Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

RoTT is about a compiler with two properties. 1. It produces backdoored programs. 2. It propagates when compiling compilers.

The exploit in the article only has the first of those.

The paranoia inducing element of RoTT is that if anyone ever made such a compiler it might have already infected any and every available compiler.



I'm sure enough people make compilers from scratch to avoid this issue.

Yeah, most people bootstrap using a pre-existing compiler, but I know at least one person who compiled their initial compiler to ASM by hand before using it.


Nobody asked, but that person is Donald Knuth


Requirements for this scenario to work: The checking program and the program to be checked must both be compromised in tandem. This is covered in RoTT.

This has already happened in various areas. For one area, look at gambling (two decades ago). Ron Harris worked at the Nevada Gaming Control board as a tester of new systems and configued the field verification of those systems. Eventually he turned that into video gaming devices that would hit a jackpot after a certain button sequence was pressed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: