On 8 February 2012 12:33, Norbert Hartl <norbert@hartl.name> wrote:
Am 08.02.2012 um 11:12 schrieb Philippe Marschall:
On 02/08/2012 10:43 AM, Marcus Denker wrote:
On Feb 8, 2012, at 10:39 AM, Philippe Marschall wrote:
well I do not think so since we can all read the code.
No, read the argument again. If the compiler is compromised and the other tools in the image are compromised you can't read the code because the tools don't display you the actual code.
But this stays the same with a boot-strap, as you will use a compomised compiler to bootstrap the bootstrap.
There is nothing you can do against it. It's true for GCC or Java, too.
Yes, but read the links on how you can use a different, second compiler.
And what if the second compiler is compromised, too? An operating system is also a virtual environment. So what if that environment is rooted, lives in another shell? The "what if"-question in a security context can be played infinitely. The compromisable areas are only defined in opposite where you have put some trust. Or saying it in other words: There is no trust until you put it somewhere.
+1 -- Best regards, Igor Stasenko.