[1] Paper: http://www.emsec.rub.de/media/crypto/veroeffentlichungen/201...
[2] Presentation: https://www.iacr.org/workshops/ches/ches2013/presentations/C...
[3] Example system: https://www.lasertec.co.jp/en/products/semiconductor/mask_se...
161–170 of 818 posts
[1] Paper: http://www.emsec.rub.de/media/crypto/veroeffentlichungen/201...
[2] Presentation: https://www.iacr.org/workshops/ches/ches2013/presentations/C...
[3] Example system: https://www.lasertec.co.jp/en/products/semiconductor/mask_se...
Earlier quoted context omitted.
Yes, irrespective of country where its manufactured, if there are compliance requirements around an un-openable box, then some process becomes required. But I think the GP's question is: "Whether it would be cheaper" - in the sense whether such an expensive QA process could have been averted by having a more trustworthy partner. One whom you're not on a race hack after hack.
The point is that if the devices are sensitive with compliance requirements then you must be able to verify them irrespective of who you hired to manufacture them. You cannot just trust the word of a contractor on this because it's your ass on the line.
It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…
The problem with tech is that it's modularity and dependency on other people/tools/hardware/etc ultimately requires trust.
> in place for more than 20 years.
Far longer than 20 years. The idea of trust, privacy and security has been discussed for a long time. The complexity of security on just on one specific technology ( compilers ) was discussed in the early 1980s by Ken Thompson.
"Reflections on Trusting Trust"
https://news.ycombinator.com/item?id=13569275
Compilers are just one part of a complex ecosystem. Now imagine having to check ABI or the physical chips/hardware themselves. Where you require sophisticated hardware.
The motto of technology is "In Trust We Trust".
Who else found the design of the page made the article difficult to read? I know darkness, spies and hacking go hand-in-hand but it's a bit too much imho.
This is because, contrary to what a lot of people say about dark themes (even though it's mostly a meme at this point), dark letters on white background are better to read than white letters on black background.
This quote describes the situation well I think, why the opinions differ and why neither dominates UIs really.
Earlier quoted context omitted.
Who's saying the firewall isn't compromised too? ;)
Right so all the stars need to align for it to go unnoticed - compromised server, firewall and other alerting/monitoring tools. I would have thought one single unexpected packet in these high security environments would raise significant alarm bells and any anomaly would be found very quickly.
If you’re running an IDS on a big 100 Gb datacenter network, you’re literally processing millions of events. Very few places would notice such a thing unless they were investigating something related, and the ones with the capability are going to be for static workloads as getting anything done will be slow and painful.
Earlier quoted context omitted.
I've worked on systems deployed in the financial sector in high risk environments. This sort of monitoring doesn't happen in the real world.
Intrusion Detection Systems are basic network security 101 type stuff. I'd be surprised if anything that was really "high risk" didn't use an IDS.
Except on extremely controlled networks, this would be very hard to detect. It gets even worse when you consider that the Chinese had/have a distributed network of compromised machines. Imagine using a Google edge server as a dead drop...
"Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not."
Why does this keep getting quoted in the comments. Yes we read the article too.
The only interesting thing about this is left out. Who planted it is clear (someone told to do so) but not a single time is it questioned who they planted it for. Smells like false flag to me. We think China does X Y and Z but we know the US does X Y Z and the rest of the alphabet. So unless something specific is leaked that shows who actually ordered this, logic would point at the US.
I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…