- It's meant to be a stealthy plane, how about tweaking the board to cause a nice and noisy signal leak in certain circumstances?
- find a way of causing the board to fail under suitable circumstances.
- Probably less plausible, if they can figure out what data is passing through the board, then there is potential to engineer side-channels in the hope that they can achieve another compromise that can leverage it. Maybe they never get the chance to take advantage, maybe they do. Or if e.g. they can find an input that an adversary can potentially influence by how they engage with the plane, use that to trigger failure as above.
I'm assuming they're properly inspected and tested on receipt, but wires on circuit boards can interfere with each other in messy ways if you exceed tolerances even a little bit. I recall an amusing case some years back where someone used genetic algorithms to lay out features on an FPGA and got a very good solution that was totally un-reproducible: it turned out their GA had optimized to take advantage of quirks of that one specific FPGA that didn't work on other FPGA's of the same model, by combining things in ways it hadn't been designed for. It seems it's very much possible to design chips that superficially looks like it should act one way but where it acts differently in certainly circumstances.
Doing so in a way that's exploitable without being caught out is probably much harder, but I share your skepticism.
Such mission critical to EMI designs would be submitted to full spectrum EMI tests once assembled (hitting it with noise of all kinds of frequencies AND testing it for leaks of all kinds).
Causing a bare board to fail? lol, perhaps if you have an atomic disintegrator. Assembled boards with actual components? Now you have something you can actually fail but this PCB house does not do said assembly nor have access to that.
Figure out what data? Completely impossible. These are just copper traces. They don't get told "Mr Copper trace, you are going to do i2c and send XYZ data! and you are going to be a pci express and send ABC!" at the fab. Jeez.
Now a real cause for concern, if say a state actor had access to the completed assembly going into the planes, they could identify a place to embed a backdoor. The state actor controlled PCB house could then embed the backdoor into the PCB itself. But at that point you have 2 different security breaches and the PCB guy is probably lesser of your concerns.
The dumber thing would be to alter the current carrying capacity of power traces which tend to be obvious staring at a board. But it would just identical to trolling by causing boards to fail and eventually get it investigated and your supplier contract revoked.
This plan didn't work out in the embassy case, but I'm not any kind of expert on electronics, so maybe the lessons learned doesn't translate exactly to the PCB situation.
[1]: https://www.nytimes.com/1988/11/15/world/the-bugged-embassy-...
I do only very basic electronics, so I'm asking here in honest confusion: Why can't you figure that out? I'd have expected that part footprints, high-level topology, fine details of individual traces, and the general need for everything to make sense at all would tell you everything you needed to know.
RF optimizations (squiggles to control propagation delay, weird shapes in corners, notches) (edit: wouldn't these give you the bus's frequency too?) and thermal tweaks (wider traces, bigger vias) would give you information about the pinout of whatever's plugged into each footprint (fast, slow, low-power, high-power, etc). Basic topology (is a line connected to two pins or thirty, is a line isolated or is it part of a sixteen-wide or ninety-wide bus) would narrow that down even more. More important parts will almost necessarily have more lines coming out of their footprints so you'd have more information about the stuff you care about.
Even if we assume there're no standards in use ("941 lines, power here here and here, high-frequency bus with 288 lines here, so that's socket AM3, which means these are..."), I wouldn't have surprised if you'd told me you could figure out what part numbers they're dropping into the slots for microprocessors and similar. What am I missing? Why can't you figure out which lines are i2c to misc peripherals and which lines are PCIe between CPU and key coprocessors?
> I do only very basic electronics, so I'm asking here in honest confusion: Why can't you figure that out?
You can. OP is trying to be snarky, but he's wrong.
I don't think it's worth getting into an argument with someone with such an obviously demeaning attitude ("Dear God," "Jeez," etc.), but a few points:
1. It's not just bare copper, silkscreen frequently tells you what's going on, even in secretive government airplanes.
2. Even without silkscreen, e.g. on assembled boards where the chip part numbers have been lasered off for "secrecy," you can often uniquely identify a chip family just by the pins connected to power/ground, certain passives like crystals or filters, etc.
3. If it's a chip with highly remappable pins where you can't just look up which ones are i2c in a datasheet (e.g. FPGA), you can often find them routed together with obvious strategies for impedance control and/or shielding.
4. For i2c in particular, you will likely see two wires routed together, each with a resistor-like footprint pulling the line high.
Amateurs regularly do stuff like this... It's silly to assume a state level actor couldn't do the same or better.
Most boards in the plane are probably designed to have as little RF sensitivity as possible, and are also shielded.
However, if you control the copper traces, you can definitely influence characteristics of the circuit. Presumably, those would be picked up in testing, because they are looking for those kinds of defects.
But a semi-passive component underneath a trace, constructed to act a resistor/capacitor/inductor once every million pulses might not be.
(1) https://hackaday.com/2017/09/11/the-components-are-inside-th...
(2) https://hackaday.com/2019/01/18/oreo-construction-hiding-you...
Analysis should be quite difficult; if you hide them between copper layers, or worse behind components and behind copper layers, I believe it'd require vert inspection with x-rays to detect.
The main question is that of utility. Data exfiltration is highly unlikely. It's possible to trigger malfunctions, but it's not clear this would be useful (when triggered at a certain date, randomly, etc) -- it would be easy to detect and cause the companies to switch to suppliers. I think the main possibility/atractivity would be some kind of radio activation of malfunction. But then you need a significantly sized antenna [1] and a very strong signal to penetrate the circuit shielding (which is probably emp-resistant).
But the main impediment I think is the total erosion of trust in Chinese manufacturing this could bring. Most of the world manufactures in China and they don't want to change this. They wouldn't sacrifice this trust except at a very good opportunity. The same goes from a strategic spying perspective: don't use bugs frivolously or you'll risk raising the awareness level compromising important opportunities.
[1] Which cannot be hidden between layers, although it might be possible to use some of the traces themselves as antennas. If the pcb has an obvious external antenna I/O then of course this would make things easy.
All that said, it does make sense to keep an eye on this possibility, but probably not in this particular case.
If they have leaked lower level plans, that leak is not necessarily useful in itself, but as you point out that does give knowledge about where to embed backdoors. It is not unusual for damage to come when an adversary manages to combine to things that individually are less protected because people fail to see the risk in an individual breach.
As for figuring out the design without it, even as an amateur there are lots of things that I can often infer from looking at a bare board. E.g seeing where power is fed in and which pins likely lead to ground. Seeing where groups of traces follow, which tends to often imply data or address lines. Seeing how chips are grouped and the like - humans lays things out 'logically' even it's not necessary. I have opened enough electronics to know you rarely need to be able to read the text on the chips to know which is a CPU and which is RAM for example.
And hitting something with EMI tests solves for the amateurs who don't know how to do the same testing themselves. It is no guarantee against a state actor prepared to do lots of their own testing to ensure they've mitigated the effects of the changes they've made until certain conditions are met for any circuitry they've hidden.
The dumb thing would be to assume that we're smart enough that a dedicated adversary with access to some of the most sophisticated electronics manufacturing on the planet can't find a way to fool us.
The biggest flawed assumption you make is echoed in the article too: the assumption it is a bare board. It is meant to be a bare board. It is meant to be just copper traces. Good luck verifying there's nothing else sandwiched between layers, obscured on screening by copper on other layers.
Yes, we don't normally do that, but not because it's impossible, but because it's pointlessly complex when we don't need things to be hidden.
The number of security holes that are the result of assuming something can't be done instead of ensuring nobody gets the chance to try is quite substantial.
Actually having the board means they can embed a chip inside it.
Combine those, and they can MITM all sorts of data. Depending on the purpose of the board: They can effectively grant stealth to their non-stealth aircraft. They can cause the F-35 to emit a response to a coded message.
Without much knowledge of the board, there is still hope for causing mayhem. The modifications could check for kill codes on many traces. China could deliver these in a multi-spectral way, not knowing what data actually flows through the board. So the kill codes show up on all the RF frequencies that the F-35 is thought to receive, and on anything optical, and so on. The kill codes could then disable the board, supply high-voltage pulses to other boards, or perhaps even make the board detonate.
They're supposed to be just copper traces. The point of comprising it is you add something that's not supposed to be there, like a chip embedded secretly inside the plastic and connected to the traces.
That is possible, but would require first having a security breach with access to the completed assembly to know _what traces_ first. At which point that security breach is slightly more concerning given it's higher level.
that's not true.
one can design a pcb to pass conformity tests but fail in a more discrete manner, even without total knowledge of the system. This is made even more possible if the manufacture has knowledge of what conformity tests must be made, and how. This is quite often common knowledge for such manufacturers as they are trying to keep costs to the minimum required to pass the testing needed for the product to be bought by the contractor.
Saboteurs might design in PCP boards that pass aging tests, then fail in reality much faster. Detecting mechanical or chemical failures that are designed to pass testing is not an easy task.
This is not an attack on you personally, because your sentiment is not yours alone.
It’s just a reflection of the total disrespect for engineering and manufacturing that Americans seem to have.
Under all internal running conditions? That's not feasible.
It is a PCB. If you're really really interested in sabotaging it, you can, erm, make it rust quicker I guess
https://media.ccc.de/v/35c3-9597-modchips_of_the_state#t=901
Edit: this is a slightly different attack, it replaces a resistor with a custom chip that alters the transmission on that line (carefully disconnects the line, turning some 1s into 0s). But it should be possible to fit something like that inside a PCB, when the layers are put together.