone rebuilds. Trusting trust issue without binaries involved: only a source code audits can expose this, neither reproducible or bootstrappable builds would catch that.