Bootstrappable builds
Bootstrappable builds
Posted Jan 7, 2021 0:53 UTC (Thu) by dvdeug (subscriber, #10998)Parent article: Bootstrappable builds
In 2008, there was a problem with Debian SSH keys due to an actual patch to OpenSSH in Debian. This was accidental and a patch to OpenSSH. It would have been harder but possible to do it intentionally and via a patch to GCC, so it would recognized OpenSSH and miscompile it as needed. It could be all written out in code, and nobody would be the wiser unless they knew what they were doing GCC-wise and were poking at that section of code.
It's not a bad concern, but it seems at this point to be more about something fun and interesting instead of something that provides any more trust in practice.
