Earlier quoted context omitted.
My take on this is that it's been fairly obvious for a long time that these kinds of attacks are possible (if not easy) with today's technology. One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. So why is this suddenly breaking news? It bears resemblance to most of the propaganda stories we have seen in rec…
>One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. Don't you think it's going to be suspicious when you see a capacitor with 6 pins? Don't you think anyone that inspects the motherboard is going to wonder why a capacitor has 4 additional lines going to a critical flash chip? Seriously.... The entire article…
Consider what a state actor could do with access to modern microprocessor level fabrication.
I'd expect that we'd see features such as the following:
- sophisticated intra-chip communication
- long periods of total dormancy of the exploits
- circuitry capable of receiving a "it's safe to begin the attack" message
- surprising communications vectors for exfiltration
- technology to make malicious parts appear under x-ray to be normal
- fallback to awaiting the message to perform DoS if more sophisticated attack vectors are not possible
I agree with your suggestion about using the existing footprint, etc. There is likely some very sophisticated tech for making malicious parts x-ray and test as normal in every respect.
The network connector exploit described in the article would be easily detectable by temperature dissipation measurements. So distributed methodologies are likely in use.
I'd also estimate that a large number of mobile devices have built-in hardware compromises that are dormant and can be used if necessary. These would be the simplest attacks to carry out and would have extremely high yield. Things like:
- phones suddenly jamming the 4G and WiFi network simultaneously
- hardware implants to help detect whether a device is being used by a high value target. Such an attack could be created using a tiny bit of silicon and would be dormant in most cases.
The biggest risk to a state actor doing these kinds of attacks is being detected, so firmware based attacks are potentially more risky than hardware attacks, since we are better at detecting a checksum mismatch than we are at testing hardware across the spectrum of possible input conditions that might trigger unusual behavior.
So I think we'd see state actors dipping their toe in slowly to these kinds of attacks, first establishing the supply chain hacks without anything malicious going on, and then gradually phasing in actual malicious hardware once the relevant parameters for the attack are better understood.