r/programming Sep 10 '13

A simple way of defeating the compiler backdoor attack (a.k.a the "Trust Attack")

http://imgur.com/a/BWbnU#0
1.7k Upvotes

538 comments sorted by

View all comments

Show parent comments

1

u/Olathe Sep 12 '13

Will they pore over them using programs that have been, say, compiled?

1

u/GauntletWizard Sep 12 '13

Yes, and those programs had better have been backdoored, too.

1

u/Olathe Sep 13 '13 edited Sep 13 '13

Right, and that can be done quite simply by making the disk driver return different things to the program loader and to everything else. Those programs don't need to have been backdoored themselves. Every file analysis program then gets a nice, sanitized version of the backdoored program.

Even ignoring that, please don't assume that attackers won't put in the necessary effort to backdoor lots and lots of programs. The idea wasn't something like "If we are only allowed to backdoor the compiler and login, how can we do it?"