Lunduke
News • Science & Tech
The creator of UNIX built a Trojan Horse which let him log in to any UNIX machine.
And nobody knew about it for years.
May 05, 2024
post photo preview

Back in 1984, the Association for Computing Machinery presented Ken Thompson with a “Turing Award” for his many contributions to the world of computing.

And for good reason.

Ken worked on Multics, co-created UNIX, created multiple programming languages (Bon and B — which directly led to C), co-created the Plan 9 operating system, UTF-8, and on and on.  If anyone deserves an award for advancing computing... it's Ken Thompson.

But we’re not here today to talk about those extraordinary contributions to computing.

No, sir.

We’re here to talk… about his acceptance speech.

Because that speech revealed a truly fascinatin computer virus that Thompson had created years earlier… for the C compiler.  One which gave him a backdoor into UNIX itself.

The Speech

He titled his speech “Reflections on Trusting Trust”, and the basic premise is this:

“To what extent should one trust a statement that a program is free of Trojan horses? Perhaps it is more important to trust the people who wrote the software.”

To prove his point, Ken told the tale of how he had — years earlier — created what was, essentially, a computer virus that infected the C compiler (cc) and the UNIX login program.

Seriously.

This is real.

Ken could gain control of most UNIX systems

It worked, essentially, like this:

Ken modified cc (the C compiler on UNIX systems) so that — only when it was compiling UNIX’s “login” program — it would inject a small “backdoor” (into “login”) that would allow him to log in as any user on the system if he used a predefined “password”.

Which is, obviously, a pretty big security hole.

However…

That sort of "universall password" code would be likely to be found during even a rudimentary code review of the C compiler. Or, heck, even by any casual programmer who happened upon that section of the code.

What Ken did next was… devious.

Hiding his UNIX backdoor

He needed to make sure that, should anyone find his nefarious code in “cc”… that his backdoor would live on.

So he then added functionality to “cc” so that it would detect if it was compiling itself (because the C compiler was compiled… in the C compiler)… and insert code into the compiler that would add… itself.

Which means…

Even if the source code is removed from “cc” project… the code (for adding both the login backdoor and the “keep adding this to the C compiler” bits) would get “invisibly” injected into “cc” every time it got compiled by an already infected build of the compiler.

So… as long as there was an unbroken chain of using the C compiler from that point onward, the UNIX login backdoor was unlikely to be effectively removed.

Brutal.

According to Thompson:

“The actual bug I planted in the compiler would match code in the UNIX "login" command. The replacement code would miscompile the login command so that it would accept either the intended encrypted password or a particular known password. Thus if this code were installed in binary and the binary were used to compile the login command, I could log into that system as any user.”

The Moral of the story

As Ken Thompson put it…

“The moral is obvious. You can't trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect.”

Did this make it out into the wild?

I know what you're thinking.  "Is this code still out there?  How many systems were impacted by this?"

What we know: This bit of naughty code was released to at least one machine (used by a UNIX support group). This has been confirmed by Ken, himself.

However, it is believed that the code went no further than that machine.

But... do we know for sure?

Do we actually have a high level of confidence that the modified “cc” and “login” went no further than that support group UNIX box?

No. No, we do not.

In fact, according to Eric S. Raymond

“[I have] heard two separate reports that suggest that the crocked login did make it out of Bell Labs, notably to BBN, and that it enabled at least one late-night login across the network by someone using the login name “kt”.”

BBN.  That's Raytheon.  A critical DARPA researcher -- one which was instrumental in the early days of ARPANET.  A huge amount of software came out of BBN.  Heck, even the first Text Adventure game came from there.

If UNIX machines at Raytheon BBN were infected... the possibility of infected versions of those files making it to other sites is incredibly high.

Truly wild

Which leads to a (rather amusing, and mildly terrifying) bit of historical trivia:

Ken Thompson — one of the co-creators of UNIX — intentionally created a trojan horse that infected both the C compiler and the “login” program of UNIX systems.

What’s more… it went undetected for years.  We wouldn't even have known about it, if he hadn't told us he created it.

And we truly have no clue how widespread that trojan became.

community logo
Join the Lunduke Community
To read more articles like this, sign up and join my community today
22
What else you may like…
Videos
Podcasts
Posts
Articles
Lunduke's Week in Tech - Aug 23, 2025

USA Owns Intel & Microsoft's Intifada Problem (Plus: UK Says Email Causes Drought)

The Article:
https://lunduke.substack.com/p/lundukes-week-in-tech-aug-23-2025

More from The Lunduke Journal:
https://lunduke.com/

00:39:03
Microsoft "Intifada" Shut Down After 4 Hours

Note: This video is being made free for all due to the nature of the news story. While all Audio Podcasts and Articles from The Lunduke Journal are always free, many videos are exclusive for subscribers. More details, and links, at Lunduke.com.

After the "Worker Intifada" declared they would occupy Microsoft Campus "as long as it takes" for Microsoft to cut ties with "the murderous Zionists", the event barely lasted past lunch.

The Article:
https://lunduke.substack.com/p/worker-intifada-occupies-microsoft

More from The Lunduke Journal:
https://lunduke.com/

00:34:11
Lunduke's Week in Tech - August 15th, 2025

Linux Kernel Chaos & The Non-Woke Software List

The Article: https://lunduke.substack.com/p/lundukes-week-in-tech-aug-15-2026

More from The Lunduke Journal:
https://lunduke.com/

00:45:49
November 22, 2023
The futility of Ad-Blockers

Ads are filling the entirety of the Web -- websites, podcasts, YouTube videos, etc. -- at an increasing rate. Prices for those ad placements are plummeting. Consumers are desperate to use ad-blockers to make the web palatable. Google (and others) are desperate to break and block ad-blockers. All of which results in... more ads and lower pay for creators.

It's a fascinatingly annoying cycle. And there's only one viable way out of it.

Looking for the Podcast RSS feed or other links? Check here:
https://lunduke.locals.com/post/4619051/lunduke-journal-link-central-tm

Give the gift of The Lunduke Journal:
https://lunduke.locals.com/post/4898317/give-the-gift-of-the-lunduke-journal

The futility of Ad-Blockers
November 21, 2023
openSUSE says "No Lunduke allowed!"

Those in power with openSUSE make it clear they will not allow me anywhere near anything related to the openSUSE project. Ever. For any reason.

Well, that settles that, then! Guess I won't be contributing to openSUSE! 🤣

Looking for the Podcast RSS feed or other links?
https://lunduke.locals.com/post/4619051/lunduke-journal-link-central-tm

Give the gift of The Lunduke Journal:
https://lunduke.locals.com/post/4898317/give-the-gift-of-the-lunduke-journal

openSUSE says "No Lunduke allowed!"
September 13, 2023
"Andreas Kling creator of Serenity OS & Ladybird Web Browser" - Lunduke’s Big Tech Show - September 13th, 2023 - Ep 044

This episode is free for all to enjoy and share.

Be sure to subscribe here at Lunduke.Locals.com to get all shows & articles (including interviews with other amazing nerds).

"Andreas Kling creator of Serenity OS & Ladybird Web Browser" - Lunduke’s Big Tech Show - September 13th, 2023 - Ep 044

#DailyWire Is Reading Lunduke Journal

It's the only explanation, eh @lunduke?

post photo preview

[Poll] Year of Linux vs "Big OS" Neo-Feudal Rule... What Kind of Future?

😾 Disclosure: Watching Windows Update Download/Install for 90 minutes got me Triggered about the state of "Non-Commercial-Computing" (see WEF on "You Will Own Nothing and BE HAPPY" ). Article Links at the bottom.... Not counting Microsoft's "Activists for Intifada." 🙈 "No Comment" is my vote.

In simple terms, "Server Linux" will be AWESOME (see Web Servers + Super-Computers). However, "Home Users" who want a Reliable Desktop Environment on Linux OS - Forget It!!!

In all fairness though, Windows 11 User will be screwed.... Techno-Feudalism only favors the Powerful (Corporate) and the "Well-Connected" (Political). You won't even be able to boot your computer unless your Internet-Login-ID has been validated (typically by SmartPhone "fingerprint" PKI registered with a certificate authority).

We could get LUCKY! ... 🌈 💾 🦄 DOGE OS ("Free" Release-Candidate-1) created in 4 ...

Framework is hardcore championing Omarchy despite the woke crowd complaining about the distro's creator and their political leanings. (DHH is an awesome person, and I find it hard to believe anyone could have a problem with him.)

In other news, I use Omarchy, btw.

post photo preview
post photo preview
Omarchy 2.0 - The Arch-Based, Hyprland, Non-Woke Distro
The 2.0 release of the unabashedly nerdy, developer focused, & DEI-free Linux distribution is here. And people are flocking to it.

Omarchy, an Arch-based Linux distribution which self-describes as “An opinionated Arch + Hyprland Setup”, has just published their 2.0 release.

 

Omarchy was started by David Heinemeier Hansson (DHH), the creator of Ruby on Rails, as a command-line and developer focused (and unabashedly nerdy) configuration of Arch Linux.

In the short time since it began (back in June), Omarchy has captured a massive amount of interest and has grown to become a full-fledged distribution in its own right.

Omarchy 2.0 boasts a new ISO installation method, AUR-free installation, a Chrome micro-fork with live theme switching, a Starship prompt, a new icon, and 400 other changes (from 45 contributors).

 

According to DHH, the Omarchy Discord now has over 6,000 members with the website having received over 100,000 unique visitors in the last month.

Not too shabby for a Linux distribution that is only 2 months old.

Speaking of Discord, if the Omarchy installation fails, it displays a QR code with an invite link to the Omarchy support channel. I thought that was a rather nice touch.

 

Worth noting that Omarchy — and the Hyprland window manager, which Omarchy uses by default — both were added to “Lunduke’s Non-Woke Software List” this month.

 

Omarchy is yet another Open Source project which has steered clear of Woke & DEI politics… and has seen tremendous success and adoption. We have seen that same scenario play out repeatedly now, with projects like OpenMandriva, XLibre, Hyprland, & Brave.

Avoid DEI. Experience a flood of users, contributors, and excitement.

A pattern is emerging. Hopefully more projects learn this important lesson.


The Lunduke Journal is the last bastion of truly independent Tech Journalism. Ad Free, Big Tech Free, Non-Woke, & Audience Supported.

Read full Article
post photo preview
Microsoft Adds Copilot AI to Excel
Microsoft warns users not to use Copilot in Excel spreadsheets “for any task requiring accuracy or reproducibility”.

Buckle up, Buttercup. Because you’re about to hear about one of the stupidest features ever added to a piece of software.

Microsoft has added their Copilot AI to Excel — so you can have an AI chatbot embedded into cells of your spreadsheet.

 

In case you were wondering just how bad of an idea this is, Microsoft is explicitly warning people that “Copilot uses AI and can give incorrect responses”.

In fact, Microsoft says you should NOT (they put “NOT” in all caps, so you know they mean it) use Copilot in Excel “for any task requiring accuracy or reproducibility” or for “tasks with legal, regulatory or compliance implications”.

 

I mean, really. Who uses spreadsheets for silly, math-y things like “accuracy” or “reproducibility”?

Another thing to keep in mind: Using Copilot AI within Excel means sending your spreadsheet data to Microsoft for analysis. Worth thinking about if you are using Excel for something like a “business”, or “government”, or “personal financial data”.

 

If that isn’t enough to deter you, and if you really hate that whole “accuracy” thing — and have a Microsoft 365 Copilot license — you can grab the Windows or Mac versions of Office in the Microsoft Beta Channel.


The Lunduke Journal is the last bastion of truly independent Tech Journalism. Ad Free, Big Tech Free, Non-Woke, & Audience Supported.

Read full Article
post photo preview
Ladybird Gains Google Sheets Support
Ladybird dev says: “Been told many times over the years that ‘you’ll never get complex stuff like Google Docs running’ lmao.”

The Ladybird web browser can now handle Google Sheets.

 

Watching as Ladybird rapidly gains support for increasingly complex websites (and web “apps”) is a truly marvelous thing.

As the lead developer of Ladybird says, it’s not perfect. But increasingly usable.

I mean, heck. Look at that. That’s Google Sheets. Running in a web browser that is not based on Firefox or Chrome.

 

The real question, for many of us, is “how long until we can use Ladybird as our daily web browser?”

According to the team, “Summer of 2026” is their target for the first official “Alpha” release. And my guess is… they’re probably about right. But, based on the rapid progress, I’d say it’s also reasonable to assume that super-duper-early adopters can probably start daily test driving Ladybird a bit sooner than that.

It seems like we are seeing significant new functionality, and site support, almost every day. Here’s Cal.com running in Ladybird.

 

And here one of the developers is showing off gamepad support. Which. Awesome.

 

Let this be your regular reminder: Anybody who is telling you “you can’t build [insert project here], it’s too hard and requires a massive team”… is full of doggy doo-doo.

Read full Article
See More
Available on mobile and TV devices
google store google store app store app store
google store google store app tv store app tv store amazon store amazon store roku store roku store
Powered by Locals