Researchers backdoor an entire Linux distro via a tampered GNU strip binary — trusting-trust beyond compilers
jedisct1 · x · 2026-09-08
An arXiv paper (2607.24888) extends Ken Thompson's trusting-trust attack beyond compilers: by manipulating only finished ELF files, the authors build a full attack around GNU strip. In NixOS's bootstrap, a single tampered strip binary seed implants a payload that propagates across generations of strip and survives into the final standard environment. On a real nixpkgs revision, the attack builds a complete graphical installer and backdoors nearly all of its binaries. The result challenges the assumption that trusting-trust is compiler-specific and is a major warning for reproducible builds and binary seed trust chains.
More from Research
- Open-source hub aggregates the best voice AI benchmarks for TTS, STT and more — alexcovo_eth · 2026-09-08
- Researcher fine-tunes fruit fly brain model to strike Y-M-C-A poses on cue — emax · 2026-09-08
- Task-aware quantization hits 99% of BF16 reasoning at 15% size, beating Unsloth by up to 19 points — devildip · 2026-09-08
- Vibecoder uses AI to 'castrate' a simulated fruit fly, sparking animal rights outrage — Polymarket · 2026-09-08
- ECCV 2026 tutorial tackles the evaluation bottleneck for visual foundation and world models — georgiagkioxari · 2026-09-08
- Distilled SKILL.md beats Workflow Memory by 6.06 points — skills stabilize execution, not knowledge — rohanpaul_ai · 2026-09-08