Glossary · Term

Trusting Trust

← all terms

Definition

Plain language

The classic warning that you can't fully trust software just by reading its code, because the tools that built it could have been tampered with.

As stated in the literature

Shorthand for Thompson's 1984 argument that a compromised compiler can reinsert a backdoor into itself and its outputs, leaving no evidence in source; this paper revisits it with AI coding agents as the modern build tool.

Also called: Reflections on Trusting Trust, trusting trust

Why it matters: It sets the limit on what code review can promise, and that limit gets sharper as more code is written and assembled by tools nobody inspects line by line.

For example, you could read every line of a program, find nothing wrong, and still end up running a backdoor because the compiler that turned that code into a runnable file added one.

Heard on the show

“The paper is "Reflections on Trusting Trust, Revisited," by Franziska Roesner and Tadayoshi Kohno, posted September 15th, 2026.”
Episode 268 — A Rigged Benchmark Taught a Self-Improving Agent to Always Disable SSL

Related terms