GEEK HAUS
Back to feed

Researchers show a tampered GNU strip tool can backdoor nearly an entire NixOS Linux distribution build

·arxiv.org
read original

EDITOR BRIEF

A new paper demonstrates that Ken Thompson’s trusting-trust attack can extend beyond compilers to ordinary build utilities. The researchers compromised GNU strip in NixOS’s binary seed, causing a payload to propagate through later strip generations and into the final system, backdooring almost every binary in a graphical installer build.

INSIGHTS

The work broadens the perceived threat model for software supply chains, showing that source-level audits and reproducible builds may miss attacks hidden in binary transformation tools. It also underscores the importance of independently verified bootstrap paths, diverse rebuilds, and stronger provenance checks for Linux distributions and package ecosystems.

COMMENTS

Discussion

> geekhaus:~$ next read?

Next read recommendations