| |
Trusting-Trust Attack against an Entire Linux Distribution
Researchers demonstrated a trusting-trust attack on the NixOS Linux distribution by compromising GNU strip, a standard build utility, rather than a compiler. By manipulating binary ELF files, they showed how a single tampered strip in the bootstrap seed could propagate malicious code through successive generations and backdoor nearly all binaries in the final system, including a complete graphical installer. This challenges the conventional understanding that trusting-trust attacks are limited to compilers, revealing a broader security vulnerability in Linux distribution build systems.
Read Full Article →
← More Tech news