Skip to content

Commit

Permalink
Merge pull request #1007 from zerb4t/qmbZLTr1Ws
Browse files Browse the repository at this point in the history
[[Compromises]] Trusting Trust
  • Loading branch information
mnm678 authored Feb 16, 2023
2 parents 5359ce2 + adedf76 commit dd42b37
Show file tree
Hide file tree
Showing 2 changed files with 18 additions and 0 deletions.
17 changes: 17 additions & 0 deletions supply-chain-security/compromises/1984/login-bell.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# "Unix Support Group" event

According to [secondary sources research](https://niconiconi.neocities.org/posts/ken-thompson-really-did-launch-his-trusting-trust-trojan-attack-in-real-life/), a [well-known, published author](https://dl.acm.org/doi/10.1145/358198.358210) deployed a compiler trojan attack on the Unix login command by advertising a non-backwards-compatible feature to Bell Labs' Unix Support Group, making its way to the `login` command within a month.

## Impact

None as reported.

## Type of compromise

Compiler backdoor, possibly compounded with human elements.

## References

1. [Ken Thompson Really Did Launch His "Trusting Trust" Trojan Attack in Real Life](https://niconiconi.neocities.org/posts/ken-thompson-really-did-launch-his-trusting-trust-trojan-attack-in-real-life/)

Note: it's likely this event occured in the 70s but, absent primary sources, we picked the year _Reflections_ was published.
1 change: 1 addition & 0 deletions supply-chain-security/compromises/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,3 +95,4 @@ of compromise needs added, please include that as well.
| [SquirrelMail backdoor](2007/squirrelmail.md) | 2007 | Source Code | [1](https://lwn.net/Articles/262688/) |
| [gentoo rsync compromise](2003/gentoo-rsync.md) | 2003 | Source Code Repository | [1](https://archives.gentoo.org/gentoo-announce/message/7b0581416ddd91522c14513cb789f17a) |
| [Debian infra compromise](2003/debian.md) | 2003 | Publishing infrastructure | [1](https://www.debian.org/News/2003/20031202) |
| [Unix Support Group login backdoor](1984/login-bell.md) | <1984 | Dev Tooling | [1](https://niconiconi.neocities.org/posts/ken-thompson-really-did-launch-his-trusting-trust-trojan-attack-in-real-life/) |

0 comments on commit dd42b37

Please sign in to comment.