← Back to events
ActiveTech

Trusting-Trust Attack against an Entire Linux Distribution (via the strip utility)

What happened

Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not. We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished…

Summary assembled by rule from the sources below

Why it's spreading

Sources