“Reflections on Trusting Trust” annotated
fermatslibrary.com
fermatslibrary.com
I'm not saying that the security field had a 'Hilbert's Program' before then, but it certainly couldn't have one afterward.
Perhaps we only lack the tools to implement his solution.
https://hn.algolia.com/?query=The%20Ken%20Thompson%20Hack&so...
https://hn.algolia.com/?query=reflections%20on%20trusting%20...
Also, it looks like it's been close to a year since a post of the paper was seen by anyone. There's nothing wrong with a repost after that long.
Regardless, I'm left feeling yet again that I can't fully trust anything. Good thing I don't need to these days; I fear for those who do.
Oh but you do, you trust countless of people doing their jobs right so that you can have electricity, clean water, safe food and peaceful streets. Civilization exists because of trust.
And one has to realize that trustless systems come with a cost - they have stupendous overhead. Consider all the layers of bureaucracy companies (or the law) employ to protect themselves from malicious actors. Or, consider Bitcoin. It's good to have, and maintain, trust-based systems because they can get the job done much, much more efficiently.
As for backdoored code is reality right now. IIRC intel compiler used to optimize code better for their own processors so it would score better benchmarks compared to AMD which is trojan IMO. Not to start talking about NSA conspiracy theories.