Live data from Hacker News

Backdoor found in a China-made US military chip

cl.cam.ac.uk

151–159 of 159 posts

Re: Backdoor found in a China-made US military chip

#151
post #103

Earlier quoted context omitted.

According to China (the People's Republic of China), Taiwan (the Republic Of China) is a "renegade province." Both the PRC and the ROC claim that they are the legitimate government of China. In the US, ever since Nixon instituted the "two China" policy, China is always taken to mean the PRC. Perhaps the security researchers are not aware of this distinction, but I am also not familiar with how the issue is treated in…

Nixon acknowledged the "One China" policy, not two, when the US shifted diplomatic support from Taiwan (Republic of China) to mainland China (PRC). Taiwan is not a "major" US ally, rather the US is Taiwan's major ally. The US has several other regional countries it has a significantly greater alliances with, such as Japan, South Korea and Philippines. Though through an act of Congress, the US may (depending on the si…

My mistake; I knew that didn't sound right when I typed it.

Re: Backdoor found in a China-made US military chip

#152

Earlier quoted context omitted.

You just evaluated a hardware reversing project in part by the design of its web page. Do you have any background in this field at all?

I never evaluated any project by the design of its web page, I evaluated a web page by its design. I never evaluated any project at all, just asked why anyone should take you or this web page seriously, and you have been nothing but dismissive in response.

Hacker News Protip: If you click tptacek's name, you can see his profile, which will inform you that he's a computer security professional. That's why anyone should take him seriously.

On top of that, he also has a history here of useful and insightful commentary on security issues. That's also why anyone should take him seriously.

The reason he's responding dismissively to you is probably that you keep attacking the OP for irrelevant niggles. The sort of reasoning you're employing here would lead someone who saw a speech by Albert Einstein to dismiss it by saying, "Bah, he can't even be bothered to do his hair well. Why should I think he does his research any better?" Attacking Einstein's hair does not make his ideas any less valid. If you had material objections to the OP, you'd probably get a more congenial response.

Re: Backdoor found in a China-made US military chip

#153
post #115
post #103

Earlier quoted context omitted.

According to China (the People's Republic of China), Taiwan (the Republic Of China) is a "renegade province." Both the PRC and the ROC claim that they are the legitimate government of China. In the US, ever since Nixon instituted the "two China" policy, China is always taken to mean the PRC. Perhaps the security researchers are not aware of this distinction, but I am also not familiar with how the issue is treated in…

The parent's point is that PRC Taiwanese relations are more complex than they appear. Words like "renegade province" make it sound like they are sworn enemies, but the parent is right: it is much more complex than that. As a random but relevant example, Foxconn is a Taiwanese company but much of its manufacturing capacity is on the Chinese mainland. Taiwan is politically an ally of the US, but economically it is much…

OK, perhaps the parent presented a rhetorical question. I do think that this discussion needs to keep the two governments distinct, so I was trying to give some background. But it seems I may have just muddied the waters by not mentioning how relations are in practice.

"Renegade province" is the official stance, but you're right, it is much more complex. In practice Taiwan is autonomous, and the degree of interaction with the mainland is a big political issue -- there were no direct flights between Taiwan and the PRC until just a few years ago. And yet, as you say, Taiwan is economically interlocked with China.

It is interesting to see the discussion here and elsewhere focus on China as a bogeyman. I suppose the news fits into the narrative that has been constructed about Chinese espionage and such.

Re: Backdoor found in a China-made US military chip

#154

Interesting discussion. Some denial, some tin hat, some contemplative. I think I've had all of those emotions with this sort of thing. There are diagnostics in our network switches that allow for traffic to be replicated and sent to other ports with a different destination mac (this isn't port mirroring is more like port re-directing). Clearly in the hands of a bad guy they might set up a machine on the LAN to get a…

I'm sorry I am not sure what you are saying here. It seems to be "this is far more likely to be a test engineers backdoor that was not on the spec" then a Chinese backdoor added at the fab" with no evidence either way, I am guessing that US intelligence (and others?) are loudly saying this is happening not because they can prove it in silicon but convincing human intelligence has told them I happen to think that the…

You are correct, there is no evidence either way. So one way to look at it is to consider what would have to be true for it to be installed by the 'fab' without the knowledge of the guy who designed the chip, vs installed by the chip designer.

Given what I know of silicon chip manufacturing, and the verification that goes on during, after, and while, manufacturing. I assert it would be extraordinarily difficult for a fab operator (like TSMC) to insert a back door without the designer/manufacturer knowing it.

I also brought up that in my experience adding back doors was certainly done to aid in testability. Sometimes those aids are done in a way that they cannot be used by third parties (bond-out chips) and sometimes they could be (JTAG access) but are obscured in some way.

Backdoor access in the firmware however, is a much easier threat to actualize as it doesn't involve silicon hacking per se. So that is a more credible threat. And I mentioned that we've seen counterfeit versions of 'name brand' products already which would be a fairly straight forward threat.

Re: Backdoor found in a China-made US military chip

#155
post #22

The chip in question seems to be an Actel Microsemi ProASIC3 (PA3) [1,2], given the hints in the screenshot of the paper. [1] http://www.actel.com/products/pa3/ [2] http://www.actel.com/documents/pa3_faq.html (I guess there is no real advantage in keeping this obscured)

Is there ANY chance that this is a bit of a tempest in a teapot?

I can envision a scenario where this "backdoor" is actually part of the designed-in security features of the chip designed to prevent an unauthorized party from reading out the FPGA "programming" as it were. As such, it's conceivable that there might be multiple keys or even a series of "transport" or "default" keys that are similar to those found on ISO smartcards. What we might be looking at is a "feature" as opposed to a "backdoor."

In any case, this sort of thing only becomes a critical security breach if the application you're using the chip in depends on periodic (or boot-time) reprogramming of the FPGA. In either case, either the physical security or the trust chain of your firmware loads is broken. As we all know, key management and side channel attacks are the hardest part of implementing a secure crypto system, so is this really news?

Re: Backdoor found in a China-made US military chip

#156
post #138

Earlier quoted context omitted.

To clarify for people reading, IOS is the name of Cisco's operating system for their router's and network switches. Apple licensed the trademark from Cisco when they switched the naming of their mobile operating system. http://blogs.cisco.com/news/cisco_and_apple_agreement_on_ios...

Earth is case-sensitive: iOS == Apple's mobile OS IOS == Internetwork OS (Cisco gear) Further: Mac == Macintosh MAC == Media Access Control (Address), common in configuration of Cisco equipment...

Are we sure that "=" and not "==" is the correct operator?

If "==" was appropriate then there would be no problem of ambiguity. And there would be no need for the clarification. Because meanings could never change with context. There could be no "misinterpretation". Only the truth table result of "false".

Which is more important in human communication: case-sensitivity or context-sensitivity?

Human communication is not a computer program.

Re: Backdoor found in a China-made US military chip

#157
post #138

Earlier quoted context omitted.

Earth is case-sensitive: iOS == Apple's mobile OS IOS == Internetwork OS (Cisco gear) Further: Mac == Macintosh MAC == Media Access Control (Address), common in configuration of Cisco equipment...

Are we sure that "=" and not "==" is the correct operator? If "==" was appropriate then there would be no problem of ambiguity. And there would be no need for the clarification. Because meanings could never change with context. There could be no "misinterpretation". Only the truth table result of "false". Which is more important in human communication: case-sensitivity or context-sensitivity? Human communication is n…

[deleted]

Re: Backdoor found in a China-made US military chip

#158

Earlier quoted context omitted.

The NSA has it's own fab resources. That fact alone tells you everything you need to know. The only remaining question is to what extent is it cost effective to still use suspect parts.

Sorry, the NSA has it's own billion dollar fab soitcan build copyrighted Intel clones? I simply don't get it? * what happens when Intel release the nextgenration of chips? Apparently Intel needs to rebuild a while new fab plant at x billion - does the NSA? * do they trust the designs made by Intel? If not what do they do ? If Intel is introducing backdoors for the NSA what guarantee is tere those backdoors won't get…

Well, AFAIK the NSA doesn't publish what their fabs are capable of or what they do with them. Maybe someone here knows better?

I'd assume the NSA's fabrication capability is more on the scale of the pilot plants fabs build at each new process scale. Some universities certainly have fabrication equipment testbeds as well, so the NSA effort may be more that modest scale.

If I were tasked with the problems the NSA faces, I think I'd at least focus in on:

1. CMOS reverse engineering equipment that can shave down dies, image and analyze the structures, etc.

2. Small scale fabrication for extremely sensitive infrastructure. These roles probably aren't performance critical. Eg if you have some microcontroller that plays a role in say nuclear weapon arming protocols, you need that to be pretty much beyond suspicion.

3. Some way of sampling commodity parts for unexpected behavior non-destructively. If this could be done efficiently enough, you could use it in combination with #1 to get reasonable confidence for off the shelf parts.

One thing I'd suspect is that if the NSA did find highly targeted flaws they probably wouldn't disseminate that fact unless absolutely necessary. Keep an adversary using a strategy you know rather than provoking improvement.

Personally I doubt the NSA forces backdoors into commodity chips. In theory there might be some way of introducing a flaw that would cripple specific large computations like crypto-analysis of a particular code, or biasing a particular random number generator. But that just seems too likely to backfire.

I'd always thought it was interesting that the pentium FDIV bug was most easily found by code calculating twin primes. But there may be a mundane explanation for that rather than cloak and dagger stuff.

Re: Backdoor found in a China-made US military chip

#159
post #152

Earlier quoted context omitted.

I never evaluated any project by the design of its web page, I evaluated a web page by its design. I never evaluated any project at all, just asked why anyone should take you or this web page seriously, and you have been nothing but dismissive in response.

Hacker News Protip: If you click tptacek's name, you can see his profile, which will inform you that he's a computer security professional. That's why anyone should take him seriously. On top of that, he also has a history here of useful and insightful commentary on security issues. That's also why anyone should take him seriously. The reason he's responding dismissively to you is probably that you keep attacking the…

1 & 2: Good reasons. Useful, didn't know that.

3: I will admit, I had read his other responses in this thread, and intentionally chose to provoke a dismissive response by presenting something on the verge of being immaterial. I even apologize to anyone at the Cambridge Security Lab for any disrespect.

I don't apologize for being irreverent towards tptacek and the Cambridge Security Lab. I still think my core point, "This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.", was a totally material response to his original comment, "Cambridge Security Lab is not fucking around.". I also think (and intended) that even though I was trying to provoke him, my response was totally congenial and had a material point and therefore acceptable, while he should not have been so dismissive in response, to me and to everyone else.

Post reply on HN