The authors presented a research paper on a trusting-trust attack against a Linux distribution. The work shows that this attack is not a threat limited to compilers.
The authors built a complete attack around GNU strip. The attack changes finished ELF files, although GNU strip neither analyses nor creates source code.
When NixOS boots, one modified strip in the binary seed injects a payload that passes from one generation of strip to the next.
On a real nixpkgs revision, the attack built a complete graphical installer without failures. It inserted a backdoor into almost all of its binary files and allows arbitrary malicious behaviour by compromised packages.
Claim check:
- The authors presented a research paper on a trusting-trust attack against an entire Linux distribution through binary manipulation; it shows that this attack is not a threat specific only to compilers. (confirmed by the publication itself: evidence; «Ken Thompson’s trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not.»)
- The work builds a complete trusting-trust attack around GNU strip. (confirmed by the publication itself: evidence; «We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files.»)
- The attack uses manipulation of finished ELF files, although GNU strip neither analyses nor generates source code. (confirmed by the publication itself: evidence; «We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files.»)
- When NixOS boots, one modified strip in the binary seed injects a payload that passes from one generation of strip to the next. (confirmed by the publication itself: evidence; «In the bootstrap of the NixOS Linux distribution, a single tampered strip in the binary seed implants a payload that propagates from one generation of strip to the next and survives into the final standard environment after the seed leaves the dependency closure.»)
- The payload persists in the final standard environment after the seed leaves the dependency graph. (confirmed by the publication itself: evidence; «In the bootstrap of the NixOS Linux distribution, a single tampered strip in the binary seed implants a payload that propagates from one generation of strip to the next and survives into the final standard environment after the seed leaves the dependency closure.»)
- On a real nixpkgs revision, the attack builds a complete graphical installer without failures. (confirmed by the publication itself: evidence; «On a real nixpkgs revision, the attack builds a complete graphical installer without failures and backdoors almost every one of its binaries, enabling arbitrary malicious behavior of the subverted packages.»)
- The attack inserts a backdoor into almost all installer binary files and allows arbitrary malicious behaviour by compromised packages. (confirmed by the publication itself: evidence; «On a real nixpkgs revision, the attack builds a complete graphical installer without failures and backdoors almost every one of its binaries, enabling arbitrary malicious behavior of the subverted packages.»)
Primary sources:
score 80.5 · kind research · revision 1 · stories st-m7351h