Mastodon Feed: Post

Mastodon Feed

Boosted by andrewnez ("Andrew Nesbitt"):
zekjur@mas.to ("Michael Stapelberg 🐧🐹😺") wrote:

Paper: “Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation”

"""
Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not. We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files. […] On a real nixpkgs revision, the attack builds a complete graphical installer without failures and backdoors almost every one of its binaries, enabling arbitrary malicious behavior of the subverted packages.
"""

https://arxiv.org/abs/2607.24888