Live data from Hacker News

Three Ways to Hack a Printed Circuit Board

spectrum.ieee.org

11–13 of 13 posts

Re: Three Ways to Hack a Printed Circuit Board

#11
post #10
post #7

Seems insufficient that the conclusion is just to check the received board against the schematic and BOM.

It is not, but having access to schematics, bom and description of how it works would mean more people looking at it and probing it. This would be helpful in preventing large scale attacks to go for a long time but would not prevent directed attacks (like infecting a single shipment to a single customer). Also, I always thought bypass capacitors an excellent way to inject malicious hardware. Everybody is practically…

>Also, I always thought bypass capacitors an excellent way to inject malicious hardware. Everybody is practically trained to ignore them and does not expect them to do anything. Yet they have access to almost all signal lines and technically possibility to inject or disrupt signal.

Call me jaded but the fact that Bloomberg essentially made a fake report about this type of attack made me completely disinterested in this type of attack. It's just some sensationalist crap that is meant to destroy the reputation of a company. It was never about the practicality of the attack. Just replace an entire IC and be done with it.

It's easy to image an Amazon seller replacing a microcontroller with one that contains ransomware. If you try to do the same thing with a bypass capacitor then you massively increase the amount of effort needed to execute the attack. The microcontroller attack could be as simple as emulating a keyboard and opening a virus site in internet explorer.

I don't know how many people actually pay the ransom but lets say 5% of the buyers end up paying a $500 ransom. That would be $25 extra profit per mainboard. If your mainboard is $10 cheaper than the competition customers will flock to your products and you can easily scale out your operation.

Re: Three Ways to Hack a Printed Circuit Board

#12
post #10

Earlier quoted context omitted.

It is not, but having access to schematics, bom and description of how it works would mean more people looking at it and probing it. This would be helpful in preventing large scale attacks to go for a long time but would not prevent directed attacks (like infecting a single shipment to a single customer). Also, I always thought bypass capacitors an excellent way to inject malicious hardware. Everybody is practically…

>Also, I always thought bypass capacitors an excellent way to inject malicious hardware. Everybody is practically trained to ignore them and does not expect them to do anything. Yet they have access to almost all signal lines and technically possibility to inject or disrupt signal. Call me jaded but the fact that Bloomberg essentially made a fake report about this type of attack made me completely disinterested in th…

Well... this doesn't have to be as overt as you described.

For example, bypass cap could monitor the line and detect when a security feature to prevent tampering with the device turns on and just disrupt that feature. Or maybe it could prevent the phone from turning off when it should to keep that pesky covert monitoring software running even after you think you have switched your phone off. Or maybe it will cause camera light to be turned off when a particular radio signal is detected so that you don't know you are watched. Dunno.

Just because Bloomberg report turned out to be fake doesn't necessarily mean the attack vector is fake or pointless.

There are millions of engineers/hackers smarter than me and I can imagine somebody will put together a working and useful attack, eventually.

Re: Three Ways to Hack a Printed Circuit Board

#13
post #8

Authors propose to mess with circuit board runs by adding components and modifying connections. There is no security on the design files, so they are trivially modified, though it is annoying to do so if you don't have the original design files. The outputs - Gerbers or ODB++ databases - can be imported into a design tool and modified. They also propose to detect such changes by looking for missing refdes. That's far…

APT?

APT is an Advanced Persistent Threat, or more casually known as a good hacking group. :)
Post reply on HN