Live data from Hacker News

Nvidia Hit by Major Cyberattack

wccftech.com

21–30 of 41 posts

Re: Nvidia Hit by Major Cyberattack

#21
post #12

Earlier quoted context omitted.

Or all their talent made itself scarce when they saw the writing on the wall and what they have left is scriptkiddies who are capable of defacing a website when given a target to take down. It's bad to underestimate the enemy, but also bad to overestimate them.

It's bad to make so many powerful enemies.

Hopefully Putin realizes they has no more claim over whatever holy grail they are chasing than anybody else.

Re: Nvidia Hit by Major Cyberattack

#22
post #15
post #11

Earlier quoted context omitted.

Even if they get the RTL I'm not sure how useful those would be. While Russia does have semiconductor fabs, apparently their smallest node is around 65nm, completely useless for the large designs current NVidia GPUs use. At best they could have them made at a fab in mainland China, but even there the smallest node is only 14nm.

A thief would be using the RTL to make a clone of NVIDIA graphics card, they’d be using the IP cores as modules in their own designs. With some minor adjustment it shouldn’t be too difficult to get at least most of the RTL working in a different mode (maybe lower clock speed)

That's not how VLSI chip design works. You can't just take the RTL designed for 5 - 8 nm, zoom it up to 65nm and expect it to still work.

When you design a CPU or GPU, the RTL, like the core pipelines, schedulers, and various buses, are designed from the start on a certain manufacturing process where they're expected to work correctly at specific frequencies that are fast enough to feed the pipelines at the right timings, in order to get the top expected performance. Failure to meet the fabrication process expectations means the RTL design will perform much worse than expected in practice.

That's why many of Intel's past designs sucked so bad in the performance and efficiency category as their 10nm manufacturing process fell behind, so they had to scale their newer designs back on the aging 14+++++ process, which caused those CPUs to flop big time.

Re: Nvidia Hit by Major Cyberattack

#23
post #8

Putting on my Paranoia hat: what if some aggressor indeed was able to introduce code into the Nvidia drivers, which - if put on enough systems - would cripple the ability to (re-)train Ai systems which might be used in military defense systems. What if - even worse - people decided to use Nvidia hardware in the inference systems as well… Putting down the paranoia hat. Happy weekend.

That's just a very very weird though. Sry but no one just hacks into Nvidias driver dev department and injects complex code to cripple ml training. It's just nothing someone can just do. And there is also nothing which will prevent Nvidia to debug the ml issue and revert the change.

Didn't a bunch of Linux distro s get infected with a "Ken Thompson Hack" a while back?

https://softwareengineering.stackexchange.com/questions/1848...

Re: Nvidia Hit by Major Cyberattack

#24
post #8

Earlier quoted context omitted.

That's just a very very weird though. Sry but no one just hacks into Nvidias driver dev department and injects complex code to cripple ml training. It's just nothing someone can just do. And there is also nothing which will prevent Nvidia to debug the ml issue and revert the change.

Didn't a bunch of Linux distro s get infected with a "Ken Thompson Hack" a while back? https://softwareengineering.stackexchange.com/questions/1848...

Ok I think it was Delphi now, but my brain remembered debian. lol.

There is a double cross compilation method to detect if you are infected.

https://wiki.c2.com/?TheKenThompsonHack

Re: Nvidia Hit by Major Cyberattack

#25
post #18

The article lacks a lot of information unfortunately, but it makes it sound like the website (distribution channel) was the only part they are concerned about, which wouldn't be classed as major. What I'd class as major would be some third party gaining access to NVIDIA's RTL designs and source code for their drivers for current and unreleased GPUs, but this hack doesn't sound remotely close to that. Luckily.

> the website (distribution channel) was the only part they are concerned about, which wouldn't be classed as major By whom? I'd certainly class it as major if their website could distribute malware instead of the real drivers, as that impacts everyone. Stealing nvidia's proprietary designs impacts only them. I visited that page a few days ago to setup a new system which is, at the same time, supposed to be very secu…

Maybe should consider doing the rotation already... Better safe than sorry in such cases.

Re: Nvidia Hit by Major Cyberattack

#28

Rooting for leaks of info/keys/specs that allow nouveau to legally evolve.

> Another major concern is that NVIDIA will now have to ensure that their services and the software they are providing to end-users is entirely free of any viruses or malicious code that could affect them.

I don't know, things like this just show how great it is to put unknown code into your kernel.

Re: Nvidia Hit by Major Cyberattack

#29
post #16
post #9

Earlier quoted context omitted.

AI aside, hacking into the driver’s build process to inject hidden backdoors into the drivers could be a realist attack.

Is it realistic though? Hacking into Nvidias corp network, infiltrating their git server, disabling security scans and then injecting a backdoor undetected in complex code? In a process which is highly controlled due to it being a very central peace of software. Very unrealistic. It's easier to find or buy zero days in the wild for the same goal

Well.. that's exactly what happened to Solarwinds last year, didn't it?

Actually smarter than that - they got into the build system and added the malicious code in the build process so you couldn't see it in the repository.

Do you think it's that difficult for a state sponsored body to infiltrate into a commercial company?

Re: Nvidia Hit by Major Cyberattack

#30
post #11

The article lacks a lot of information unfortunately, but it makes it sound like the website (distribution channel) was the only part they are concerned about, which wouldn't be classed as major. What I'd class as major would be some third party gaining access to NVIDIA's RTL designs and source code for their drivers for current and unreleased GPUs, but this hack doesn't sound remotely close to that. Luckily.

Even if they get the RTL I'm not sure how useful those would be. While Russia does have semiconductor fabs, apparently their smallest node is around 65nm, completely useless for the large designs current NVidia GPUs use. At best they could have them made at a fab in mainland China, but even there the smallest node is only 14nm.

There are EUV machines in China. Not sure why people keep perpetuating the myth that there aren't.
Post reply on HN