Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Surely these two things aren't exclusive? One could log into one's account on a (Linux|BSD|etc.) installation and find all one's data gone, then read the source code to find out what went wrong. I presume you don't check the complete source code for your operating system before installing it, just to see if there are any bugs there.


Besides, checking all "OS" source code won't save you. You'll also need to read all source code for the compiler etc. as proven by Ken Thompson:

http://cm.bell-labs.com/who/ken/trust.html


I don't think anyone is suggesting that this is malicious, and any compiler-only bug that didn't affect only compiling would almost have to be.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: