5 points
1 hour ago
| 4 comments
| HN
vaylian
1 hour ago
[-]
See the sovereign tech fund web site: https://www.sovereign.tech/tech

Arch Linux's package management is only one out of many open source projects that are being financially supported.

I think the tweet is just FUD (Fear, Uncertainty and Doubt)

reply
DonnyV
1 hour ago
[-]
"Rust is self-hosting: To build a new rustc, you need an existing rustc binary (usually the previous stable release). This creates a chain of trust that goes back to the very first bootstrap (historically from OCaml, but modern versions rely on prior Rust binaries).

If any link in that historical chain was ever compromised the backdoor can live on indefinitely.

Unlike C/C++ (which has diverse independent compilers like GCC, Clang, MSVC), Rust has essentially one production compiler (rustc). This makes diverse double-compilation (DDC), the main defense, much harder. DDC involves compiling the compiler source with multiple independent compilers and checking that the outputs match (proving the binary corresponds to the source). With only one mature compiler, you can't easily cross-verify.

There have been public demonstrations of exactly this kind of attack working on Rust (e.g., Manish Goregaokar's "Reflections on Rusting Trust" in 2016."

https://x.com/lmilsfsd/status/2011920950070046787

reply
hyperman1
1 hour ago
[-]
I assume mrustc is capable of bootstrapping rust?

https://github.com/thepowersgang/mrustc

reply
bigyabai
1 hour ago
[-]
Lunduke is not a programmer, he's a tech influencer. If he cannot point to the part of the Open Source program that is backdoored, it's probably another one of his meaningless ragebait pieces.

Suffice to say that Lunduke is technology's "Boy who cried Wolf" concerning security research.

reply
adityamwagh
1 hour ago
[-]
This just post just seems like a conspiracy theory.
reply
yunohn
1 hour ago
[-]
I’m struggling to understand why the German government is looking to compromise archlinux - arguably a niche of niches that is unlikely to be used by any of their enemies/targets.
reply
7bit
1 hour ago
[-]
To quote a commenter on X:

> There's no way you're this retarded

reply