Hacker News new | ask | show | jobs
by brendank310 1318 days ago
David Wheeler's Ph.D dissertation on the subject hasn't been refuted as far as I know, so the diverse double compilation method should be sufficient to mitigate the compiler subversion threat. I worked on a project to do this in OpenEmbedded to build firmware for the Power9 Talos workstation firmware and the BMC. Somewhat painful but successful.