3 ms·
Definitely Ken Thompson's Turing Award lecture, Reflections on Trusting Trust. [0] [0]: https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson
by clusmore 6y ago
Definitely Ken Thompson's Turing Award lecture, Reflections on Trusting Trust. [0]
[0]: https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
- dllthomas 6y agoIn case you hadn't caught it, there's a very cool way to catch "trusting trust" style attacks called "diverse double compiling". The idea is that compilers from sufficiently disparate sources are very unlikely to have the same malware, and while different compilers aren't expected to produce the same output for the same source they are expected to produce functionally identical output for the same source. So if you compile a compiler (where you've vetted the source) with an array of compilers, you have something that, applied to (again) that same source should produce something bitwise identical - any deviations are an attack or a bug in at least one of your compilers, and can be investigated manually. https://dwheeler.com/trusting-trust/ https://dwheeler.com/trusting-trust/