Return Styles: Pseud0ch, Terminal, Valhalla, NES, Geocities, Blue Moon. Entire thread

Trusting trust

Name: Anonymous 2017-01-26 20:31

So how likely is it that there are hidden trojan horse-like vulnerabilities in common open source software that we haven't noticed? How valuable is the idea that we should start over and build our systems the right way to prevent that possibility at every step?

Name: Anonymous 2017-01-26 21:29

vulnerabilities in common open source software that we haven't noticed
??
There are thousands autists drowning in FOSS code, lots of them are weaponised autists but lots are also whiteknight community friends, they would honestly make any shady codes publix.

Name: Anonymous 2017-01-26 21:35

>>2
Yeah but if it was built into the binary to replicate itself without tainted source, e.g. through a compiler, it would be much harder to notice.

This is probably not the only solution, but I think you'd have to compile one compiler with two different compilers, then use each different compiled compiler to detect differences between compiled binaries in their outputs.

e.g.
Compiler A 2.0 (compiled by Compiler A 1.9) is tained
to verify this, you'd have to compile a second version of Compiler A 2.0 (call it Compiler AB 2.0, with Compiler B (which has either no vulnerabilities, or sufficiently different ones).

Then you'd compile Compiler A 2.0 again with both Compiler A 2.0, and Compiler AB 2.0. If the binaries are different, you could be reasonably sure that Compiler A isn't tainted, or that A and B are tainted in the same way.

Name: Anonymous 2017-01-26 23:11

not likely

Name: Anonymous 2017-01-27 0:22

>>4
prove it

JACKSON FIVE CNSATNT

Name: Anonymous 2017-01-27 0:56

>>3
Write your own bootstrapping compiler to compile a full featured compiler that you can trust. Problem solved.

Name: Anonymous 2017-01-27 8:37

>>6
1. write bootstrapping compiler
2. write full featured compiler
3. implement diff

Name: Anonymous 2017-01-27 10:05

>>7
1.skip the bullshit & compile GCC with TCC

Name: Anonymous 2017-01-27 11:05

i dont run any apps that have not been handcompiled by me myself in GHC

Name: Anonymous 2017-01-27 12:42

>>9
GHC is compromised.

Name: Anonymous 2017-01-27 17:36

>>7
lets see

Name: Anonymous 2017-01-27 18:33

>>6
But I'd have to write it in machine code, because my assembler might be compromised.

In fact, my editor might also be compromised, and detect that I'm trying to bootstrap a compiler. I'd have to flip bits on the machine itself (with switches?) to program a basic hex editor first

Name: Anonymous 2017-01-27 21:57

>>12
Better scrap all that and start from raw silicon.

Name: Anonymous 2017-01-27 22:56

better write your own universe

Name: Anonymous 2017-01-27 23:17

>>12
I hope you're not using x86, because it's been compromised for years.

Name: Anonymous 2017-01-28 0:15

>>15
that's what i was worrying about tbh

Name: Anonymous 2017-01-28 16:43

>>12
he can't even write an x86 assembler
he's worried about trusting trust compilers
laughinggirls.tiff

Name: Anonymous 2017-01-28 17:03

how write aseembler?

Name: Anonymous 2017-01-28 19:11

>>18
Make a bunch of regex to substitute machine code for mnemonics.

Name: Anonymous 2017-01-28 20:35

Name: Anonymous 2017-01-28 21:23

>>17
x86 is bloat

Name: Anonymous 2017-01-28 23:00

πŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡Έ
I claim these dubz in the name of the United States of America
πŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡Έ

Name: Anonymous 2017-01-28 23:06

>>22
Racist Trump supporter!

Name: Anonymous 2017-01-29 3:39

>>17
I can write assembly, but if the assembler is compromised it doesn't help

Name: Anonymous 2017-01-29 12:57

>>24
he can write assembly
he cannot write an assembler
2017
ishygddt

Name: Anonymous 2017-01-29 15:58

How do we write an uncompromised assembler

Name: Anonymous 2017-01-29 16:30

>>26
Hex editor, opcode table and calculator.

Name: Anonymous 2017-01-29 16:57

>>26
First u need to build an uncompromised CPU

Name: Anonymous 2017-01-29 19:44

GOTO >>1

Name: Anonymous 2017-01-30 20:31

Any progress on this, guys?

Name: Anonymous 2017-01-30 21:28

>>30
It's closed because you're a fucking cuck

Name: Anonymous 2017-01-30 21:33

>>31
but im writing code in binary right now

Name: Anonymous 2017-01-31 0:55

πŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡Έ
I claim these dubz in the name of the United States of America
πŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡Έ

Name: Anonymous 2017-01-31 7:26

>>31
e/pol/in cuck meme, /pol/ro!

Name: Anonymous 2017-01-31 9:35

>>34
/pol/
It's a /tv/ meme, cocknigger.

Newer Posts
Don't change these.
Name: Email:
Entire Thread Thread List