Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

1–10 of 159 posts

Re: Backdoor found in a China-made US military chip

#3

Can somebody explain exactly what they got access to? What is encrypted?

"This backdoor has a key, which we were able to extract. If you use this key you can disable the chip or reprogram it at will, even if locked by the user with their own key."

From this, I'd say that anyone who used the backdoor would basically be able to take over the chip completely. Which is somewhat scary, considering the author says it's used in weapons systems—hopefully the author's informed an intelligence agency with the specifics.

Re: Backdoor found in a China-made US military chip

#8
The language used in this article seems very much like the author has something to sell and is trying to create the impression that it is advanced and mysterious. The claims about improvements of many orders of magnitude in speed and cost as well as the unavailability of information and services to private individuals suggest to me that someone is trying to get a defense contract for some overhyped technology that won't really deliver what's promised.

Edit: they seem to have submitted a patent application for the process of sending test signals to a chip and monitoring it with an oscilloscope: http://www.sumobrain.com/patents/wipo/Integrated-circuit-inv...

Re: Backdoor found in a China-made US military chip

#9

Can somebody explain exactly what they got access to? What is encrypted?

Taken from text: "This particular chip is prevalent in many systems from weapons, nuclear power plants to public transport. In other words, this backdoor access could be turned into an advanced Stuxnet weapon to attack potentially millions of systems."

Re: Backdoor found in a China-made US military chip

#10

Can somebody explain exactly what they got access to? What is encrypted?

This particular chip is prevalent in many systems from weapons, nuclear power plants to public transport. In other words, this backdoor access could be turned into an advanced Stuxnet weapon to attack potentially millions of systems.

From the description I'm guessing an interface device that does something in the order of I2C/CAN/M on one end and external comms to the outside world on the other (why else would require "sophisticated encryption standard").

Post reply on HN