Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

61–70 of 159 posts

Re: Backdoor found in a China-made US military chip

#61
post #36

"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest.

Is there any way to mangle it to being true? I don't think so. Maybe 99% of volume, but not type, is produced in China. Or 99% of types are made in China, but with volume elsewhere. Maybe 99% of this particular IC family are made in China, with the rest being made elsewhere is something that works.

I'm sure places like Japan, Korea, Taiwan etc make more than 1%, regardless of type vs volume.

The 99% does strike me as something that was thumbsucked.

Re: Backdoor found in a China-made US military chip

#62
post #57

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! Where else are they going to get the chips in the quantities required since the US outsourced most of its commercial silicon foundries? Of the few remaining in the US, the largest is wholly owned by the Taiwanese company TSMC. Post-industrial economics is idiotic, and this is one of the major examples of…

> Post-industrial economics is idiotic, and this is one of the major examples of why.

You say that like the US Military (among other US and non-US government victims) doesn't have the ability to dictate sourcing of parts to the point of driving the growth of domestic foundries.

This looks more like poor decision making, not a fact of "post-industrial economics".

Re: Backdoor found in a China-made US military chip

#63
post #24

"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest.

To add, silicon can, and obviously is inspected by manufacturer using optical and electronic microscopes. There are companies specialized in reverse engineering chips or verifying existing components. Even hobbyists can grind down chips and figure out what the circuitry does, using nothing more than good optics and a digital camera plus freely available software to stitch the images together and start analyzing trace…

I've seem to recall something regarding this. The manufacturer has the exact blueprints to help guide them. Reverse engineers can't rely on the blueprints because they might be comprised.

Re: Backdoor found in a China-made US military chip

#64

Can somebody explain exactly what they got access to? What is encrypted?

I'm going to put my speculation hat on here. Others here have mentioned that the chip in question is an Actel FPGA.

First, we must understand what these are used in: embedded systems. Typically, at the heart of most embedded systems you have two possibilities: a microcontroller or microprocessor, or an FPGA. The microcomputers run some kind of firmware (instruction set fed to a processor architecture) which is completely different then an FPGA which are actually re-configurable transistor arrays to implement fixed digital logic. This transistor configuration is typically loaded from EEPROM on power up - so it is stored/uploaded by a user somewhere after they've done some work in their CAD tool.

In either case, whether it be firmware written for a microprocessor based system, or the "firmware" for an FPGA (I forget what that logic routing configuration format is called - technically not firmware since it's not instructions) it is likely that whoever wrote it would want to protect it from being read or protect their device from having another firmware loaded on. There are many schemes to do so, it is possible that this is what has been compromised.

Re: Backdoor found in a China-made US military chip

#65
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China),"

That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest.

- kryptiskt, http://news.ycombinator.com/item?id=4030818

It has actually not been "very easy" for me to verify this, but I did find something saying that in 2009, China had 9% of the world's production capacity, which makes me strongly doubt that they are now 99% of the actual manufacturing amount: http://www.manufacturingnews.com/news/10/0212/semiconductors...

@tptacek: Care to provide references for why Cambridge Security Lab is as big a deal as you're making them out to be, and why we should overlook this blatantly exaggerated fact they cited?

Re: Backdoor found in a China-made US military chip

#66
Several months ago there was a report of similar nature that mainstream Intel CPUs include a concealed (hyper-)hypervisor that appears to exist in China-produced chips, but absent from pre-production samples made by Intel themselves. I don't know where this all went, but it was some Russian guy who found it by accident, and he was largely dismissed as a loon and generally laughed at (though from I could tell he did know a thing or two about hypervisors, system programming and what not).

Re: Backdoor found in a China-made US military chip

#67
post #30

Earlier quoted context omitted.

Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…

I assume most people on HN don't follow security and might not be familiar with the University of Cambridge's security program. Having said that, I take issue with almost every point you made: * Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actual…

[deleted]

Re: Backdoor found in a China-made US military chip

#68
post #37

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

Hopefully this isn't too political for HN, but I suggest combining your surprise with the news that China was given a direct line around Wall Street to buy Treasuries directly from the USG: http://www.reuters.com/article/2012/05/21/us-usa-treasuries-... There's a relationship here.

> "China was given a direct line around Wall Street to buy Treasuries directly from the USG"

This isn't particularly surprising - several large "real money" investors (pensions and the like) have had this sort of relationship with the Treasury. It enabled them to directly place bids on Treasury issuance without going through Primary broker-dealers (Wall Street). They were called "Directs" and would bid through the "TreasuryDirect" system.

Basically enabled the largest investors in USG securities to bypass the "commissions" other investors would pay to Wall Street firms.

I'm guessing that for some reason foreign accounts such as governments and sovereign funds had not been given access to this system for some reason, and after a point, the Chinese government investment funds (which are some of the largest in the world both in terms of funds managed and funds committed to the US) laid bare the inconsistency that they'd been disallowed this, simply on the grounds of being foreign.

Otherwise unremarkable.

Re: Backdoor found in a China-made US military chip

#69
Evidently, the military prefers to cut cost rather than have complete control over the manufacturing of their computer chips. Spending hundreds of millions on jets that have to be American-made is fine, but it's on the computer chips powering those jets and pretty much all advanced military technology that they have to save money.

Re: Backdoor found in a China-made US military chip

#70
Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing.

There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a copy of all the traffic. Is it a cyberwar beach head? Probably not. Could it be exploited in an attack? Probably. Of course if someone tried to route all that traffic outside the network into the transit network it would be pretty obvious. So not a good scenario.

Like the controller back door article on Ars last month I suspect most of these things are diagnostic aids. You ask an engineer to test something and that something is buried inside a bunch of silicon and the only way to do that is to build some stuff in there that lets you look at things.

Of course you can do this in a 'smart' way, and in a 'stupid' way. When I started at Intel there were extra pads on the silicon that got to these extra functions, you ordered a 'bond-out' chip where bonding wires (between the chip pins and the silicon) would be attached. All of the in circuit emulators up to the 386 had a 'bond out' version in the emulator pod that gave you access to internal state of the chip. Others have pointed out the key for loading replacement microcode, another 'feature' to fix bugs in the field and do diagnostics.

So things which require either 'special' chips or attaching a JTAG probe directly to the part, are generally ok in my book. Once you have physical access nearly all bets are off.

Its an expensive way to compromise the enemy. Simpler to just build a piece of gear that looks and operates exactly like the original but is your own design. There was some counterfeit Cisco boxes like this in the channel for a bit. Of course they 'fail' when you update IOS and it fails. Still the cost to exploit is lower and more assured than back dooring silicon in a fab.

Its also pretty hard to add features to a chip without the designer of the chip in on the game. Every transistor is accounted for by long verification and analysis so 'extra' ones would show up. That limits the risk to a chip manufacturer being the 'bad guy' (and they are very traceable so unlikely to do that)

None of this though should take away from the excellent work Cambridge is doing. The silicon analysis is really cutting edge stuff, and I think it would be useful for chip designers in verifying their masks are accurate too. If you could effectively 'decompile' the resulting silicon and verify it against your netlist, that would catch mask errors. And that would save anywhere from $100,000 to $2,000,000 depending on size of the mask.

Post reply on HN