2026-10-11 18:00 UTC

The authors of “Trusting-Trust Attack against an Entire Linux Distribution” claim a distribution-wide trusting-trust attack, potentially showing that inspecting source alone cannot establish the integrity of a Linux software supply chain.

state: expiredheat: lowuncertainty: highknownscott: lowsupply-chain-security toolchain-integrity build-verification

What is this?

“Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation” is a 2026 paper listed on arXiv; the supplied Semantic Scholar snippet names Julien Malka, Aman Sharma, Martin Monperrus, Stefano Zacchiroli, and Théo Zimmermann as authors. Its title claims distribution-wide scope, while the snippets describe the trusting-trust mechanism: a compromised compiler backdoors its outputs and preserves the backdoor when rebuilding itself. The supplied excerpts do not identify the distribution, establish the demonstrated scope, or detail the binary manipulation, so the search answer’s assertion of a successful demonstration through compiler vulnerabilities is not substantiated here. The case raises a question about whether source inspection establishes binary integrity, but the excerpts do not establish the paper’s specific findings.

Why it matters to Scott

The source-alone-is-insufficient lesson is already held in Scott’s Sovereign Software Assurance page, which requires demonstrated capability beyond source possession, including reproducible builds and security testing. The supplied excerpts establish neither the paper’s distribution-wide results nor consequences for his actual toolchains, so this remains an illustration of that position rather than a substantiated extension or publishing opportunity; the radar hits do not show this same paper already tracked.
ip:framework.sovereign-software-assuranceradar:concept.software-supply-chainradar:concept.supply-chain-security
queries asked of Scott's wikis
  • source transparency versus executable integrity
  • compiler bootstrap trust and build verification
  • reproducible builds diverse double compilation
  • coding agent harness dependency and toolchain security
  • software provenance trust boundaries in automated builds

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnTrusting-Trust Attack against an Entire Linux Distributionsigna1122350
🟧 echo.paper ⭐The linked paper is titled “Trusting-Trust Attack against an Entire Linux Distribution”; the observation supplies no attack details.Paper authors; names not supplied——

Interpretation history

Decision trace