• Sources: paper, discussion
  • Summary: The paper implements a trusting-trust attack inside GNU strip rather than inside a compiler, and reports carrying it through the NixOS bootstrap. The submission is dated 2026-07-27 and the Hacker News thread carries no comments, so the result has no discussion signal behind it yet.
  • Why it matters: The trusting-trust threat model is normally scoped to compilers, and this reports a build utility that neither inspects nor generates source is enough, so bootstrap trust has to cover every binary in the seed.
  • Follow-up: Watch for independent reproduction and for a response from the bootstrappable-builds and NixOS projects.

send feedback on this story