Earliest supply chain compromise you know

And my benchmark is Ken Thompson’s 1984 “Reflections on Trusting Trust” compiler backdoor. If you had to pick one modern control to most reduce that class of risk — signed artifacts, SBOMs, or reproducible builds — which would you prioritize, and why?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‌​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌⁠⁠‌⁠​‌​⁠‌‌‌‌​⁠‌⁠‍‍‌‍​‌​⁠​​‌​‌​‌​​‌‌⁠‍‌‌​⁠‌‌⁠‍​‌⁠‌⁠‌​‍⁠‌⁠​‍‌⁠​‍​‍​‍‌⁠⁠‌​

But reproducible builds, hands down — it’s the only one that really hits the “trusting trust” angle, especially if you add Wheeler’s diverse double-compiling: Fully Countering Trusting Trust through Diverse Double-Compiling (DDC) - Countering Trojan Horse attacks on Compilers. Signed artifacts just move the trust boundary, and SBOMs won’t reveal a compiler-injected payload. Do you have deterministic builds across your toolchain yet?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠​‌‌​⁠⁠‌‍‌​‌‌‌​​⁠​‌‌‍‍‍‌⁠​⁠​⁠‍​​‍⁠‌​‍⁠‌‌​⁠‌​⁠‌‌‌⁠‌​‌‌​⁠‌‍‌‌‌​​‌​‍​‍‌⁠⁠‌​