Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

131–140 of 159 posts

Re: Backdoor found in a China-made US military chip

#131

TL; DR - No proof / source code / details on the backdoor - Outlandish claims of this being a "stuxnet" weapon Show me some source, a schematic, or a technique that you're using, and then I might believe you, otherwise this is just FUD. They didn't even name the bloody chip.

Exactly my thought. It's simple enough to grab HN headlines, far harder to sustain attention without walking the walk.

"It's not that I don't trust you, it's that I don't yet have necessary and sufficient evidence in relation to your claim to trust you."

Re: Backdoor found in a China-made US military chip

#132

Earlier quoted context omitted.

I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…

The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.

Sorry, the NSA has it's own billion dollar fab soitcan build copyrighted Intel clones?

I simply don't get it?

* what happens when Intel release the nextgenration of chips? Apparently Intel needs to rebuild a while new fab plant at x billion - does the NSA? * do they trust the designs made by Intel? If not what do they do ? If Intel is introducing backdoors for the NSA what guarantee is tere those backdoors won't get used y someone else? * if they do trustthe design but don't trust the fab process surely it is better to put armed guard in the fab room or similar checks * and this is only for one generation of one class of chip. Do this for the chips in the CCTV cameras and the door locks and the ...

Re: Backdoor found in a China-made US military chip

#133

Earlier quoted context omitted.

Confusingly, IBM's mainframes run on the "i" operating system.

i series aren't mainframes, they're midrange, the replacement for the AS/400 platform. Mainframe stuff is z series, a replacement for the System/390 line.

And the official term would be IBM i running on Power Systems. Damn IBM and their ever changing name of the most stable platform available.

Re: Backdoor found in a China-made US military chip

#134
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

I'm respectful of your qualifications, but annoyed when you use your credentials without qualification. A paranoid man might assume your comments are strategically placed to benefit parties you're aligned with, based on how little context there is here; I know better, others might not. "These are good guys. This paper is the real deal." I appreciate what you bring to HN, but that this is the top comment worries me, p…

There's really no debate that Cambridge has probably the top university hardware security analysis program in the world. They published attacks on the IBM 4758 Security Coprocessor, a bunch of attacks on specific smartcards, and are basically the standard bearer for (non classified) research into this kind of stuff. I think some of the chip companies (Intel, IBM) might have better resources for pure silicon debugging, but less security clue to go with it.

Re: Backdoor found in a China-made US military chip

#136

Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing. There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a…

I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…

> with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them

My instincts would be that in the absence of real evidence they are 'loudly saying this is happening' to beat the war drums, declare it as proof a 'cyberwar' is happening, are using it to get more funding and preparing for new draconian measures to control it both domestically and internationally.

Re: Backdoor found in a China-made US military chip

#137
post #118

Earlier quoted context omitted.

1800 cases of counterfeit parts, not 1800 cases of maliciously designed parts. There could well be malice involved, but the vast majority of those cases were almost certainly economically motivated.

He needs to provide more specific information and evidence. Heed your own advice.

I'm not the one making extraordinary claims.

Re: Backdoor found in a China-made US military chip

#138

Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing. There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a…

To clarify for people reading, IOS is the name of Cisco's operating system for their router's and network switches. Apple licensed the trademark from Cisco when they switched the naming of their mobile operating system. http://blogs.cisco.com/news/cisco_and_apple_agreement_on_ios...

Earth is case-sensitive:

iOS == Apple's mobile OS

IOS == Internetwork OS (Cisco gear)

Further:

Mac == Macintosh

MAC == Media Access Control (Address), common in configuration of Cisco equipment...

Re: Backdoor found in a China-made US military chip

#139

Earlier quoted context omitted.

I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…

The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.

Not surprising, given how important custom ASICs are for serious codebreaking.

Re: Backdoor found in a China-made US military chip

#140
post #57

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! Where else are they going to get the chips in the quantities required since the US outsourced most of its commercial silicon foundries? Of the few remaining in the US, the largest is wholly owned by the Taiwanese company TSMC. Post-industrial economics is idiotic, and this is one of the major examples of…

Commercial silicon foundaries, yes, but Intel, IBM, TI, National, etc all still have their own fabs in the US. Also, isn't Global Foundaries building a new fab in New York right now?
Post reply on HN