Comment by tetha
2 hours ago
> It is precisely about showing that you can still propagate backdoored code if the compromised binary in your seed is NOT the compiler.
But that seems like quibbling about semantics. Thompson says that if a compromised binary generates a binary, you cannot trust the generated binary.
This does not even have to be gcc, it could be vim. Or strip. Or cat. Or dd.
Or an iop to write data to persistent storage if the firmware of your SSD is compromised.
No comments yet
Contribute on Hacker News ↗