Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

71–80 of 159 posts

Re: Backdoor found in a China-made US military chip

#71
This appears to be an improvement on Differential Power Analysis attack against a FPGA. Congrats to the guys who discovered it!

It's interesting to note that in the DPA/SPA world the standard model of operation is to develop a new attack and then patent the countermeasures ;)

It should be noted that this is "probably" not a backdoor in the traditional sense (intentionally planted by some nefarious government organisation), rather just bad, leaky design that has been identified by an improved attack methodology...

Re: Backdoor found in a China-made US military chip

#72
post #27

Earlier quoted context omitted.

Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…

If I had to guess, he's being funded by the military and he is definitely fishing for money. I've seen the same kind of language before. On the other hand, as the parent comment said, these researchers are reputable and we should assume that they've actually found something. This report was just written for a different audience (generals, not engineers).

This comment makes the most sense, in an interesting thread.

Re: Backdoor found in a China-made US military chip

#73
post #68
post #37

Earlier quoted context omitted.

Hopefully this isn't too political for HN, but I suggest combining your surprise with the news that China was given a direct line around Wall Street to buy Treasuries directly from the USG: http://www.reuters.com/article/2012/05/21/us-usa-treasuries-... There's a relationship here.

> "China was given a direct line around Wall Street to buy Treasuries directly from the USG" This isn't particularly surprising - several large "real money" investors (pensions and the like) have had this sort of relationship with the Treasury. It enabled them to directly place bids on Treasury issuance without going through Primary broker-dealers (Wall Street). They were called "Directs" and would bid through the "T…

How do you balance that with the post below that the commissions you identify aren't allowed to be charged for these kinds of transactions?

Re: Backdoor found in a China-made US military chip

#74
post #57

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! Where else are they going to get the chips in the quantities required since the US outsourced most of its commercial silicon foundries? Of the few remaining in the US, the largest is wholly owned by the Taiwanese company TSMC. Post-industrial economics is idiotic, and this is one of the major examples of…

Senate Armed Services Report: http://armed-services.senate.gov/Publications/Counterfeit%20...

Re: Backdoor found in a China-made US military chip

#75
post #41
post #16

Earlier quoted context omitted.

Backdoors --- intentional, accidental, or (most typically) "deniably" accidental --- are extremely common in software of all kinds, from RTOS kernels to web stacks to third-party database wrapper libraries. Are there backdoors in silicon? Of course there are backdoors in silicon. Just like in software, most of them will be deniably accidental. It's unlikely we'll be able to trace most of them to deliberate sabotage,…

I'm only going based on the tone of the writing and the content of the patent application; both are written like hype. He might actually be doing something novel, or he might just be trying to get attention for his company and not doing anything special relative to others in the field. There may be good reasons to avoid talking about details in his field, but when someone selling something does that, hype is a reason…

[deleted]

Re: Backdoor found in a China-made US military chip

#76
post #22

The chip in question seems to be an Actel Microsemi ProASIC3 (PA3) [1,2], given the hints in the screenshot of the paper. [1] http://www.actel.com/products/pa3/ [2] http://www.actel.com/documents/pa3_faq.html (I guess there is no real advantage in keeping this obscured)

Ouch, as it would be quite easy to think that you are "safe" if you spin your own processor from scratch and run it on an FPGA.

Who's to say that manufacturing in China means the backdoor was injected by China? I would have thought the US is just as likely a source, given that the design came from there. Surely the US government would love having access to FPGAs in foreign systems?

The cynic in me says that Cambridge needs to keep poking, as they might find two backdoors: one inserted by the US, the other by China.

Re: Backdoor found in a China-made US military chip

#77
post #6

The fact that he's pleading for money as he makes these claims makes me suspicious of them. He needs to provide more specific information and evidence.

Last week a report was released that revealed 1800 cases during a 1-year survey. [pdf] This is just one device, he has good reasons to advertise his expertise. [pdf] http://www.armed-services.senate.gov/Publications/Counterfei...

1800 cases of counterfeit parts, not 1800 cases of maliciously designed parts. There could well be malice involved, but the vast majority of those cases were almost certainly economically motivated.

Re: Backdoor found in a China-made US military chip

#78
post #35
post #6

The fact that he's pleading for money as he makes these claims makes me suspicious of them. He needs to provide more specific information and evidence.

He's an academic in England. Of course he's going to try to monetise his research.

That doesn't make it any less suspect.

Re: Backdoor found in a China-made US military chip

#79
post #57

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! Where else are they going to get the chips in the quantities required since the US outsourced most of its commercial silicon foundries? Of the few remaining in the US, the largest is wholly owned by the Taiwanese company TSMC. Post-industrial economics is idiotic, and this is one of the major examples of…

You can get anything made in the US, it just may cost an egregious amount. The military will do it without batting an eye.

We (government contractor) pay a bunch extra to buy tools made in the US - even if they aren't normally manufactured here - just to satisfy the buy US provisions.

Typically what happens is that a subcontractor says it is US made, and then outsources to a foreign country and pockets the difference. Obviously there is money to be made there.

However, that is defrauding the government and those subcontractors can/will/do go to federal prison.

Re: Backdoor found in a China-made US military chip

#80
post #27

Earlier quoted context omitted.

Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…

If I had to guess, he's being funded by the military and he is definitely fishing for money. I've seen the same kind of language before. On the other hand, as the parent comment said, these researchers are reputable and we should assume that they've actually found something. This report was just written for a different audience (generals, not engineers).

Definitely written for generals, but if the claims are true (and it wouldn't be difficult for a general to send and engineer to check it out and report back), they definitely should be thrown some money for more research
Post reply on HN