4 ms·
"Reflections on Trusting Trust" by Ken Thompson is one of my favorites. Most papers by Jon Bentley (e.g. A Sample of Brilliance) are also great reads. I'm a f
by joaobatalha 9y ago
"Reflections on Trusting Trust" by Ken Thompson is one of my favorites.
Most papers by Jon Bentley (e.g. A Sample of Brilliance) are also great reads.
I'm a frequent contributor to Fermat's Library, which posts an annotated paper (CS, Math and Physics mainly) every week. If you are looking for interesting papers to read, I would strongly recommend checking it out - http://fermatslibrary.com/ http://fermatslibrary.com/
- Reflections on Trusting Trust (Annotated Version) - http://fermatslibrary.com/s/reflections-on-trusting-trust http://fermatslibrary.com/s/reflections-on-trusting-trust
- A Sample of Brilliance (Annotated Version) - http://fermatslibrary.com/s/a-sample-of-brilliance http://fermatslibrary.com/s/a-sample-of-brilliance
- tequila_shot 9y agohttp://fermatslibrary.com/ http://fermatslibrary.com/ isn't opening. Help?
- joaobatalha 9y agoNot sure what happened, it was down, but it seems to be back up now. team@fermatslibrary.com is usually pretty responsive
- djhworld 9y agoThis is a really nice site, but the owner should really enable HTTPS if they want people to give their email address over for the newsletter
- skypather 9y agosecond!
- manigandham 9y agoWhy? Emails are not private information.
- wrinkl3 9y agoThe Ken Thompson Hack is a haunting idea. The intelligence agencies almost certainly would've tried to implement it at some point.
- exelius 9y agoThey have -- this is basically what Stuxnet did. Some of the equation group leaks were even further advanced -- they installed themselves in the hard drive firmware, then hid the sectors where the exploit code was stored even from the BIOS. So point is, it's been done. That's why the Equation Group malware operated undetected for almost a decade (and maybe longer than that). Never underestimate the power of a government -- they can afford to hire and train an army of Ken Thompsons for the price of an aircraft carrier.
- exikyut 9y ago> they installed themselves in the hard drive firmware, then hid the sectors where the exploit code was stored even from the BIOS. Where can I read more technical details (such as code analysis) about this? I've never heard of anything like this hiding for 10 years before.
- devopsproject 9y agohttps://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf https://www.symantec.com/content/en/us/enterprise/media/secu...
- exikyut 9y agoOkay, that was interesting reading. Now I actually know what Stuxnet did and how it worked. The un-named nls_933w.dll responsible for modifying firmware on "over a dozen" HDDs is only termed as Stuxnet-like however: https://securelist.com/equation-the-death-star-of-malware-galaxy/68750/ https://securelist.com/equation-the-death-star-of-malware-ga... That's remarkably impressive though. HDDs aren't impenetrable walls - http://spritesmods.com/?art=hddhack http://spritesmods.com/?art=hddhack - but reflashing firmware on over a dozen disks, presumably from Windows... nice.
- khaledh 9y agoKen Thompson's "Reflections on Trusting Trust" reminds me of this answer to "What is a coder's worst nightmare?": https://www.quora.com/What-is-a-coders-worst-nightmare/answer/Mick-Stute https://www.quora.com/What-is-a-coders-worst-nightmare/answe...
- decentralised 9y agoJoao, espero que nao leves a mal mas a tua versão anotada do Ethereum white paper não fez muito sentido... e um trabalho ainda em curso?