Earlier quoted context omitted.
Backdoors --- intentional, accidental, or (most typically) "deniably" accidental --- are extremely common in software of all kinds, from RTOS kernels to web stacks to third-party database wrapper libraries. Are there backdoors in silicon? Of course there are backdoors in silicon. Just like in software, most of them will be deniably accidental. It's unlikely we'll be able to trace most of them to deliberate sabotage,…
I'm only going based on the tone of the writing and the content of the patent application; both are written like hype. He might actually be doing something novel, or he might just be trying to get attention for his company and not doing anything special relative to others in the field. There may be good reasons to avoid talking about details in his field, but when someone selling something does that, hype is a reason…
Backdoor found in a China-made US military chip
91–100 of 159 posts
Re: Backdoor found in a China-made US military chip
#92The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…
Hopefully this isn't too political for HN, but I suggest combining your surprise with the news that China was given a direct line around Wall Street to buy Treasuries directly from the USG: http://www.reuters.com/article/2012/05/21/us-usa-treasuries-... There's a relationship here.
Re: Backdoor found in a China-made US military chip
#93Earlier quoted context omitted.
You caught me. I'm a secret shill for Ross Anderson.
That wasn't the gist of my comment, but okay. I'm disappointed that you feel the rest of my comment wasn't worth your time, and you chose to attach to a throwaway hypothetical. Alas, it was worth a shot.
Re: Backdoor found in a China-made US military chip
#94Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing. There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a…
http://blogs.cisco.com/news/cisco_and_apple_agreement_on_ios...
Re: Backdoor found in a China-made US military chip
#95Earlier quoted context omitted.
The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! Where else are they going to get the chips in the quantities required since the US outsourced most of its commercial silicon foundries? Of the few remaining in the US, the largest is wholly owned by the Taiwanese company TSMC. Post-industrial economics is idiotic, and this is one of the major examples of…
> Post-industrial economics is idiotic, and this is one of the major examples of why. You say that like the US Military (among other US and non-US government victims) doesn't have the ability to dictate sourcing of parts to the point of driving the growth of domestic foundries. This looks more like poor decision making, not a fact of "post-industrial economics".
[edit] Wouldn't claiming that post-industrial economics is not the problem, by suggesting a course of military funded industrial economics as the solution, not be agreeing with the point that post-industrial economics is the problem, even while claiming otherwise?
Re: Backdoor found in a China-made US military chip
#96Re: Backdoor found in a China-made US military chip
#97Earlier quoted context omitted.
That wasn't the gist of my comment, but okay. I'm disappointed that you feel the rest of my comment wasn't worth your time, and you chose to attach to a throwaway hypothetical. Alas, it was worth a shot.
I find it exhausting to have to write things defensively just to ward off drama. The fact that I had to offer was very simple: that the security group at Cambridge is very credible. And you knew that, because you acknowledged in your comment. I'm left wondering why you commented at all.
It isn't just this particular instance that is driving my comment (in which I acknowledge your reputation, and nobody else's, a small oversight in your reply). The driving force is more your showing up in threads, saying something either plainly obvious or, worse, absolutely confusing, and then expecting your reputation to carry your comment the rest of the way. Most of the time, the reasoning behind your comment is completely unclear. It isn't avoiding drama to elaborate, it's making your point clearer and not relying upon a name you've created for yourself in this community when the rationale behind your opinion is unclear to those of us without your ability. The other comment that annoyed me recently, and most front of mind, was this one about nginx[1]:
"This is a very bad bug, and you should fix it ASAP. Don't wait."
Two things here:
1. Thank you, Captain Obvious. What an enlightening comment.
2. What does "very bad" mean?
The actual situation related to that vulnerability was much more complex, and the threat fairly small. You, however, glossed right over that and skipped to basically informing the lay to panic, then got really snarky when people questioned you on the motivation. I don't believe that making the lay panic is the right way to achieve greater security, regardless of your credentials, and this is one of those cases where the reasoning behind your comment would have gone a long way.Think about what a novice admin walks away from that comment with. Yes, he upgrades, awesome. That's exactly what we expect of administrators. There's something more sinister underlying your end result, though, which is that you've trained an administrator to act on what you and other security professionals say when it comes to security, without any explanation or reason. Security would be a much better place if people started gaining the ability to think for themselves and understand the issue, and you're working to reverse that. I see this crap with bcrypt, too. "Just use bcrypt." "Why?" "Because smart people said so." Now what if you fuck up? What if you give bad advice?[2] Half of this community is going to take you at face value, because you don't present supporting facts for your position to be debated openly. Because it's 'tiring'.
You are quite unmatched in the security arena with your technical prowess. There's no question of that. It's comments like these, however, that make me annoyed that you're using said reputation inappropriately, and any questioning you receive on the matter leads to single-sentence snark like the pointless gray comment in this thread. Before asking why I commented, consider your own comments and the different standard you hold your own commentary to in this forum.
[1]: http://news.ycombinator.com/item?id=3709269
[2]: I fully expect a snarky reply to this hypothetical, so make it good.
Re: Backdoor found in a China-made US military chip
#98Re: Backdoor found in a China-made US military chip
#99But, this Frienemy war is not about taking advantage of these backdoors. That is the nuclear option. The war is about who has the potential to pwn the other.
BTW- I'm typing this on a Chinese netbook.
Re: Backdoor found in a China-made US military chip
#100Earlier quoted context omitted.
I simply do not believe one could find a "back door" looking at a chip in a SEM. It sounds to me like you are describing destructive physical analysis whose purpose is to make sure requisite manufacturing practices are being followed.
The way I read that is that they make the designs and look for circuitry that does not match the designs, which is presumed to be backdoors. I would think that defects and intentional backdoors would both be findable on an SEM. Do you think otherwise? I don't have a ton of experience with bare silicon, so I'd be interested to know if that's unreasonable.
In the cross section case you are going to see a few dozen transistors out of the millions in a design of any complexity.
It would be remotely feasible to discover some sort of shenanigans if you knew the exact layout of the design, which would basically mean you are a foundry yourself. In that case you might get lucky and spot some difference between the mask you made, and the mask that was used to produce the part under inspection.
But the scales involved make this not believable to me. It would be roughly like scanning the whole of, say, America, and checking every street and intersection of every town, and comparing it against some known quantity to see if something changed in Springfield Missouri.
Maybe somebody could automate this, but the chemical processes for removing layers is less than perfect. Those strands of metal stretching across the ASIC have some built in tension, and if you remove the layer of glass above them, then tend to spring up and jumble. Good luck trying to do something with that.