[Security] Malware attacking compilers

Jonathan Moore moore at eds.org
Tue Aug 25 19:45:08 UTC 2009


On Tue, Aug 25, 2009 at 12:33 PM, aestetix aestetix<aestetix at gmail.com> wrote:
>
> This is a very interesting concept, kind of a "ghost in the ghost in the
> machine" attack. It's not new by any measures, but it's still fun. I seem to
> remember seeing this idea both in Godel Escher Bach, as well as the Gold Bug
> Variations.

Here is the origin of the idea, "Reflections on Trusting Trust":

   http:/www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf

and here is a defince:

 http://www.dwheeler.com/trusting-trust/acsac-countering-trusting-trust-20050922-alt.pdf

-Jonathan



More information about the Security mailing list