- Sources: paper, discussion
- Summary: The paper implements a trusting-trust attack inside GNU strip rather than inside a compiler, and reports carrying it through the NixOS bootstrap. The submission is dated 2026-07-27 and the Hacker News thread carries no comments, so the result has no discussion signal behind it yet.
- Why it matters: The trusting-trust threat model is normally scoped to compilers, and this reports a build utility that neither inspects nor generates source is enough, so bootstrap trust has to cover every binary in the seed.
- Follow-up: Watch for independent reproduction and for a response from the bootstrappable-builds and NixOS projects.
send feedback on this story