Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

81–90 of 159 posts

Re: Backdoor found in a China-made US military chip

#81
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest. - kryptiskt, http://news.ycombinator.com/item?id=4030818 It has ac…

Does Taiwan count as part of China? A brief look at the Taiwan-China relationship shows it's a more difficult question than it initially seems

Re: Backdoor found in a China-made US military chip

#82
As a former chip designer I question the idea that the manufacturer introduced this backdoor (if indeed there is one).

found a previously unknown backdoor inserted by the manufacturer. This backdoor has a key...

It's hard to understand what this guy is talking about. Is he claiming that the manufacturer added additional hardware that the designers were unaware of? Or they made modifications to existing circuitry so it doesn't match the design? It would be very hard to do either without cooperation from the designers, especially given the paranoia of hardware engineers (and of defense hardware engineers, an entirely different level of paranoia). The question "are we manufacturing what we designed?" is one that is constantly asked throughout the lifetime of a part. In fact the answer, for individual parts, is often "no", because they can be defective. Still, the question is constantly asked with a variety of automated tools at all points of the manufacturing process.

Here's what I think he might have found: an additional fixed key introduced by the designers themselves into the chip, and having nothing special to do with the manufacturer. In other words, a deliberate backdoor.

Re: Backdoor found in a China-made US military chip

#83
post #22

The chip in question seems to be an Actel Microsemi ProASIC3 (PA3) [1,2], given the hints in the screenshot of the paper. [1] http://www.actel.com/products/pa3/ [2] http://www.actel.com/documents/pa3_faq.html (I guess there is no real advantage in keeping this obscured)

I see no mention of tamper-resistance/self-destruct features?

Power glitch detection, mechanisms to detect decapping/stripping, wire mesh shielding, protection against ultra-violet laser stimulation of transistors, ... are all important.

For those interested in further reading, Security Engineering[1] by Ross Anderson contains a section on chip security. Another paper[2] by Ross Anderson and Markus Kuhn (1996) provides additional background.

[1] https://www.cl.cam.ac.uk/~rja14/book.html

[2] https://www.cl.cam.ac.uk/~rja14/tamper.html

Re: Backdoor found in a China-made US military chip

#85
post #44

Earlier quoted context omitted.

...now you tell me. Political candidates should be required to sign the same stuff. And managers. And physicists. And PR stuntmen.

Why physicists?

I think that was meant as a reference either climate change scientists to cold fusion.

Re: Backdoor found in a China-made US military chip

#86

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

I simply do not believe one could find a "back door" looking at a chip in a SEM. It sounds to me like you are describing destructive physical analysis whose purpose is to make sure requisite manufacturing practices are being followed.

Re: Backdoor found in a China-made US military chip

#87

Earlier quoted context omitted.

I'm not sure I see the problem. They let the biggest debt buyer cut out the middle man. I'm sure there was some backroom dealing going on there, but it seems like the biggest losers there are the middlemen who wound up getting cut out.

The middle man was getting a cut anyway. It was mainly to make China's purchases secrete. Primary dealers are not allowed to charge customers money to bid on their behalf at Treasury auctions, so China isn't saving money by cutting out commission fees.

>make China's purchases secrete

Sometimes the typos are more fun than the whole thread.

Re: Backdoor found in a China-made US military chip

#88
1. you dont buy your military stuff from a potential enemy 2. US (and everybody) was (and probably still is) doing exactly the same. I do remember a scandal in the 80' concerning telephone systems sold behind the Iron Curtain by the US that could be kill remotely by an inner kill switch.

Re: Backdoor found in a China-made US military chip

#89
post #86

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

I simply do not believe one could find a "back door" looking at a chip in a SEM. It sounds to me like you are describing destructive physical analysis whose purpose is to make sure requisite manufacturing practices are being followed.

The way I read that is that they make the designs and look for circuitry that does not match the designs, which is presumed to be backdoors. I would think that defects and intentional backdoors would both be findable on an SEM. Do you think otherwise? I don't have a ton of experience with bare silicon, so I'd be interested to know if that's unreasonable.

Re: Backdoor found in a China-made US military chip

#90

Earlier quoted context omitted.

I'm not sure I see the problem. They let the biggest debt buyer cut out the middle man. I'm sure there was some backroom dealing going on there, but it seems like the biggest losers there are the middlemen who wound up getting cut out.

The middle man was getting a cut anyway. It was mainly to make China's purchases secrete. Primary dealers are not allowed to charge customers money to bid on their behalf at Treasury auctions, so China isn't saving money by cutting out commission fees.

If they were going through (presumably) private middle men, then were their purchases = a matter of public record in the first place?
Post reply on HN