Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

41–50 of 159 posts

Re: Backdoor found in a China-made US military chip

#41
post #16
post #8

The language used in this article seems very much like the author has something to sell and is trying to create the impression that it is advanced and mysterious. The claims about improvements of many orders of magnitude in speed and cost as well as the unavailability of information and services to private individuals suggest to me that someone is trying to get a defense contract for some overhyped technology that wo…

Backdoors --- intentional, accidental, or (most typically) "deniably" accidental --- are extremely common in software of all kinds, from RTOS kernels to web stacks to third-party database wrapper libraries. Are there backdoors in silicon? Of course there are backdoors in silicon. Just like in software, most of them will be deniably accidental. It's unlikely we'll be able to trace most of them to deliberate sabotage,…

I'm only going based on the tone of the writing and the content of the patent application; both are written like hype. He might actually be doing something novel, or he might just be trying to get attention for his company and not doing anything special relative to others in the field. There may be good reasons to avoid talking about details in his field, but when someone selling something does that, hype is a reasonable default explanation.

Re: Backdoor found in a China-made US military chip

#42
post #16
post #8

The language used in this article seems very much like the author has something to sell and is trying to create the impression that it is advanced and mysterious. The claims about improvements of many orders of magnitude in speed and cost as well as the unavailability of information and services to private individuals suggest to me that someone is trying to get a defense contract for some overhyped technology that wo…

Backdoors --- intentional, accidental, or (most typically) "deniably" accidental --- are extremely common in software of all kinds, from RTOS kernels to web stacks to third-party database wrapper libraries. Are there backdoors in silicon? Of course there are backdoors in silicon. Just like in software, most of them will be deniably accidental. It's unlikely we'll be able to trace most of them to deliberate sabotage,…

To paraphrase Fight Club:

"Look, the people you are after are the people you depend on. We boot your servers, we back up your drives, we write your applications, we maintain your kernels. We guard your data. Do not... fuck with us. "

Having set the stage, consider: the competency required to manually evaluate silicon packages is extraordinarily rare. Even if you wanted to shell out 6 figures for a competent superficial evaluation, you'd have a lot of trouble finding available Chris Tarnovskys to do the work.

Could secure hardware be bootstrapped? Could we use the embarrassment of riches we have in terms of number of transistors available to implement arrays of small and fast processors which can emulate security hardware and be programmed using formal verification? This way, we could concentrate all of our scrutiny on one unit, and change much of the hardware problem into a software one. It wouldn't be as fast or as cheap, but it might be fast enough and workably secure.

Re: Backdoor found in a China-made US military chip

#43
post #34

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

I think the problem is that there are too many suppliers. Everyone wants to be a middle-man. If the government asks for domestic parts from it's big contractors, the big ones ask their small ones, and they ask theirs and so on. But at the end of the day someone realizes it's cheaper to outsource it - does so - and forges the documentation. As the part travels all the way back up the chain each one says it's domestic.…

The chain is audited regularly.

A manufacturer outsourcing stuff has a hell of a lot of documentation to forge. Each screw, each washer, each resistor, has a batch number that it can be traced to.

Re: Backdoor found in a China-made US military chip

#44
post #34

Earlier quoted context omitted.

I think the problem is that there are too many suppliers. Everyone wants to be a middle-man. If the government asks for domestic parts from it's big contractors, the big ones ask their small ones, and they ask theirs and so on. But at the end of the day someone realizes it's cheaper to outsource it - does so - and forges the documentation. As the part travels all the way back up the chain each one says it's domestic.…

They need custody chain management. I assumed they had one. And everyone who signed for it has securety clearance meaning they signed a paper that basically says "I understand that I'll go to jail for twenty years if I'm caught lying about anything".

...now you tell me. Political candidates should be required to sign the same stuff. And managers. And physicists. And PR stuntmen.

Re: Backdoor found in a China-made US military chip

#45
Two thoughts:

1) Say what you will about the military-industrial complex, but they do buy a load of physical products. When those are sourced domestically it has a lot of good spillover effects on the rest of the industry (see Steve Blank's Secret History of Silicon Valley).

2) I'd be far more worried about Intel, AMD, nVidia, Texas Instruments, et al, especially if I was a foreign procurement officer. The logic in those chips is incredibly complex and almost impossible to verify in any detail by a third party. Coincidentally, they're all US companies.

Re: Backdoor found in a China-made US military chip

#46
post #37

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

Hopefully this isn't too political for HN, but I suggest combining your surprise with the news that China was given a direct line around Wall Street to buy Treasuries directly from the USG: http://www.reuters.com/article/2012/05/21/us-usa-treasuries-... There's a relationship here.

I'm not sure I see the problem. They let the biggest debt buyer cut out the middle man. I'm sure there was some backroom dealing going on there, but it seems like the biggest losers there are the middlemen who wound up getting cut out.

Re: Backdoor found in a China-made US military chip

#47

Hardware trust is something I've been wondering about for a while now. It's easy to hide a software bug. (As evidenced by the occasional blue moon story about somebody stumbling over one.) But a hardware bug just seems like a constant paranoia that can never be investigated without expensive tooling.

There's a bit of research going into this area right now. Verification strategies for hardware, etc. Another way around it is to bump up your integration of trusted FPGA platforms where you can write and use your own hardware in a potentially more trustworthy way.

Re: Backdoor found in a China-made US military chip

#48
post #6

The fact that he's pleading for money as he makes these claims makes me suspicious of them. He needs to provide more specific information and evidence.

I think he works in a domain where a lot of these things are accepted by his colleagues as fact. Judging by the way this website is laid out, the general public is not his audience.

Re: Backdoor found in a China-made US military chip

#49
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

Cisco has been fighting with the Chinese over imitation network gear (branded as Cisco) for years. So rest assured that the switches are all backed-doored too. It's a big problem. Really, tribes out to forge their weapons at home.

Re: Backdoor found in a China-made US military chip

#50
post #37

Earlier quoted context omitted.

Hopefully this isn't too political for HN, but I suggest combining your surprise with the news that China was given a direct line around Wall Street to buy Treasuries directly from the USG: http://www.reuters.com/article/2012/05/21/us-usa-treasuries-... There's a relationship here.

I'm not sure I see the problem. They let the biggest debt buyer cut out the middle man. I'm sure there was some backroom dealing going on there, but it seems like the biggest losers there are the middlemen who wound up getting cut out.

The middle man was getting a cut anyway. It was mainly to make China's purchases secrete.

  Primary dealers are not allowed to charge 
  customers money to bid on their behalf at Treasury    
  auctions, so China isn't saving money by cutting out 
  commission fees.
Post reply on HN