Skip to content
HN On Hacker News ↗

Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation

▲ 241 points 59 comments by signa11 2w ago HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is human-written.

19 %

AI likelihood · overall

Human
100% human-written 0% AI-generated
SEGMENTS · HUMAN 1 of 1
SEGMENTS · AI 0 of 1
WORD COUNT 181
PEAK AI % 19% · §1
Analyzed
Sep 7
backend: pangram/v3.3
Segments scanned
1 windows
avg 181 words each
Distribution
100 / 0%
human / AI fraction
Verdict
Human
Pangram v3.3

Article text · 181 words · 1 segments analyzed

Human AI-generated
§1 Human · 19%

View PDF HTML (experimental) Abstract:Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not. We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files. In the bootstrap of the NixOS Linux distribution, a single tampered strip in the binary seed implants a payload that propagates from one generation of strip to the next and survives into the final standard environment after the seed leaves the dependency closure. On a real nixpkgs revision, the attack builds a complete graphical installer without failures and backdoors almost every one of its binaries, enabling arbitrary malicious behavior of the subverted packages. Subjects: Cryptography and Security (cs.CR); Software Engineering (cs.SE) Cite as: arXiv:2607.24888 [cs.CR] (or arXiv:2607.24888v1 [cs.CR] for this version) https://doi.org/10.48550/arXiv.2607.24888 arXiv-issued DOI via DataCite Submission history From: Aman Sharma [view email] [v1] Mon, 27 Jul 2026 12:59:15 UTC (1,848 KB)