Open post Russ Cox @rsc@hachyderm.io · 33mo ago Replying to @rsc@hachyderm.io <p>Luiz Barroso wrote a few very good, short essays on engineering practices at Google. He tragically died in September, but I recently discovered that he had already shared them beyond Google and they're now posted at <a href="https://fontoura.org/papers/barroso.pdf" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">fontoura.org/papers/barroso.pdf</span><span class="invisible"></span></a></p><p>The whole thing is worth reading but the three one-pagers on pages 2, 3, and 4 of the PDF are each gems.</p> The original linkedin post announcing them is https://www.linkedin.com/pulse/luiz-barrosos-short-essays-engineering-culture-marcus-fontoura linkedin.com
Open post Russ Cox @rsc@hachyderm.io · 35mo ago Replying to @hovav@infosec.exchange <p>The security hill I will die on: Credit for the “backdoored compiler” trick should go to Karger and Schell (“Multics Security Evaluation: Vulnerability Analysis,” 1974).¹ That’s the “Unknown Air Force Document” from which Thompson (1984) borrowed the idea.<br />__<br />¹ <a href="https://www.acsac.org/2002/papers/classic-multics-orig.pdf" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">acsac.org/2002/papers/classic-</span><span class="invisible">multics-orig.pdf</span></a>, §3.4.5</p> @hovav Ken updated his copy of the paper decades ago to cite them directly. That copy is gone but a presumably unauthorized mirror is at http://cm.bell-labs.co/who/ken/trust.html - see reference 4. cm.bell-labs.co