Am 08.02.2012 um 12:04 schrieb Philippe Marschall:
On 02/08/2012 11:33 AM, Norbert Hartl wrote:
Am 08.02.2012 um 11:12 schrieb Philippe Marschall:
On 02/08/2012 10:43 AM, Marcus Denker wrote:
On Feb 8, 2012, at 10:39 AM, Philippe Marschall wrote:
well I do not think so since we can all read the code.
No, read the argument again. If the compiler is compromised and the other tools in the image are compromised you can't read the code because the tools don't display you the actual code.
But this stays the same with a boot-strap, as you will use a compomised compiler to bootstrap the bootstrap.
There is nothing you can do against it. It's true for GCC or Java, too.
Yes, but read the links on how you can use a different, second compiler.
And what if the second compiler is compromised, too?
Am I the only one who read the link?
Now I read it. But it doesn't change the game. There is an assumption of "a trusted compiler". So they put trust into a compiler and then derive a scenario that is far from being applyable to define an easier way of establishing trust. I can say it again in yet another way: Trust is a _human_ factor that you cannot establish with technology. That's the whole point in everything security. Norbert