How can we be sure that Ken (working for Google) didn't infect the toolchain used for Chrome to propagate that legend?
How can we be sure that Ken (working for Google) didn't infect the toolchain used for Chrome to propagate that legend?
Then again, perhaps he also infected all those fancy PCB & IC supply toolchains…
EDIT: just kidding - no "chrome-headless-c++ -c firefox.o firefox.cpp" (yet).
It does not.
There is no shared code between Firefox and Chrome. They use completely different rendering engines with independent histories (Chrome uses Blink originated from WebKit originated from KHTML, Firefox uses Gecko originated from Netscape originated from Mosaic).
The only shared component is that Firefox utilizes public APIs for Google SafeBrowsing.
Disclaimer: ex-Mozillian
The "on trusting trust" attack regards using your compiler as a mechanism to infect compiled executables -- including compilers themselves, and their generated code.
I didn't mean to suggest that the two browsers shared any code.
For some of these shared open source libraries, either Mozilla or Google is the primary contributor/maintainer, and both organizations usually make contributions. This is true across many things, even libraries in the open source space that are not involved in the browsers themselves but may be in the toolchain (Mozilla has produced robust open source CI/CD tooling, bug trackers, etc over its history).
ELI5: are you really sure that when you work on Firefox source code from VS Code, that what ends up in the saved file and what gets committed to Git is what you actually see on screen?
VSCode doesn't seem like a "on trusting trust" attack vector since we can easily observe the git outputs of the C/C++ source and these parts often reviewed by peers. Unlike object code -- we can always take a look at the disassembly but in practice it's not scrutinized.
It's probably frustrating to those who work on Firefox to suggest that it somehow depends on Chrome. I get that. But it wasn't where I was going.
There is some kinda-out-there reality though -- with something like WASM or v8 you can theoretically run real toolchains like gcc and clang "in the browser". ;)
> frustrating to those who work on Firefox to suggest that it somehow depends on Chrome.
Maybe those developers should not look too closely at who ultimately pays their salaries :)