编译器可能会撤销您的安全检查
Compiler Can Undo Your Security Checks

原始链接: https://davidbombal.com/your-compiler-can-undo-your-security-checks/

在 2026 年美国黑帽大会(Black Hat USA)的这次访谈中,David Bombal 与安全研究员 Chris Domas 深入探讨了软件安全领域的一个关键现实:编写“安全”的源代码并不能保证生成的二进制文件是安全的。 讨论的重点在于编译器如何通过激进的优化无意中引入漏洞。即使开发人员遵循了最佳实践,编译器也可能删除内存清理操作、绕过安全检查,或造成“检查时间与使用时间”(TOCTOU)缺陷。Domas 解释说,这些问题往往受寄存器压力、结构体布局和特定数据大小等技术变量的影响,从而将原本安全的代码转变为危险的机器指令。 双方探讨了更换编译器或使用 Rust 等编程语言是否能彻底解决问题,以及人工智能如何被用于在数百万行代码中搜寻此类模式。最后,Domas 为开发人员提供了实用的建议:不仅要进行源代码层面的分析,还要启用编译器警告、利用清理工具(sanitizers),最重要的是,对最终交付的二进制文件进行严格测试。本次访谈提醒我们,在现代计算中,编译器与代码本身一样,都是攻击面的一部分。

Hacker News 最新 | 往期 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 编译器可以撤销你的安全检查 (davidbombal.com) 5 分 | birdculture 27 分钟前 | 隐藏 | 往期 | 收藏 | 讨论 | 帮助 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Big thanks to @ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces.

David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure.

Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns.

Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped.

// Christopher Domas’ SOCIAL //
LinkedIn: / christopher-domas
GitHub: https://github.com/xoreaxeaxeax
X: https://x.com/xoreaxeaxeax

// David’s Social //

================
Coect with me:
================
Discord: http://discord.davidbombal.com
X: https://www.x.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube Main https://www.youtube.com/davidbombal
YouTube Tech: https://www.youtube.com/chael/UCZTIRrENWr_rjVoA7BcUE_A
YouTube Clips: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Emerging Technologies: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Shorts: https://www.youtube.com/chael/UCEyCubIF0e8MYi1jkgVepKg
Apple Podcast: https://davidbombal.wiki/applepodcast
Spotify Podcast: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: / davidbombal

================
Support me:
================
Or, buy my CCNA course and support me:
DavidBombal.com: CCNA ($10): http://bit.ly/yt999ccna
Udemy CCNA Course: https://bit.ly/ccnafor10dollars
GNS3 CCNA Course: CCNA ($10): https://bit.ly/gns3ccna10

// MY STUFF //
https://www.amazon.com/shop/davidbombal

// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]

// MENU //
0:00 – Coming Up
0:48 – Intro
02:05 – Different Ways of Exploiting CPU’s

04:10 – The C Specifications
06:17 – The Compiler Deleting Nemsec
08:40 – Do we need to use a new Compiler ?

10:09 – Compiler Inventing Vulnerabilities
12:13 – Don’t Give up Writing Secure Code
12:44 – Sponsored Section
14:25 – Any Easy Options To Create A New Compiler ?

15:09 – Chris’s Presentation at Black Hat
20:00 – Weird Situations with Size of Data
21:22 – What Can Developers Do ?
23:32 – Who Can Leverage this Vulnerability ?

25:02 – Could AI Make it Easy For Attackers To Leverage This?

28:27 – Recommendations For Developers
29:48 – Advice To Be Like Chris
30:36 – Conclusion & Outro

Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

Disclaimer: This video is for educational purposes only.
#bhusa2026 #securecoding #compiler

联系我们 contact @ memedata.com