3 ms·
Yes, worrying. http://www.linuxjournal.com/content/allegations-openbsd-backdoors-may-be-true http://www.linuxjournal.com/content/allegations-openbsd-back... N
by inthewind 13y ago
Yes, worrying.
http://www.linuxjournal.com/content/allegations-openbsd-backdoors-may-be-true http://www.linuxjournal.com/content/allegations-openbsd-back...
Not sure what was confirmed on that story, but I remember reading it and thinking there wasn't much chance that I'd ever be able to audit my own system.
- jodrellblank 13y agoThere's no chance at all that you completely could. http://cm.bell-labs.com/who/ken/trust.html http://cm.bell-labs.com/who/ken/trust.html Ken Thompson, 1984, explains how to get a system with perfectly clean source code to compile a hacked 'login' binary every time. "In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect."