Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

141–150 of 159 posts

Re: Backdoor found in a China-made US military chip

#141
post #30

Earlier quoted context omitted.

Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…

I assume most people on HN don't follow security and might not be familiar with the University of Cambridge's security program. Having said that, I take issue with almost every point you made: * Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actual…

Its nice that Chris Tarnovsky and Karsten Nohl are really awesome people, but what does that have to do with the article, other than that they work at the same place?

Re: Backdoor found in a China-made US military chip

#142
post #13

The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.

"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest. - kryptiskt, http://news.ycombinator.com/item?id=4030818 It has ac…

@laughinghan if you have to ask my suspicion is that no word of mouth will be enough for you, so instead may I recommend:

http://en.wikipedia.org/wiki/Ross_J._Anderson http://en.wikipedia.org/wiki/Markus_Kuhn http://en.wikipedia.org/wiki/Steven_Murdoch

...and http://www.lightbluetouchpaper.org/ ; I am unaffiliated with Cambridge other than knowing a few of the people there.

Re: Backdoor found in a China-made US military chip

#143
post #30

Earlier quoted context omitted.

I assume most people on HN don't follow security and might not be familiar with the University of Cambridge's security program. Having said that, I take issue with almost every point you made: * Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actual…

Its nice that Chris Tarnovsky and Karsten Nohl are really awesome people, but what does that have to do with the article, other than that they work at the same place?

They don't work at the same place.

The point is that hardware reversing is not an incredible claim.

Re: Backdoor found in a China-made US military chip

#144

The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…

There is this perpetual balancing game being played. The rules have changed for different US agencies over the years, originally it was only "100% made in the USA" or maybe some select partners (the UK and Israel perhaps) but due to competitive pressures and pricing for a lot of federal products, it's okay to assemble in the US and source parts from where ever. DoD has slightly stronger rules and then really strong rules for some devices.

Bottom line is to make any sort of computer at a remotely competitive price, you're probably going to use some Asian parts. At least some parts. Then it's a matter of where you draw the line and the price vs. risk. How about a Chinese power supply? It all depends on where and how the device is being used. Then it also depends on the system not "promoting" that device to another purpose.

You can manage it all and make it from only 100% trusted sources, but you know what? It's insanely expensive and by the time you get a computer, there are ones on the market 6x better.

Re: Backdoor found in a China-made US military chip

#145

Earlier quoted context omitted.

A hardware security researcher's inability to perform Gartner-correct market research is not relevant to his/her ability to decap, image, and analyze silicon, and thus not at all relevant to me. Wow do I ever not care about this particular gotcha.

Is that a "no, I cannot provide any reason to take this seriously besides my (arrogant) word and this vague, exaggerated, ugly, poorly coded web page"? This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.

You just evaluated a hardware reversing project in part by the design of its web page. Do you have any background in this field at all?

Re: Backdoor found in a China-made US military chip

#146
post #44

Earlier quoted context omitted.

They need custody chain management. I assumed they had one. And everyone who signed for it has securety clearance meaning they signed a paper that basically says "I understand that I'll go to jail for twenty years if I'm caught lying about anything".

...now you tell me. Political candidates should be required to sign the same stuff. And managers. And physicists. And PR stuntmen.

There is a problem of enforcing any kind of law or promises on the people at the top:

http://www.youtube.com/watch?v=YRUxmoq1weY

http://www.jeffreywigand.com/7ceos.php

Outing Valerie Plame Wilson as a CIA agent, a 100% treason charge

Re: Backdoor found in a China-made US military chip

#147

Can somebody explain exactly what they got access to? What is encrypted?

They have procured programmable logic chips (FPGA) with the feature that the configuration data that defines the function on powerup can be encrypted/signed.

The configuration is commonly stored in a small serial eeprom (tiny 8-pin chip) and automatically read when the FPGA powers up. The content of this chip is often called "bitstream", this configuration eeprom/flash is sometimes also internal to the FPGA.

The key this configuration is encrypted with is supposed to be stored securely inside the FPGA, but they managed to extract it using undocumented commands on the "debug port" (JTAG) that the vendor explicitly claimed did not exist.

Note: This is an interface that normally is not easily accessible from the outside, but sometimes connected to a microcontroller to update the FPGA configuration.

Theoretically someone who gets access ("normal" computer backdoor over the network) to such a device might be able to re-program the chip thereby causing malfunction or add a flaw deliberately. The second scenario would be to decrypt the configuration information, "decompile" it and learn about secret algorithms or functions.

Re: Backdoor found in a China-made US military chip

#148

Earlier quoted context omitted.

Confusingly, IBM's mainframes run on the "i" operating system.

i series aren't mainframes, they're midrange, the replacement for the AS/400 platform. Mainframe stuff is z series, a replacement for the System/390 line.

If you can't pick it up and throw it out of the window it's a mainframe.

Re: Backdoor found in a China-made US military chip

#149

Evidently, the military prefers to cut cost rather than have complete control over the manufacturing of their computer chips. Spending hundreds of millions on jets that have to be American-made is fine, but it's on the computer chips powering those jets and pretty much all advanced military technology that they have to save money.

Hundreds of millions? You're off by about three orders of magnitude, there.

Re: Backdoor found in a China-made US military chip

#150

Earlier quoted context omitted.

Is that a "no, I cannot provide any reason to take this seriously besides my (arrogant) word and this vague, exaggerated, ugly, poorly coded web page"? This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.

You just evaluated a hardware reversing project in part by the design of its web page. Do you have any background in this field at all?

I never evaluated any project by the design of its web page, I evaluated a web page by its design.

I never evaluated any project at all, just asked why anyone should take you or this web page seriously, and you have been nothing but dismissive in response.

Post reply on HN