Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

21–30 of 159 posts

Re: Backdoor found in a China-made US military chip

#23
The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually.

I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-series logic which can pretty much be assumed to be inert. Samples were regularly decapped and scanned using an SEM to verify to make sure the vendors weren't screwing us or integrating backdoors.

Every part was asset managed to hell as well. Every part was traceable to the point that every finger that poked it was known (I moved from engineering to writing the asset management systems before leaving).

Crazy.

Re: Backdoor found in a China-made US military chip

#24

"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest.

To add, silicon can, and obviously is inspected by manufacturer using optical and electronic microscopes. There are companies specialized in reverse engineering chips or verifying existing components. Even hobbyists can grind down chips and figure out what the circuitry does, using nothing more than good optics and a digital camera plus freely available software to stitch the images together and start analyzing traces from the picture.

Sure, this stuff gets harder with modern technology, but it would be ridiculous to assume that manufacturers blindly click together chips and hope for the best because they can't inspect their work.

Re: Backdoor found in a China-made US military chip

#25
TL; DR - No proof / source code / details on the backdoor - Outlandish claims of this being a "stuxnet" weapon

Show me some source, a schematic, or a technique that you're using, and then I might believe you, otherwise this is just FUD. They didn't even name the bloody chip.

Re: Backdoor found in a China-made US military chip

#26
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

I would assume that the most likely attack would be for a country to buy weapons containing this chip and reading out the firmware using the backdoor.

Re: Backdoor found in a China-made US military chip

#27
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…

If I had to guess, he's being funded by the military and he is definitely fishing for money. I've seen the same kind of language before. On the other hand, as the parent comment said, these researchers are reputable and we should assume that they've actually found something. This report was just written for a different audience (generals, not engineers).

Re: Backdoor found in a China-made US military chip

#28
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

I'm respectful of your qualifications, but annoyed when you use your credentials without qualification. A paranoid man might assume your comments are strategically placed to benefit parties you're aligned with, based on how little context there is here; I know better, others might not.

"These are good guys. This paper is the real deal."

I appreciate what you bring to HN, but that this is the top comment worries me, particularly when it comes to security of all things. There's valuable comments that are contrary to your opinion surrounding you, and I wish you'd explain your side a bit more clearly in cases like this.

Re: Backdoor found in a China-made US military chip

#29
post #17

If it is from Actel, then it is CMMI certified :) www.cl.cam.ac.uk/~sps32/SG_talk_BA.pdf

Yeah, there's enough info on the scan to figure out the part family.

...its more fun than reading the keys (CB21 5DQ) from FLASH:

Helion Technology Limited -- Helion Technology.

Re: Backdoor found in a China-made US military chip

#30
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…

I assume most people on HN don't follow security and might not be familiar with the University of Cambridge's security program.

Having said that, I take issue with almost every point you made:

* Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actually has an open source package to help do it. There's nothing incredible about that claim.

* I'm not sure I follow how the most famous act of computer-aided industrial espionage isn't germane to hardware backdoors. Researchers put their work into context so people outside the field will take it seriously.

* The military uses Microsoft Windows and Red Hat Linux, too, both of which are general-purpose packages. You think a universally distributed backdoor in either that had escaped detection until 2012 wouldn't be relevant to national security?

* Go read Tarnovsky's blog, where he has blogged about extracting keys from silicon.

The only point you've made here that I agree with is that the attack/activation surface of these illicit features is likely to be more important than anything else.

Post reply on HN