Reflections on Trusting Trust (1984) [pdf]
cs.cmu.edu
cs.cmu.edu
These seem to be the threads and they're mostly small:
2017 https://news.ycombinator.com/item?id=13569275
2015 https://news.ycombinator.com/item?id=10698537
2015 https://news.ycombinator.com/item?id=9183106
2014 https://news.ycombinator.com/item?id=8662876
2011 https://news.ycombinator.com/item?id=2642486
2008 https://news.ycombinator.com/item?id=300350
Like a lot of classics, it seems to have actually been discussed less on HN than we would all assume.
https://www.gnu.org/software/mes/
Practical implementation notes can be found on the Guix blog:
https://guix.gnu.org/blog/2019/guix-reduces-bootstrap-seed-b...
https://guix.gnu.org/blog/2020/guix-further-reduces-bootstra...
It is difficult to protect against state actors.
But a lot of attackers are not state actors. They are private actors (whether lone individuals or groups) going after the low-hanging fruit. Protecting against this threat is a lot easier.
And for a lot of enterprises, the second category is a bigger threat than the first. Even if the NSA steals all your data, they are unlikely to release it to the general public or use it for extortion. The later group are much more likely to do things like that. If the NSA hacks you, you quite possibly will never know they've done it. If the later group hacks you, they'll make sure you know they've done it by the pain they'll cause.
(Of course, I realise how for companies in certain sensitive industries, such as defence, aerospace, semiconductor fabrication, etc, the threat of state-sponsored cyber-espionage from competing international powers is a real threat – however, I think in those cases one's own country's three-letter agencies are often keen to be helpful.)
I don't have a solution to the halting problem, but I can definitely tell you that `while(false) {}` terminates.
Similarly, I can't resolve the problem of trusting the people who write the libraries I use, but I identify a trusted computing base and substantially reduce or even sometimes eliminate the risk of attacks that don't violate the integrity of the TCB.
> This paper convinced me that pragmatically all computer security reduces to theater.
I have yet to be bitten by a smashed stack using any language other than C/C++.
I have yet to be bitten by a SQL injection using any interface to a DB other than passing raw strings around.
As Ken notes, I still have to trust the developers of those libraries/languages (or audit the code myself). But that's okay. Nailing down a chain of trust is possible.
Ruling out certain classes of security vulnerabilities is possible.
> One of my ex-NSA buddies told me that they don't even bother attacking crypto algorithms, they just attack the implementation.
Again, a solvable problem^1. Within the next 5-10 years, they might have to go back to attacking the algorithms.
[^1]: See e.g., https://www.wireguard.com/papers/zinzindohoue-bhargavan-prot... Note that the first sentence of Ken's paper still holds, but the number of people you have to trust can be reduced if you only need to trust the verifier's kernel instead of every line of code committed from every contributor.
I don't trust other levels of the alleged chain of trust either. For example I consider it an absolute certainty that every competent globally active intelligence agency in the world has assets inside Facebook and Google, and most likely others. The cost and difficulty of inserting or recruiting an asset is so low and the potential benefits are so high that it's certain to have happened and in fact already has[1].
By the way while my ex-NSA buddy didn't elaborate on what he meant by attacking the implementation, but I'm pretty sure that includes subverting an implementer.
Edit: I don't think we really substantially disagree, the above is meant to be elaboration not rebuttal.
[1] https://www.washingtonpost.com/world/national-security/nsa-i...
Here's how to contact me by email if you prefed: https://dwheeler.com/contactme.html
(If you like, don't forget to buy it) https://www.teamten.com/lawrence/writings/coding-machines/