Wouldn't the laser of a CD/DVD writer be powerful enough to alter the data after the fact? Not to overwrite it with completely arbitrary data, but flipping a few well-chosen bits should in principle be able to create a backdoor that wasn't there before (if it's a live or install disk, for example).
You can change things, yes, but not in a way that keeps the disc usable.
The issue here is that you can't "unburn" a bit that has been burned. Since you burn 0s, not 1s, all you can do is make more bits 0 -- which would then be corrected by the error correction mechanism. You could alter the EC codes, but that would render them useless and eliminate the ability to correct errors, causing the data to be unreadable by a normal drive due to EC failure.
So, in practice, they're pretty safe. The worst thing that an attacker could do is to render the media unusable.
That's not completely true either. I used to use some sketchy utility back in the day that could mark one recording session as inaccessible and let you add data to any remaining space on the disc. You would only see the new session. Hypothetically you can also manipulate the file table to make it look exactly like the real thing.
I don't remember if it required the disc to be un-finalized or not. It probably did.
True, I was assuming the disc wasn't written as a multi-session one (most people never use multi-session). Multi-session discs are a bit different. But, afaik, if the disc has been finalized then the result is as "immutable" as a non-multisession one. I'm not completely certain about that, though.
Are the EC codes such that any alteration from 1 to 0 in the message results in at least one flip from 0 to 1 in the (correct) EC code?
If not, then you "just" have to find the right spots where such a simultaneous alteration of the payload and the EC code is possible, and which also happens to result in a desirable behavior change.
No, the Reed Solomon codes used in the CD have one EC byte for every 3 data bytes. But there's a interleaving system where the data is encoded with error correction (adding 4 bytes to every 24) interleaved so that burst errors (that affect nearby disk surface) are distributed in the data stream, then encoded again (adding 4 bytes to 24 + 4 to give 32, with 8 EC bytes).
So you'd have to find mutations that are big enough to not be automatically corrected (more than 2 bits, you can't change, say a single 0x30 to 0x31), and also happen have the right signature so they don't flag as erasures, so you can't freely change bytes to just anything. And then you have to also satisfy the outer code that your modified byte after interleaving is correct. And do it all by only bring able to bit-flip in one direction. The only upside is that you can also flip bits in the correction bytes if you need.
Also, if the data you're modifying has any coding or compression (ZIP, Word documents, videos, most images), or there are checksums, you have to not upset that. And if it's encrypted, you won't know what to change in the first place.
So it's theoretically possible, but it would be very tricky and highly unlikely that you could change a useful piece of data unless you were extremely lucky with what the data was, what you wanted it to be, and where it was on the disk.
If you're concerned about people modifying your CD-R: encrypt and SHA-256 the whole thing and you'll be fine. I assume this threat model mostly targets governments, so they should first do both of those things and maybe also stop leaving them on trains.
Wouldn't the laser of a CD/DVD writer be powerful enough to alter the data after the fact? Not to overwrite it with completely arbitrary data, but flipping a few well-chosen bits should in principle be able to create a backdoor that wasn't there before (if it's a live or install disk, for example).