4 ms·
Whats the right way to mitigate besides trusted models/sources?
by FloatArtifact 2y ago
Whats the right way to mitigate besides trusted models/sources?
- sshh12 2y agoIt's a good question that I don't have a good answer to. Some folks have compared this to On Trusting Trust: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref... -- at some point you just need to trust the data+provider
- Legend2440 2y agoIn general, it is impossible to tell what a computer program may do even if you can inspect the source code. That’s a generalization of the halting problem.
- kortilla 2y agoThat’s not correct. There is not a general solution to tell what any arbitrary program can do, but most code is boring stuff that is easy to reason about.
- chii 2y agoBut a malicious actor can hide stuff that would be missed on a general casual inspection. Most of the methods in https://www.ioccc.org/ https://www.ioccc.org/ would be missed via a casual code inspection, esp. if there weren't any initial suspicion that something is wrong about it.
- kortilla 2y agoYes, but again, that doesn’t apply to the vast majority of code. My point is that saying you can’t know what code does “in general” is not true. We wouldn’t have code reviews if that were the case.
- 5- 2y agohttp://www.underhanded-c.org/ http://www.underhanded-c.org/ is a c programming contest specifically dealing with programs that hide behaviour 'in plain sight'. the winners are very much worth a look.