David A. Wheeler's Page on Countering 'Trusting Trust' through Diverse Double-Compiling (DDC) - Countering Trojan Horse attacks on Compilers| dwheeler.com
Marius Gedminas (March 18, 2010 9:22 AM) It's been done before, but I liked your writeup better.| research.swtch.com
Go 1.21 is the first perfectly reproducible Go toolchain.| go.dev
Our Software Dependency Problem| research.swtch.com
Ken Thompson's "Trusting Trust" compiler Trojan attack was not just a thought experiment. In fact, Usenet poster Jay Ashworth stated that, from personal communications, Thompson really did launch this attack in real life and successfully compromised the Unix Support Group at Bell Labs. Recently, I've rediscovered this original message with full message headers in a search effort using various Usenet archives, showing the authenticity of the post.| niconiconi.neocities.org