Is a Code Backdoor Illegal? From Payment Time-Bombs to Ken Thompson's Compiler Hack

The article examines whether intentionally leaving a backdoor in code is illegal through three Zhihu answers: a developer's time-bomb to secure payment, a security expert's legal analysis that China punishes misuse not existence, and Ken Thompson's compiler-level backdoor demonstrating supply-chain threats.

Architect's Guide
Architect's Guide
Architect's Guide
Is a Code Backdoor Illegal? From Payment Time-Bombs to Ken Thompson's Compiler Hack

Overview

The article examines three notable answers from a Zhihu question: "Is it illegal to deliberately leave a vulnerability in code?" The answers cover a contractor's payment-enforcement tactic, a legal expert's statutory interpretation, and Ken Thompson's historic compiler-level backdoor.

First Answer: Contractor's Time-Bomb for Payment Enforcement

Answerer 特立独行的猪 recounts an outsourcing project for a Taiwan company: custom Android ROM, development fee 160,000 RMB, maintenance 20,000 RMB/year. Payment schedule: 40,000 deposit, 80,000 on production ROM delivery, final 40,000 on source-code handover.

Before delivering the production ROM, the developer embedded a timestamp check hidden in a driver that would prevent boot after six months.

Four months later the client still hadn't paid the final installment, using various excuses. Two months after that the time-bomb triggered; downstream customers complained, and the client paid the balance. The answerer argues this was self-protection, not illegal, especially given cross-border litigation difficulties.

Author's Reflection on First Answer

The author recalls similar early freelance experiences where clients disappeared after delivery, wishing they had known about time-limiting mechanisms. They caution that while the answerer claims legality, only a court can decide; such tactics remain risky.

Second Answer: Legal Perspective from Security Expert tombkeeper

Answerer tombkeeper (TK教主) states China has no law that penalizes a backdoor per se, because "backdoor" lacks an objective definition. Examples: auto-update mechanisms, hot-patch systems, remote maintenance, ISP remote management of ONTs — all could be considered backdoors.

Therefore, legal liability attaches to the use of a backdoor for malicious acts, not its mere existence. If you leave a backdoor and never use it, no crime; if you exploit it, you are charged for the specific malicious action.

Third Answer: Ken Thompson's Compiler Backdoor (Trusting Trust Attack)

Answerer 沧海 describes Ken Thompson's 1983 Turing Award revelation. At Bell Labs, Thompson could access any Unix account regardless of password changes. Even after a colleague audited the Unix source, removed the apparent backdoor, and recompiled, Thompson still gained access.

The secret: the backdoor resided in the C compiler itself. The compiler injected the login backdoor whenever it compiled the login program, and also injected the compiler backdoor when compiling the compiler. Since the Unix system had to be built with that compiler, cleaning the source code was futile.

This supply-chain attack pattern reappeared in the XcodeGhost incident. The answerer classifies backdoor sophistication levels:

Low: code-level

Mid: toolchain-level

High: compiler-level

Ultimate: hardware-level (virtually undetectable)

Conclusion: "Be nice to programmers."

Additional Note: IDA Pro Supply-Chain Attack

The author mentions a recent case where a hacker group poisoned IDA Pro, a critical reverse-engineering tool, constituting a targeted attack against security professionals.

References

Zhihu question: https://www.zhihu.com/question/531724027<br/>Answer 1: https://www.zhihu.com/question/531724027/answer/2487270093<br/>Answer 2: https://www.zhihu.com/question/531724027/answer/2539891264<br/>Answer 3: https://www.zhihu.com/question/531724027/answer/2487130220

Code example

·················END·················
资料链接
清华学姐自学的Linux笔记,天花板级别!
新版鸟哥Linux私房菜资料
阿里大佬总结的《图解Java》火了,完整版PDF开放下载!
Alibaba官方上线!SpringBoot+SpringCloud全彩指南
国内最强的SpringBoot+Vue全栈项目天花板,不接受反驳!
Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

information securitybackdoorsupply-chain attackKen ThompsonXcodeGhostcompiler backdoorlegal liabilitytime-bomb
Architect's Guide
Written by

Architect's Guide

Dedicated to sharing programmer-architect skills—Java backend, system, microservice, and distributed architectures—to help you become a senior architect.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.