Very cool
Very cool
Posted Aug 1, 2024 19:26 UTC (Thu) by Phantom_Hoover (guest, #167627)In reply to: Very cool by paulj
Parent article: Pulling Linux up by its bootstraps
Posted Aug 2, 2024 8:43 UTC (Fri)
by chris_se (subscriber, #99706)
[Link]
I think Thompson's argument is correct in a philosophical sense, but not in a practical sense. I agree with you in that I don't believe that such a super-backdoor doesn't exist.
But other supply chain attacks are real (as we've seen with e.g. the XZ backdoor). And I applaud any work that tries to make it harder and harder for such an attack to occur undetected. Methods that can detect vastly more sophisticated (and possibly unrealistic) attacks will also help detect the more realistic ones.
I also think that most developers aren't thinking enough about supply chain attacks in the modern world. So I'm very excited about projects that push these types of ideas more into the current zeitgeist.
Posted Aug 6, 2024 3:02 UTC (Tue)
by NYKevin (subscriber, #129325)
[Link] (1 responses)
Posted Aug 6, 2024 8:54 UTC (Tue)
by chris_se (subscriber, #99706)
[Link]
Regardless of whether Thompson himself meant it like that or not, I really like your summary. It's catchy enough that one could make a t-shirt out of it. :-)
Very cool
Very cool
Very cool