This description was written by a machine and published without a person checking it. It is what the agent made of this grouping, and not a statement anybody has stood behind.

Trust you did not create yourself

A subject the papers are about. The loosest grouping, and the one to reach for last.

Where trust in a running system comes from, when it cannot come from reading the source. Thompson's compiler is the origin of the question; the rest of the set is the industry discovering, four decades later, that he was describing a supply chain.

The origin has a documented source, and it is in this set. Thompson built *Reflections on Trusting Trust* around Section 3.4.5, 'Trap Door Insertion', of Karger and Schell's 1974 Multics security evaluation -- held here as `karger2002multics`, the ACSAC 2002 reprint. So the famous lecture is not the first statement of the attack but the most memorable one, and the corpus holds the report it came from together with the authors' own retrospective, published alongside it in the same session and linked to it.

The answers offered since are consistently procedural rather than technical, which is the pattern worth noticing. Karger and Schell's answer was an evaluation team -- people paid to find what review missed. Hissam's is open source and many eyes. Yeoh's is zero trust as an architecture and a maturity model. Feffer's is red-teaming. None of these verifies a compiler; each substitutes a process, and a reader tracking the set chronologically watches the question get answered by organisational design four times over.

Feffer is the set's own sceptic and belongs at the end: *silver bullet or security theater?* asks whether the newest of those procedures does anything, which is the question the previous three also invite. Martinez on supply chain attacks and George on systemic risk in the digital economy are the cost side -- what it is worth when the answer turns out to be no.

The Karger reprint's copy is the proceedings volume rather than the paper, 20 pages declared against 160 held, and sits in the queue for it.

8 references

Red-teaming for generative AI: Silver bullet or security theater?
Michael Feffer and others (2024) · Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society
When trust fails: Examining systemic risk in the digital economy from the 2024 crowdstrike outage
A. Shaji George (2024) · Partners Universal Multidisciplinary Research Journal
Zero trust cybersecurity: Critical success factors and A maturity assessment framework
William Yeoh and others (2023) · Computers & Security
Software supply chain attacks, a threat to global cybersecurity: SolarWinds' case study
Jeferson Martínez and others (2021) · International Journal of Safety and Security Engineering
Trust and vulnerability in open source software
Scott A. Hissam and others (2002) · IEE Proceedings - Software · Institution of Engineering and Technology
Multics security evaluation: vulnerability analysis
Paul A. Karger and others (2002) · 18th Annual Computer Security Applications Conference (ACSAC 2002)
Thirty years later: lessons from the Multics security evaluation
P.A. Karger and others (2002) · 18th Annual Computer Security Applications Conference (ACSAC 2002) · IEEE Comput. Soc
Reflections on Trusting Trust
Ken Thompson (1984) · Communications of the ACM · Association for Computing Machinery