U.S. and U.K. F-35 Jets Include 'Core' Circuit Boards from Chinese-Owned Company
forbes.com
forbes.com
They aren't buying computers from china. The company that did design the electronics (GE) decided to have this little outfit manufacture the PCBs for them (I mean, we're talking a production run in the low thousands so far -- this is NOT a big project). And the little outfit got bought by a bigger PCB company in China a few years back.
The risk to the supply chain is zero -- anyone can make printed circuit boards. The intelligence risk is limited to the ability to see how chips are wired together, with some ability to guess what ICs are in use by clues in the pinouts.
For example, suppose there was some little-known chemistry that would make a PCB likely to fail $X years after manufacture. Or bonus points if it had out-gassing that made other, innocent parts have high failure rates?
let the traces move enough to introduce cross talk if its vibrated and accelerated in just the right way.
There is a short term gain, even if they never get used against china: the US and it's allies have to spend more in testing to account for the Chinese built PCBs.
Check out this missile guidance computer. https://www.bunniestudios.com/blog/?p=3649 Pretty much just a PowerPC and some RAM glued to a giant FPGA with a lot of off board inputs. These days they'd use something like a Zynq that has the hard processor core on the FPGA die, making it look even more like an FPGA breakout board.
While a part of me agrees, I don't want the Chinese to have access to even non-critical things. What if they insert some kind of small component that can be embedded in a PCB stackup that siphons data from a bus, or introduce a high Q resonator that creates an easily discoverable signature when hit with a certain frequency, or something else (like The Thing - https://en.wikipedia.org/wiki/The_Thing_(listening_device)?
x-ray inspection at the bare-board level would check for both of those things (of course), but usually x-ray inspection is done by the assembler after boards are populated - not before - and I've never heard of it being one on a bare-board as an inspection step post receipt. So something like this actually could be missed.
You wouldn't even need to do it to every board, you could do it to some fraction of them, and have (essentially) a secret frequency vulnerability lying in wait. Basically it would invalidate your stealth/LO (obviously this is dependent on shielding and a lot of other things, but you get the idea).
In either case, it's kind of a shitty test given defense applications aren't constrained to the same EMC regulations as the rest of the commercial world.
No, they could insert fake chips during the assembly. Chips that do almost anything, from interfere with operation to logging information, to transmitting data, to exploding in place.
- It's meant to be a stealthy plane, how about tweaking the board to cause a nice and noisy signal leak in certain circumstances?
- find a way of causing the board to fail under suitable circumstances.
- Probably less plausible, if they can figure out what data is passing through the board, then there is potential to engineer side-channels in the hope that they can achieve another compromise that can leverage it. Maybe they never get the chance to take advantage, maybe they do. Or if e.g. they can find an input that an adversary can potentially influence by how they engage with the plane, use that to trigger failure as above.
I'm assuming they're properly inspected and tested on receipt, but wires on circuit boards can interfere with each other in messy ways if you exceed tolerances even a little bit. I recall an amusing case some years back where someone used genetic algorithms to lay out features on an FPGA and got a very good solution that was totally un-reproducible: it turned out their GA had optimized to take advantage of quirks of that one specific FPGA that didn't work on other FPGA's of the same model, by combining things in ways it hadn't been designed for. It seems it's very much possible to design chips that superficially looks like it should act one way but where it acts differently in certainly circumstances.
Doing so in a way that's exploitable without being caught out is probably much harder, but I share your skepticism.
Such mission critical to EMI designs would be submitted to full spectrum EMI tests once assembled (hitting it with noise of all kinds of frequencies AND testing it for leaks of all kinds).
Causing a bare board to fail? lol, perhaps if you have an atomic disintegrator. Assembled boards with actual components? Now you have something you can actually fail but this PCB house does not do said assembly nor have access to that.
Figure out what data? Completely impossible. These are just copper traces. They don't get told "Mr Copper trace, you are going to do i2c and send XYZ data! and you are going to be a pci express and send ABC!" at the fab. Jeez.
Now a real cause for concern, if say a state actor had access to the completed assembly going into the planes, they could identify a place to embed a backdoor. The state actor controlled PCB house could then embed the backdoor into the PCB itself. But at that point you have 2 different security breaches and the PCB guy is probably lesser of your concerns.
The dumber thing would be to alter the current carrying capacity of power traces which tend to be obvious staring at a board. But it would just identical to trolling by causing boards to fail and eventually get it investigated and your supplier contract revoked.
Under all internal running conditions? That's not feasible.
(1) https://hackaday.com/2017/09/11/the-components-are-inside-th...
(2) https://hackaday.com/2019/01/18/oreo-construction-hiding-you...
Analysis should be quite difficult; if you hide them between copper layers, or worse behind components and behind copper layers, I believe it'd require vert inspection with x-rays to detect.
The main question is that of utility. Data exfiltration is highly unlikely. It's possible to trigger malfunctions, but it's not clear this would be useful (when triggered at a certain date, randomly, etc) -- it would be easy to detect and cause the companies to switch to suppliers. I think the main possibility/atractivity would be some kind of radio activation of malfunction. But then you need a significantly sized antenna [1] and a very strong signal to penetrate the circuit shielding (which is probably emp-resistant).
But the main impediment I think is the total erosion of trust in Chinese manufacturing this could bring. Most of the world manufactures in China and they don't want to change this. They wouldn't sacrifice this trust except at a very good opportunity. The same goes from a strategic spying perspective: don't use bugs frivolously or you'll risk raising the awareness level compromising important opportunities.
[1] Which cannot be hidden between layers, although it might be possible to use some of the traces themselves as antennas. If the pcb has an obvious external antenna I/O then of course this would make things easy.
All that said, it does make sense to keep an eye on this possibility, but probably not in this particular case.
They're supposed to be just copper traces. The point of comprising it is you add something that's not supposed to be there, like a chip embedded secretly inside the plastic and connected to the traces.
That is possible, but would require first having a security breach with access to the completed assembly to know _what traces_ first. At which point that security breach is slightly more concerning given it's higher level.
that's not true.
one can design a pcb to pass conformity tests but fail in a more discrete manner, even without total knowledge of the system. This is made even more possible if the manufacture has knowledge of what conformity tests must be made, and how. This is quite often common knowledge for such manufacturers as they are trying to keep costs to the minimum required to pass the testing needed for the product to be bought by the contractor.
It is a PCB. If you're really really interested in sabotaging it, you can, erm, make it rust quicker I guess
This plan didn't work out in the embassy case, but I'm not any kind of expert on electronics, so maybe the lessons learned doesn't translate exactly to the PCB situation.
[1]: https://www.nytimes.com/1988/11/15/world/the-bugged-embassy-...
I do only very basic electronics, so I'm asking here in honest confusion: Why can't you figure that out? I'd have expected that part footprints, high-level topology, fine details of individual traces, and the general need for everything to make sense at all would tell you everything you needed to know.
RF optimizations (squiggles to control propagation delay, weird shapes in corners, notches) (edit: wouldn't these give you the bus's frequency too?) and thermal tweaks (wider traces, bigger vias) would give you information about the pinout of whatever's plugged into each footprint (fast, slow, low-power, high-power, etc). Basic topology (is a line connected to two pins or thirty, is a line isolated or is it part of a sixteen-wide or ninety-wide bus) would narrow that down even more. More important parts will almost necessarily have more lines coming out of their footprints so you'd have more information about the stuff you care about.
Even if we assume there're no standards in use ("941 lines, power here here and here, high-frequency bus with 288 lines here, so that's socket AM3, which means these are..."), I wouldn't have surprised if you'd told me you could figure out what part numbers they're dropping into the slots for microprocessors and similar. What am I missing? Why can't you figure out which lines are i2c to misc peripherals and which lines are PCIe between CPU and key coprocessors?
> I do only very basic electronics, so I'm asking here in honest confusion: Why can't you figure that out?
You can. OP is trying to be snarky, but he's wrong.
I don't think it's worth getting into an argument with someone with such an obviously demeaning attitude ("Dear God," "Jeez," etc.), but a few points:
1. It's not just bare copper, silkscreen frequently tells you what's going on, even in secretive government airplanes.
2. Even without silkscreen, e.g. on assembled boards where the chip part numbers have been lasered off for "secrecy," you can often uniquely identify a chip family just by the pins connected to power/ground, certain passives like crystals or filters, etc.
3. If it's a chip with highly remappable pins where you can't just look up which ones are i2c in a datasheet (e.g. FPGA), you can often find them routed together with obvious strategies for impedance control and/or shielding.
4. For i2c in particular, you will likely see two wires routed together, each with a resistor-like footprint pulling the line high.
Amateurs regularly do stuff like this... It's silly to assume a state level actor couldn't do the same or better.
Most boards in the plane are probably designed to have as little RF sensitivity as possible, and are also shielded.
However, if you control the copper traces, you can definitely influence characteristics of the circuit. Presumably, those would be picked up in testing, because they are looking for those kinds of defects.
But a semi-passive component underneath a trace, constructed to act a resistor/capacitor/inductor once every million pulses might not be.
Saboteurs might design in PCP boards that pass aging tests, then fail in reality much faster. Detecting mechanical or chemical failures that are designed to pass testing is not an easy task.
This is not an attack on you personally, because your sentiment is not yours alone.
It’s just a reflection of the total disrespect for engineering and manufacturing that Americans seem to have.
Actually having the board means they can embed a chip inside it.
Combine those, and they can MITM all sorts of data. Depending on the purpose of the board: They can effectively grant stealth to their non-stealth aircraft. They can cause the F-35 to emit a response to a coded message.
Without much knowledge of the board, there is still hope for causing mayhem. The modifications could check for kill codes on many traces. China could deliver these in a multi-spectral way, not knowing what data actually flows through the board. So the kill codes show up on all the RF frequencies that the F-35 is thought to receive, and on anything optical, and so on. The kill codes could then disable the board, supply high-voltage pulses to other boards, or perhaps even make the board detonate.
If they have leaked lower level plans, that leak is not necessarily useful in itself, but as you point out that does give knowledge about where to embed backdoors. It is not unusual for damage to come when an adversary manages to combine to things that individually are less protected because people fail to see the risk in an individual breach.
As for figuring out the design without it, even as an amateur there are lots of things that I can often infer from looking at a bare board. E.g seeing where power is fed in and which pins likely lead to ground. Seeing where groups of traces follow, which tends to often imply data or address lines. Seeing how chips are grouped and the like - humans lays things out 'logically' even it's not necessary. I have opened enough electronics to know you rarely need to be able to read the text on the chips to know which is a CPU and which is RAM for example.
And hitting something with EMI tests solves for the amateurs who don't know how to do the same testing themselves. It is no guarantee against a state actor prepared to do lots of their own testing to ensure they've mitigated the effects of the changes they've made until certain conditions are met for any circuitry they've hidden.
The dumb thing would be to assume that we're smart enough that a dedicated adversary with access to some of the most sophisticated electronics manufacturing on the planet can't find a way to fool us.
The biggest flawed assumption you make is echoed in the article too: the assumption it is a bare board. It is meant to be a bare board. It is meant to be just copper traces. Good luck verifying there's nothing else sandwiched between layers, obscured on screening by copper on other layers.
Yes, we don't normally do that, but not because it's impossible, but because it's pointlessly complex when we don't need things to be hidden.
The number of security holes that are the result of assuming something can't be done instead of ensuring nobody gets the chance to try is quite substantial.
https://media.ccc.de/v/35c3-9597-modchips_of_the_state#t=901
Edit: this is a slightly different attack, it replaces a resistor with a custom chip that alters the transmission on that line (carefully disconnects the line, turning some 1s into 0s). But it should be possible to fit something like that inside a PCB, when the layers are put together.
Hypothetically, what would happen to a pcb board , 33x33cm in size, with the ground lines running around the edge of that board, when hit with a high power 900 MHz broadcast?
On that note I don’t understand the willful cognitive dissonance around Chinese espionage. They’re a powerful state aggressively looking out for their own self interests just like all the others.
Unless the government inspected every board individually, there's no way to guarantee supply chain. At least from a national defense perspective, everything that comes out of China is a possible risk.
To flip the debate around, if the US manufactured PCBs for China, don't you think we would do the same thing?
It's really not hard to imagine some smart people being told to make it work.
And for you security deniers that say nothing like this ever happens, https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
But getting the information to be transmitted is a lot harder. I don't know what kind of component this is, but I suspect that not a lot of PCBs have direct access to that kind of high level information (assuming that there is a kind of system bus that even passes such data around...).
Raytheon once ran into a "small" problem with it. They actually did whole PCBA in China for AIM 9L.
There is a blogger guy who actually found a whole image processing board with top tier FPGAs that somehow got to an electronics scrap trader around here few years ago.
the link above is about that particular case, but the hearsays of American defence hardware like ICBM gyros popping up around China in scrap piles predates that by few years
I am sure China knows everything about the F-35 its not a secret weapon.
Many people I know simply see these headlines and start to see China as an official enemy. I don't understand why we should see them that way at all. The official enemies of the US are typically brutalized in various ways and slandered in the media. It is difficult to know what is to be taken at face value.
Why are you in such a hurry to escalate to war and send off Americans to die? Do you think you can really walk off with an economic advantage after war with a nation of 1 billion?
Of course not.
However, this discussion is about whether we should be concerned that they’re supplying parts for the f35. Based on my firewall logs, that sounds fairly reasonable to me.
Moreover, China's economy is heavily dependent on the consumption of the goods they manufacture for other countries. As their own population demands better wages and living conditions they've been outsourcing basic manufacturing to places like Africa. They haven't got a good foundation to develop the systems, intellectual properties, research, and other things necessary to move beyond manufacturing. Things may be changing, but the sort of cultural change required for that effort is huge. Even with Trump's substantial effort to tear down the US as a world power it is not likely China will rise to even nearly the same level of dominance any time soon (decades out, if ever).
China is hardly going to "eclipse" the US. I think the concern is less economic and more geopolitical. It should worry the West that a highly authoritarian nation is becoming wealthy and powerful.
It's a reasonable concern, I think. Once China gets hard geopolitical power it will start to export its own way of thinking, just as the US did. But unlike the US, which at least in theory believes in basic rights, China is a literal authoritarian surveillance state with no such values.
I worry that state run concentration camps like those in xinjiang will become normalized.
I do think the world should bring more attention to Xinjing, but I don't think escalating tensions is going to do anything worthwhile (especially when I haven't heard a whit about the trade war being sanctions for humanitarian violations). The trade war is also not going to help American workers, capital controls would do that though.
China has made it abundantly clear for a long time that it considers the US to be an ideological enemy, a military rival and a target for economic and geopolitical warfare.
Since ~2008 / Xi Jin Ping took over, its also been fairly clear that China has no intention of liberalizing in any sense, and the government is actively working to undermine the US/European model of a harmonious world.
However, US government policy pre-Trump basically assumed that China was going to liberalize and play by the (US/EU) rules.
I’m not a Trump fan by any means, but regarding China I think he is the first to drop the pretense that China is a friend of America, and now the China hawks in the media, government and military are all piling on.
Not true. China is only interested in preserving its own authoritarian system. China feels fine to coexist with other forms of government, democracy or monarchy. It may influence other countries to advance its business interest, but never attempt to overthrow a government for ideological reasons. What you said only shows the US considers China an ideological enemy, but not the reverse.
edit: in addition, things that we’ve seen in recent years like ‘purges’ of Western influences in Chinese universities - those directly contradict your point that China doesn’t consider the West an ideological enemy.
If the former also fits your definition of “enemy”, I get your point.
"Stay away from me" doesn't mean anything without a willingness to do something if the other doesn't stay away.
The previous administrations were directly collaborating with China, which was justified to the public with the wishful thinking that the CCP would liberalize when exposed to the productive free market. This administration doesn't have the same ties with the Chinese state that the previous ones did, and at the same time China is becoming visibly less liberal and more tyrannical. It's not paranoia if you know anything about the CCP.
The USSR did match or surpass everyone else for a while. You can argue about long-term sustainability, but from 1945 to 1975 ca. they were a legitimate superpower by all definitions.
2) contractors on military projects are highly regulated. I wonder if any laws or contractual agreements were broken by this
All Chinese plating is crap, always rushed through rinse and usually contains residuals.
Can't believe no one mentioned this, a ticking time bomb for corrosion and failure.
https://www.thinkdefence.co.uk/2009/11/us-to-keep-jca-source...
Edit: fat thumb typos
You run ten completely truthful stories about X doing something but no stories about Y doing the same thing.
The perception then becomes skewed towards Y.
Is manufacturing a PCB in China for a critical piece of defense equipment a security risk, possibly, it's also a possibility the same is true if they made that PCB in France or Israel or Japan (though I'm sure the threat curve is different).
The other questions I'm curious about are things like, ignoring the F-35, how much other equipment in service is dependent on Chinese manufacturers - electronics are everywhere and China is the nations factory (of sub-assemblies at least).
Propaganda can also straight up tell the truth. Propaganda, contrary to the impression given to many put through the public school system, is not a synonym for "lie". Propaganda is often lies, but being dishonest is not a defining characteristic of propaganda.
One famous example: Loose lips sink ships. Okay, maybe that's a bit exaggerated, but it's generally pretty true. In a war, breaches in secrecy can easily cost lives. Those loose lips posters were still unambiguously propaganda though.
China is far less capable, and nobody else is even close to being able to reach national self-sufficiency without going back to a very primitive meager existence.
I'm not saying there's no possible conflict of interest here or that China wouldn't try something or that we should continue to use Shenzhen Fastprint for circuit boards to go in our super premium fancy stealth doodads.
I'm saying this is stupid and a non-issue and people should calm down.
If you know very little about someone, just examining their laundry will tell you quite a bit about them. So 'effective' is really relative.
And, I'd argue that just having their hands on a physical component gives them the ability to introduce purposeful exotic flaws which they can exploit, or just ensure failure sometime in the future yet aren't detectable by standard quality control methods. Kinda like 'zero-day' code flaws that are kept in ones back pocket until needed.