Businesses and governments urged to take action over Trojan Source supply chain attacks
Summary
Businesses and governments have been urged to take action to protect themselves against hacking attacks that are capable of injecting invisible back doors into the source code of widely used programming languages. The hacking technique, disclosed today by researchers at the University of Cambridge, can be used by hostile attackers to insert back doors into source code across almost all computer languages. Nicholas Boucher and Ross Anderson of Cambridge University’s Computer Science Laboratory demonstrated that C, C++, JavaScript, Java, Rust, Go and Python are vulnerable to Trojan Source attacks. They warned in a research paper published today (1 November) that the same attacks could be applied to almost any programming language that uses common software compilers that make use of Unicode – the international standard for encoding text and scripts. “We recommend that governments and firms that rely on critical software should identify their supplier’s posture, exert pressure on them to implement adequate defences and ensure that any gaps are covered by controls elsewhere in their toolchain,” the academics state in their paper.