Earlier quoted context omitted.
Aside from this not being a very useful comment, I think there's good cause to assume this may be a little dressed up: "Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces.…
I assume most people on HN don't follow security and might not be familiar with the University of Cambridge's security program. Having said that, I take issue with almost every point you made: * Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actual…
Backdoor found in a China-made US military chip
141–150 of 159 posts
Re: Backdoor found in a China-made US military chip
#142The Cambridge Security Lab is not fucking around. Assume this is not hype. I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
"Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China)," That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest. - kryptiskt, http://news.ycombinator.com/item?id=4030818 It has ac…
http://en.wikipedia.org/wiki/Ross_J._Anderson http://en.wikipedia.org/wiki/Markus_Kuhn http://en.wikipedia.org/wiki/Steven_Murdoch
...and http://www.lightbluetouchpaper.org/ ; I am unaffiliated with Cambridge other than knowing a few of the people there.
Re: Backdoor found in a China-made US military chip
#143Earlier quoted context omitted.
I assume most people on HN don't follow security and might not be familiar with the University of Cambridge's security program. Having said that, I take issue with almost every point you made: * Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actual…
Its nice that Chris Tarnovsky and Karsten Nohl are really awesome people, but what does that have to do with the article, other than that they work at the same place?
The point is that hardware reversing is not an incredible claim.
Re: Backdoor found in a China-made US military chip
#144The bit that surprises the fuck out of me is that they're buying stuff in from China. I've never seen that - ever! They would buy expensive stuff fabbed specially in the US rather than import usually. I did a lot of work for the UK Ministry of Defence and the US Department of Defence over the years on custom silicon and FPGA work and the paranoia factor is scary. We had the layouts of everything bought in - even 74-s…
Bottom line is to make any sort of computer at a remotely competitive price, you're probably going to use some Asian parts. At least some parts. Then it's a matter of where you draw the line and the price vs. risk. How about a Chinese power supply? It all depends on where and how the device is being used. Then it also depends on the system not "promoting" that device to another purpose.
You can manage it all and make it from only 100% trusted sources, but you know what? It's insanely expensive and by the time you get a computer, there are ones on the market 6x better.
Re: Backdoor found in a China-made US military chip
#145Earlier quoted context omitted.
A hardware security researcher's inability to perform Gartner-correct market research is not relevant to his/her ability to decap, image, and analyze silicon, and thus not at all relevant to me. Wow do I ever not care about this particular gotcha.
Is that a "no, I cannot provide any reason to take this seriously besides my (arrogant) word and this vague, exaggerated, ugly, poorly coded web page"? This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.
Re: Backdoor found in a China-made US military chip
#146Earlier quoted context omitted.
They need custody chain management. I assumed they had one. And everyone who signed for it has securety clearance meaning they signed a paper that basically says "I understand that I'll go to jail for twenty years if I'm caught lying about anything".
...now you tell me. Political candidates should be required to sign the same stuff. And managers. And physicists. And PR stuntmen.
http://www.youtube.com/watch?v=YRUxmoq1weY
http://www.jeffreywigand.com/7ceos.php
Outing Valerie Plame Wilson as a CIA agent, a 100% treason charge
Re: Backdoor found in a China-made US military chip
#147Can somebody explain exactly what they got access to? What is encrypted?
The configuration is commonly stored in a small serial eeprom (tiny 8-pin chip) and automatically read when the FPGA powers up. The content of this chip is often called "bitstream", this configuration eeprom/flash is sometimes also internal to the FPGA.
The key this configuration is encrypted with is supposed to be stored securely inside the FPGA, but they managed to extract it using undocumented commands on the "debug port" (JTAG) that the vendor explicitly claimed did not exist.
Note: This is an interface that normally is not easily accessible from the outside, but sometimes connected to a microcontroller to update the FPGA configuration.
Theoretically someone who gets access ("normal" computer backdoor over the network) to such a device might be able to re-program the chip thereby causing malfunction or add a flaw deliberately. The second scenario would be to decrypt the configuration information, "decompile" it and learn about secret algorithms or functions.
Re: Backdoor found in a China-made US military chip
#148Earlier quoted context omitted.
Confusingly, IBM's mainframes run on the "i" operating system.
i series aren't mainframes, they're midrange, the replacement for the AS/400 platform. Mainframe stuff is z series, a replacement for the System/390 line.
Re: Backdoor found in a China-made US military chip
#149Evidently, the military prefers to cut cost rather than have complete control over the manufacturing of their computer chips. Spending hundreds of millions on jets that have to be American-made is fine, but it's on the computer chips powering those jets and pretty much all advanced military technology that they have to save money.
Re: Backdoor found in a China-made US military chip
#150Earlier quoted context omitted.
Is that a "no, I cannot provide any reason to take this seriously besides my (arrogant) word and this vague, exaggerated, ugly, poorly coded web page"? This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.
You just evaluated a hardware reversing project in part by the design of its web page. Do you have any background in this field at all?
I never evaluated any project at all, just asked why anyone should take you or this web page seriously, and you have been nothing but dismissive in response.