lucida
blog paper tags 中文

Reflections on Trusting Trust

1984 · Ken Thompson

Through self-reproducing programs and a backdoored compiler, Thompson shows why source review alone cannot fully establish trust in a toolchain or software supply chain.

thoughts, notes, and writings