Its not new at all

Story: Fortify Identifies Vulnerabilities in Open Source SoftwareTotal Replies: 1
Author Content
q

Oct 11, 2007
6:01 AM EDT
You cant trust anything that is build with compromised compiler. Ken Thompson wrote about this some time ago.
dinotrac

Oct 11, 2007
6:26 AM EDT
Thompson's compiler case is the extreme, but, yes, this is a similar concept. If I understand what they are saying, and I may not, it is different in a fundamental way. That would be the creation of a trust relationship on tools you download and never verify. it's like the C compiler problem gone mad. In this toolkit-based object-oriented world, we may grab a number of different tools from a number of different providers and never think twice about it. In the old days, chances are we used the compiler we got from the vendor.

Posting in this forum is limited to members of the group: [ForumMods, SITEADMINS, MEMBERS.]

Becoming a member of LXer is easy and free. Join Us!