If it is from Actel, then it is CMMI certified :) www.cl.cam.ac.uk/~sps32/SG_talk_BA.pdf
Backdoor found in a China-made US military chip
21–30 of 159 posts
Re: Backdoor found in a China-made US military chip
#22[1] http://www.actel.com/products/pa3/ [2] http://www.actel.com/documents/pa3_faq.html
(I guess there is no real advantage in keeping this obscured)
Re: Backdoor found in a China-made US military chip
#23I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-series logic which can pretty much be assumed to be inert. Samples were regularly decapped and scanned using an SEM to verify to make sure the vendors weren't screwing us or integrating backdoors.
Every part was asset managed to hell as well. Every part was traceable to the point that every finger that poked it was known (I moved from engineering to writing the asset management systems before leaving).
Crazy.
Re: Backdoor found in a China-made US military chip
#24"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest.
Sure, this stuff gets harder with modern technology, but it would be ridiculous to assume that manufacturers blindly click together chips and hope for the best because they can't inspect their work.
Re: Backdoor found in a China-made US military chip
#25Show me some source, a schematic, or a technique that you're using, and then I might believe you, otherwise this is just FUD. They didn't even name the bloody chip.
Re: Backdoor found in a China-made US military chip
#26The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
Re: Backdoor found in a China-made US military chip
#27The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…
Re: Backdoor found in a China-made US military chip
#28The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
"These are good guys. This paper is the real deal."
I appreciate what you bring to HN, but that this is the top comment worries me, particularly when it comes to security of all things. There's valuable comments that are contrary to your opinion surrounding you, and I wish you'd explain your side a bit more clearly in cases like this.
Re: Backdoor found in a China-made US military chip
#29Re: Backdoor found in a China-made US military chip
#30The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…
Having said that, I take issue with almost every point you made:
* Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actually has an open source package to help do it. There's nothing incredible about that claim.
* I'm not sure I follow how the most famous act of computer-aided industrial espionage isn't germane to hardware backdoors. Researchers put their work into context so people outside the field will take it seriously.
* The military uses Microsoft Windows and Red Hat Linux, too, both of which are general-purpose packages. You think a universally distributed backdoor in either that had escaped detection until 2012 wouldn't be relevant to national security?
* Go read Tarnovsky's blog, where he has blogged about extracting keys from silicon.
The only point you've made here that I agree with is that the attack/activation surface of these illicit features is likely to be more important than anything else.