Surprisingly, it took until last year for someone to actually ask Ken for the code: https://research.swtch.com/nih
It's such a well-written article.
Here's previous HN discussion about it:
11–20 of 46 posts
Surprisingly, it took until last year for someone to actually ask Ken for the code: https://research.swtch.com/nih
It's such a well-written article.
Here's previous HN discussion about it:
There is something nightmarish about this kind of exploit, and that is maybe why we've been collectively in denial for such a long time. How many supply-chain generated backdoors in the wild today?
Supply-chain backdoors are one thing, but the saving grace about the backdoors injected by trusting-trust attacks like in the OP is that they're quite fragile. If the shape of the expected target program changes sufficiently, then the backdoor will fail to propagate. And propagating the backdoor into programs that have yet to be written requires an effectively omnisicient adversary. As long as you have multiple imple…
Clicked on the first Bell Labs link hoping to read the original and ended up on some VPN service's landing page. Sigh. :(
There is something nightmarish about this kind of exploit, and that is maybe why we've been collectively in denial for such a long time. How many supply-chain generated backdoors in the wild today?
There is something nightmarish about this kind of exploit, and that is maybe why we've been collectively in denial for such a long time. How many supply-chain generated backdoors in the wild today?
I mean, this class of attack is defeated as a matter of course in high reliability applications like aerospace. You just check the compiler output precisely corresponds to the compiler input. You need to do that anyways to prevent miscompilation errors in general (this class of attack is just intentional miscompilation), so it hardly counts as a nightmarish problem, just a annoying one.
There is something nightmarish about this kind of exploit, and that is maybe why we've been collectively in denial for such a long time. How many supply-chain generated backdoors in the wild today?
I mean, this class of attack is defeated as a matter of course in high reliability applications like aerospace. You just check the compiler output precisely corresponds to the compiler input. You need to do that anyways to prevent miscompilation errors in general (this class of attack is just intentional miscompilation), so it hardly counts as a nightmarish problem, just a annoying one.
just is doing a lot of work there.
>"This site uses features not available in older browsers."
>Enable Javascript.
Black plaintext on white background with hyperlinks. Revolutionary.
>"infinite spinner" >"This site uses features not available in older browsers." >Enable Javascript. Black plaintext on white background with hyperlinks. Revolutionary.