Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing. There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a…
I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…
Backdoor found in a China-made US military chip
121–130 of 159 posts
Re: Backdoor found in a China-made US military chip
#122Earlier quoted context omitted.
I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…
The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.
Re: Backdoor found in a China-made US military chip
#123It is trivial for manufacturers to sneak backdoors into chips. It is improbable to keep backdoors a secret. People aren't good at keeping secrets.
Re: Backdoor found in a China-made US military chip
#124Earlier quoted context omitted.
I think the problem is that there are too many suppliers. Everyone wants to be a middle-man. If the government asks for domestic parts from it's big contractors, the big ones ask their small ones, and they ask theirs and so on. But at the end of the day someone realizes it's cheaper to outsource it - does so - and forges the documentation. As the part travels all the way back up the chain each one says it's domestic.…
The chain is audited regularly. A manufacturer outsourcing stuff has a hell of a lot of documentation to forge. Each screw, each washer, each resistor, has a batch number that it can be traced to.
Re: Backdoor found in a China-made US military chip
#125The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…
http://en.wikipedia.org/wiki/List_of_semiconductor_fabricati...
Re: Backdoor found in a China-made US military chip
#126Earlier quoted context omitted.
The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.
Does the NSA have its own fabs to keep back doors out or to keep secrets in?
Re: Backdoor found in a China-made US military chip
#127Earlier quoted context omitted.
The way I read that is that they make the designs and look for circuitry that does not match the designs, which is presumed to be backdoors. I would think that defects and intentional backdoors would both be findable on an SEM. Do you think otherwise? I don't have a ton of experience with bare silicon, so I'd be interested to know if that's unreasonable.
I do think it is unreasonable. With a SEM you only get to look at the surface of things, which is going to be either glass or metal or polysilicon. The only way to see a transistor in a sem is if you chemically remove all the top layers (which are the connections between transistors), or perform a cross section. In the cross section case you are going to see a few dozen transistors out of the millions in a design of…
Re: Backdoor found in a China-made US military chip
#128Earlier quoted context omitted.
Excellent! They are credible. Why? Because you said so? That is good information, but just hearing your reasoning would make your comment a lot more credible itself without your reputation, which many people aren't familiar with. Other people here are making the case that the motives behind this research aren't perfectly pure, so, presenting the unique insight that you have on the credibility of this group would be a…
I am sorry that it upset you that I was unable to share details about a bug, but I am unwilling to withhold heads-ups to the other people here running apps behind nginx just to save your feelings. I think if you use the search box at the bottom of the screen, you'll have no trouble at all finding thousands and thousands of words spelling out in great detail what I think about bcrypt. I am a person, not a web service.…
Re: Backdoor found in a China-made US military chip
#129The chip in question seems to be an Actel Microsemi ProASIC3 (PA3) [1,2], given the hints in the screenshot of the paper. [1] http://www.actel.com/products/pa3/ [2] http://www.actel.com/documents/pa3_faq.html (I guess there is no real advantage in keeping this obscured)
I see no mention of tamper-resistance/self-destruct features? Power glitch detection, mechanisms to detect decapping/stripping, wire mesh shielding, protection against ultra-violet laser stimulation of transistors, ... are all important. For those interested in further reading, Security Engineering[1] by Ross Anderson contains a section on chip security. Another paper[2] by Ross Anderson and Markus Kuhn (1996) provid…
Re: Backdoor found in a China-made US military chip
#130The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.