J-core Open Processor
j-core.org
j-core.org
"Numato provides a GPL-licensed python3 tool to flash bitstreams onto their board. [TODO: port to python 2]"
No, please. Don't even bother
Anyone familiar with J-Core able to expand on the how an audit would be done end-to-end?
Seems like it would be much harder to do in practice than in theory.
It's harder to audit ASICs that other people have had fabricated without having the exact same standard cell libraries, tooling versions (optimisations change over time), knowing what optimisation settings they used, etc. to be able to prove the masks came from the same code.
I say probably because it's possible that advanced actors like the USA and China have developed tools that add features (backdoors) while making the visual layout look very similar. Then you would probably only find the backdoors by "fuzzing" the chip like you would a piece of software.
Iirc, there was a group from the CCC working on using image recognition algorithms to extract netlists from decapped chips. I'll have to look that up...
And many foundries themselves outsource masks due to equipment costs.
You might be able to get away with a strict characterization of the diced chips to give yourself a very high likelyhood that different die were not substituted at the packaging step. You could also decap a random selection of chips coming back from the factory to validate they used your die rather than a different one.
What about the "to silicon" part of this equation is out there now?
It looks like there is a translator, but I'm unsure about its license, source availability, and capability.
https://news.ycombinator.com/item?id=12103471
However, that submission was incorrectly marked as a duplicate of this submission:
https://news.ycombinator.com/item?id=12101908 (video)
But it's not a duplicate - they have different information. This submission is the web site of the project and has links to files and "how to" documentation. The second submission is to an hour-long about the project, and while it contains information, it's fundamentally different.
I don't know why the original submission of this link got marked as a duplicate - I believe it to have been a mistake.
The current method of handling duplicates is quite simply not working. Consider the multiple large discussions about Google deleting a blog without warning[1][2][3].
HN needs a way to merge items, not simply mark some as duplicates, which kills the item, and any discussion on it then sinks without trace. There must be a better way.
[0] https://news.ycombinator.com/item?id=12105922
[1] https://news.ycombinator.com/item?id=12097063
I've given some thought to how a more fair submission system would work, and I came up with the following idea:
1. Dup submissions are treated as upvotes
2. If an article has N upvotes, the original submitter gets N points (as it is now), the second submitter (or upvoter -- same thing) gets N/2 points, the third gets N/3 points, etc. until either the article makes it onto the front page or some arbitrary point threshold (like 10) is reached.
3. Every upvote or submission costs one karma point. So you have to have at least one karma point to submit or upvote. You have to get your bootstrap points by submitting a comment that gets an upvote. This is to prevent spamming.