[TUHS] Thompson trojan put into practice

arnold at skeeve.com arnold at skeeve.com
Mon Sep 20 17:12:27 AEST 2021


Douglas McIlroy <douglas.mcilroy at dartmouth.edu> wrote:

> > It's part of my academic project to work on provable compiler security.
> > I tried to do it according to the "Reflections on Trusting Trust" by Ken
> > Thompson, not only to show a compiler Trojan horse but also to prove that
> > we can discover it.
>
> Of course it can be discovered if you look for it. What was impressive about
> the folks who got Thompson's compiler at PWB is that they found the horse
> even though they weren't looking for it.

I had not heard this story. Can you elaborate, please? My impression from having
read the paper (a long time ago now) is that Ken did the experiment locally only.

Thanks,

Arnold


More information about the TUHS mailing list