[41665] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Countering Trusting Trust through Diverse Double-Compiling

daemon@ATHENA.MIT.EDU (Mike Lisanke)
Thu Dec 15 05:06:58 2005

Message-ID: <8c5c6e580512141441r6f4c0e04j939e53664838791c@mail.gmail.com>
Date: Wed, 14 Dec 2005 17:41:33 -0500
From: Mike Lisanke <mikelisanke@gmail.com>
To: "David A. Wheeler" <dwheeler@ida.org>
Cc: bugtraq@securityfocus.com
In-Reply-To: <439DF3CA.1020305@ida.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

David,

I haven't read the original attack description recently, but; I seam
to remember that the ability of the tampered compiler to inject
malicious code could be stateful. Either a timing attack, or a attack
after n-builds, so that malicious code is injected in an arbitrary,
pseudo-random, less detectable way. Also, that this code would be
injected based on compiler state conditions (like after keywords
indicated that the code may be network based). I haven't read your
paper, yet; but; I'd be interested know where you'd plan to discuss
scenarios where your counter attack would fail. Thank you.

Best regards,
--
Mike

home help back first fref pref prev next nref lref last post