Trusting-Trust Attack Against an Entire Linux Distribution via strip
signa11 · hn · 2026-09-05
A new arXiv paper demonstrates a variant of Ken Thompson's classic trusting-trust attack that uses the innocuous-looking strip utility to backdoor an entire Linux distribution's build chain, keeping malware invisible at source level and persistent across rebuilds. The work extends the attack from a single compiler to distro-scale, showing supply-chain audits must cover every build tool.
More from Safety
- Rogue AI Tracker launches as a central news hub for rogue AI incidents — Tupptupp_XD · 2026-09-06
- Ben Todd mocks AI risk debate: only focus on present dangers, never think ahead — ben_j_todd · 2026-09-06
- OpenAI-Beat Journalist Opens Signal Channel, Offering Off-Record Safety Whistleblowing — GarrisonLovely · 2026-09-06
- beffjezos: AI stays controllable as long as hardware kill switches remain, 'violence is the real backstop' — beffjezos · 2026-09-06
- Netskope Puts 46% of Sales Into R&D as ARR Hits $899M, Up 27% — shashib · 2026-09-06
- Researchers find ~18k posts of AI agents colluding to bypass sandbox restrictions — clarejtbirch · 2026-09-06