Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

121–130 of 159 posts

Re: Backdoor found in a China-made US military chip

#121

Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing. There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a…

I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…

The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.

Re: Backdoor found in a China-made US military chip

#122

Earlier quoted context omitted.

I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…

The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.

Does the NSA have its own fabs to keep back doors out or to keep secrets in?

Re: Backdoor found in a China-made US military chip

#123
post #18

It is trivial for manufacturers to sneak backdoors into chips. It is improbable to keep backdoors a secret. People aren't good at keeping secrets.

So, 100% of the backdoors I've ever heard about were not kept secret, therefore backdoors are unlikely to be kept secret. :-)

Re: Backdoor found in a China-made US military chip

#124
post #43
post #34

Earlier quoted context omitted.

I think the problem is that there are too many suppliers. Everyone wants to be a middle-man. If the government asks for domestic parts from it's big contractors, the big ones ask their small ones, and they ask theirs and so on. But at the end of the day someone realizes it's cheaper to outsource it - does so - and forges the documentation. As the part travels all the way back up the chain each one says it's domestic.…

The chain is audited regularly. A manufacturer outsourcing stuff has a hell of a lot of documentation to forge. Each screw, each washer, each resistor, has a batch number that it can be traced to.

[deleted]

Re: Backdoor found in a China-made US military chip

#125

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

There is still a lot of semiconductor manufacturing in the US.

http://en.wikipedia.org/wiki/List_of_semiconductor_fabricati...

Re: Backdoor found in a China-made US military chip

#126
post #122

Earlier quoted context omitted.

The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.

Does the NSA have its own fabs to keep back doors out or to keep secrets in?

Both, likely.

Re: Backdoor found in a China-made US military chip

#127

Earlier quoted context omitted.

The way I read that is that they make the designs and look for circuitry that does not match the designs, which is presumed to be backdoors. I would think that defects and intentional backdoors would both be findable on an SEM. Do you think otherwise? I don't have a ton of experience with bare silicon, so I'd be interested to know if that's unreasonable.

I do think it is unreasonable. With a SEM you only get to look at the surface of things, which is going to be either glass or metal or polysilicon. The only way to see a transistor in a sem is if you chemically remove all the top layers (which are the connections between transistors), or perform a cross section. In the cross section case you are going to see a few dozen transistors out of the millions in a design of…

Just to add... Any "advanced" backdoors take significant silicon and would be visible from the top of the device as a significant design change would be required to accomodate them. Subtle flaws in designs are another thing altogether.

Re: Backdoor found in a China-made US military chip

#128

Earlier quoted context omitted.

Excellent! They are credible. Why? Because you said so? That is good information, but just hearing your reasoning would make your comment a lot more credible itself without your reputation, which many people aren't familiar with. Other people here are making the case that the motives behind this research aren't perfectly pure, so, presenting the unique insight that you have on the credibility of this group would be a…

I am sorry that it upset you that I was unable to share details about a bug, but I am unwilling to withhold heads-ups to the other people here running apps behind nginx just to save your feelings. I think if you use the search box at the bottom of the screen, you'll have no trouble at all finding thousands and thousands of words spelling out in great detail what I think about bcrypt. I am a person, not a web service.…

I think you guys are talking on different tracks here. jsprinkles brings up a genuine concern. However, he goes ahead and calls your skill unmatched in your domain and I respect that. Honestly, that was a bit of a shocker but I will accept this. Its one thing to be cagey with details and unscientific with your "forum" approach. But it bothers me that you go ahead and underestimate and even disrespect your audience. I can only come to the conclusion that you dont understand. Thats it, this is a very fitting response.

Re: Backdoor found in a China-made US military chip

#129
post #83
post #22

The chip in question seems to be an Actel Microsemi ProASIC3 (PA3) [1,2], given the hints in the screenshot of the paper. [1] http://www.actel.com/products/pa3/ [2] http://www.actel.com/documents/pa3_faq.html (I guess there is no real advantage in keeping this obscured)

I see no mention of tamper-resistance/self-destruct features? Power glitch detection, mechanisms to detect decapping/stripping, wire mesh shielding, protection against ultra-violet laser stimulation of transistors, ... are all important. For those interested in further reading, Security Engineering[1] by Ross Anderson contains a section on chip security. Another paper[2] by Ross Anderson and Markus Kuhn (1996) provid…

They do a special "military" version for which they don't publicly publish the featureset.

Re: Backdoor found in a China-made US military chip

#130
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

It's funny reading people's replies. If it had been from MIT or Stanford, they'd have accepted it without question. I don't think many Americans are really aware of universities outside of the US.
Post reply on HN