Supply Chain Security Is the Whole Enchilada, but Who’s Willing to Pay for It?
krebsonsecurity.com
krebsonsecurity.com
Lack of local manufacturing isn't really important in a world of global commerce, but when governments start using their manufacturing as a weapon in dimplomatic disputes it becomes important.
Also, clothing and shoes (mentioned in the comment I responded to) are easy to produce without massive capital outlay, and the raw materials are readily available from several countries. I think the local manufacturing argument makes more sense with regard to items that are seen as critical, and which would be impractical to obtain from elsewhere - such as motherboards, processors and the like.
Whilst raw materials could be easily available, there is a ramp-up time to move any industry locally, both in terms of creating the manufacturing infrastructure, and in terms of acquiring the skills needed locally.
This is the basic reasoning of every "national security" argument about having domestic production.
The parent is merely stating that basic necessities are also important for the well-being of the nation, it's not just about the IC for ballistic missiles or the 3G circuits that allows Trump to always be on twitter.
I don't think it matters for many items, such as clothing and shoes, because they are cheap to make and readily available from several countries. So even if China randomly decided that they wouldn't ship any clothes to the US anymore (which would hurt them just as much, so is unlikely), you can just as easily obtain them from Bangladesh or Vietnam, or indeed make them yourself.
While they tend to cost more, for the most part, unless you follow the vagaries of fashion, they are worth the extra money.
I bought a belt from an American company after researching different leathers. It's lasting me years at this point. I'm sure it will last decades. It's crazy how much money I wasted before on belts that were a third of the price.
Both top grain and full grain have their uses, so it depends on whether you want some character in the item as it ages or not. Generally speaking if you don't know what to do, go with full grain. It's expensive, but it's great.
The only case where I'd recommend top grain over full grain is if you're buying something where the leather needs to stay in the background. Think a multi-material item like a bag that has both a bright cloth part and a muted leather part then you'll want top grain for the muted leather because it will keep a more consistent style over time so it won't split your attention when looking at it in the future.
I have found no other use for the other types of leather. I'm far from an expert, but from my research and personal experience I really think that the rest of the leather out there is complete garbage.
https://saddlebackleather.com/full-grain-leather-belt
Make sure you double check sizing. It's not the same as jeans.
The issue with chips is, that a modern fab plant costs $1bn. You can't just make it happen, immediately. Same with food production. Technology, guns/steel, energy/oil/gas and food, those are the main "national security" industries.
They're usually not the cheap brands though. The low end is dominated by foreign manufacturers, so Europeans have moved up the value chain.
There's Carlos Santos in Portugal which takes advantage of the fact that Portugal has the lowest labor costs in Europe.
Meermin (in Spain) has a hybrid model where they source from Europe (French tanners), start the manufacture in China, and finish in Spain. Their products are reasonably priced, and pretty high quality.
It's a similar story with Dutch clothier SuitSupply. Their designs are European, and they source their fabrics from Italian mills, but sew their suits in China.
IMHO, such an concept would lead to a perfect protectionist regime while not giving any real enhanced security at all.
It's not even terribly hard. AFAIK you can buy all the tooling quite easily, and it's a well understood problem.
I would think countries would take a cost and risk-based approach. Countries that have the means, and who face major risks from a compromised supply chain compared to other standing risks, might want to think about moving things in-house.
Honduras and Nigeria might have other, more pressing concerns. Liechtenstein in particular is a financial center with an extensive manufacturing base and attendant expertise, so it might be worth considering for them.
wrt computers, why not if they're capable and willing? it has increasingly obvious and critical security considerations. russia already has a fledgling domestic processor industry for these reasons:
https://thenextweb.com/insider/2017/05/25/russia-showcases-f...
It seems like the main fabricators based in Russia are still working on getting below 90nm.
There are two paths to making this work. One is domestic production, which as you say might work for the United States, but the other is supply diversity. If you don't have a local industry but there is one in Canada, Germany and South Korea, and those countries are your allies, you're probably fine. The issue comes when you're entirely reliant on a single country (e.g. China), especially when that country is undemocratic/authoritarian. Because that makes it too easy for them to betray you without you being able to do anything about it, significantly increasing the probability that they actually do it.
Poisoning a population or depriving them of power is a great way to start a war. Peeking at their computers is merely espionage. So yes, food and power might be more important, but there exists sufficient political deterrent already.
(theoretically about having "capacities" that Chinese, Russians etc don't have but that's clearly an outdated concept - having the fastest processors in some defense system hardly matters compared to having secure electronic system broadly).
And yes, if these are sold to other countries, they get to choose who owns them, the US or China. Unless they start their own manufacturing.
If the intelligence apparatus abuses that for the purpose of spying on foreign governments that is an entirely unrelated issue. Their security is their problem.
[1] https://www.wsj.com/articles/china-plans-47-billion-fund-to-...
Companies doing photo masks for chip lithography do exist in the US. Some of them have been bought by international parents. And those international parents jump through plenty of hoops to keep their certification for being able to continue to produce photo masks for classified military projects — only US citizens are allowed to work on those projects, they may need their own clearances, etc....
Don’t think just because SuperMicro may not have been a party to that system doesn’t mean the system in question doesn’t exist.
The USA has a strong semiconductor industry. Probably stronger than China’s. China is traditionally not very strong an semiconductor fabrication.
What they are strong at is PCB assembly. Or rather cheap PCB assembly. You can do that in the USA too, it’s just not as cheap.
I’d guess most military stuff is done in the USA of domestic and mostly non-China made parts.
For example until the tariff war China was highly dependent on US agriculture (not just buying soybeans from American farmers, but by owning the largest pork producer in the US, Smithfield farms). Well they still are, of course, but they are aggressively looking for alternate trade ties.
The US and major European economies are intermingled tightly enough that it's unlikely that there could be a war between them. The NATO umbrella discouraged them from investing themselves in war-fighting capability (costing the US a lot less than the cost of fighting another war in Europe!). To that extent NATO is a fig leaf, an important one.
And maybe it did; unfortunately, the myth of offense dominance guaranteed that diplomatic crises would escalate uncontrollably into war, masking any effect which discouraged war as a choice in its own right rather than as a preventive measure against the risk that an opponent would choose war.
It's very difficult to isolate and evaluate the effect of one factor.
And given history believing such is not paranoid and wise in a sense of 'not being stupid' as opposed to prescience given the past history of exposed similar moves and a lack of transparency. Probably a borderline 'blasphemous' statement like other uncomfortable truths about things not working.
If stopping Chinese hackers, use stuff from Trusted Foundry running most secure software you can.
If stopping Five Eyes and Israel, use Russian or Chinese hardware running most secure stuff they support.
If not trusting anyone, use a computer made before 1997 that's not on a network and usually hidden in a tamper-evident compartment.
If paranoid, get rid of all electronic devices except those that detect electronic devices and emissions. Keep it far away from you itself sealed so it's not a point of attack. Periodically get it out to conduct a sweep. Your brain, pencil, paper, and hiding places are what you trust in this model. Even mechanical typewriters have acoustic and active RF weaknesses.
So, now you know how to be paranoid. Have at it. ;)
How Patriot act got passed was straight outta Nazi playbook. If a power grab, I knew secret backdoors, surveillance, and disappearances would follow. They'd launch USAP's forcing people to backdoor stuff or be held indefinitely under Patriot Act. Despite Haydens work, NSA still moves slow. I figured a few years before large-scale capabilities came online. Said 2004. Far as I recall, nothing in Snowden leaks refuted that estimate.
What about TAO? Hayden was forcing management to listen to engineers. They'd propose backdoors. Still software focused mostly, though. I estimated 1999. Later article on TAO history said 1997 was their start. Damn. Now I say 1995-1997.
Only thing left off was use obscure, less-popular hardware IP holders and terroristd probably werent using. Macs, Amigas, SGI... or just off-brand x86.
— Joel Spolsky, talking about Not-Invented-Here programming
https://www.joelonsoftware.com/2001/10/14/in-defense-of-not-...
Including an in-house built cipher (task assigned to intern).
It basically doesn't apply to widely-used open source software.
Or to put it another way, you can always maintain an internal fork that currently has zero changes from upstream.
Maybe the cost of electricity, but it seems like the labor cost wouldn’t make a huge difference since most of the production work (I presume) is automated.
a) A missing local supply chain for the raw resources, making them more expensive
b) Additional shipping cost, since every chip will still be assembled into the product in Asia anyway
https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
It’s an absolute classic that I’m sure 97% of HN readers are familiar with, but for the 3% that aren’t it’s a really great meditation on just how difficult it is to trust any computing system, without somehow recursively assessing the trustworthiness of everything that has ever happened before.
https://www.acsac.org/2002/papers/classic-multics.pdf
The seminal paper on subversion in the lifecycle was from another high-assurace, security researcher named Philip Myers in 1980:
https://csrc.nist.gov/csrc/media/publications/conference-pap...
The recommendations were carefully specifying what things do, implementing them in a structured way to inspect for backdoors, using safe languages to block regular vulnerabilities, using covert-channel analysis to find leaks, verifying things down to object code or transistors, letting people build from crypto-signed source, and using couriers for the hardware from trusted facilities onshore ("trusted trucks").
People ignored most of that. Even Thompson as he was obsessed with unsafe language vs Wirth whose work let you choose per module. It's coming back to bite everyone.
https://www.teamten.com/lawrence/writings/coding-machines/
It took me 30min-1hr to read. I can't recall specifically. Worth it. :)
Writing for this week’s newsletter put out by the SANS Institute,
a security training company based in Bethesda, Md., editorial board
member William Hugh Murray has a few provocative thoughts:
1. Abandon the password for all but trivial applications.
2. Abandon the flat network.
3. Move traffic monitoring from encouraged to essential.
4. Establish and maintain end-to-end encryption for all applications.
5. Abandon the convenient but dangerously permissive default access control rule of “read/write/execute”Centrally, yes. But supply chain verification & tracking is one thing blockchains are genuinely good at. There are actual blockchain-based products on the market for that.
Imagine a company such as Apple forcing their suppliers to authenticate each production step from raw material to shipped good on a proprietary blockchain. It's certainly doable from a technical standpoint, and Apple's suppliers are probably eager enough not to lose Apple's business to comply.
My point is, just because someone added a verification message to a blockchain, doesn't mean it actually happened in real life - or indeed preclude additional things from happening.
- if all links in the supply-chain are properly verifying/tracking components, why can't they send this verif/tracking data to their client's server?
- if they're not making a good-faith effort, what does blockchain solve?
Blockchain is genuinely good at maintaining an immutable, trust-free ledger. It's NOT good at making sure the data that's written to it is true.
Blockchain is a solution in search of a problem, here.
if you can't trust the manufacturer to begin with (as is the alleged case with super micro) then this is totally useless.
We can’t trust the supply chain.
So now is machine "B" certified to produce "A" but not machine "C".
This takes all pretty long and I don't think it's done this way in the electronics world, because there are almost no callbacks. So why bother so much with the supply chain.
And not to forget, the test is just if the part does pass the tolerances in the factory. It does not test, if a guy in the factory does cheat.
Even if the factory checked "everyting" and all the details. Then comes somebody like the NSA and they just grab the package on the transport from the factory to the customer (Cisco).
Even if you can totally secure the factory, you can just redirect the parts in shipping. I think "insurmountably hard problem" is a fair description.
Supply chain tracking of the sort you describe is excellent for tracking packages and the movement of goods. It's very useful for tracking the inputs to and outputs from a manufacturing process. Perhaps it's just my personal failure to understand your proposal, but this approach seems mainly limited to tracking known and expected inputs. So it might have a hard time detecting some nigh-invisible addition that takes place within an existing stage of manufacture and does not result in any additional attestation.
Can you help me understand? How does a blockchain solve the problem of a fabrication step compromised?