The Die Is Cast: Hardware Security Is Not Assured
queue.acm.org
queue.acm.org
Apple made an official statement that the claims were, well, bullshit and that no such chips have ever been found.
Amazon published a signed statement from its chief security officer saying that the Bloomberg article was “so full of inaccuracies ... that they’re hard to count” and that after their own security team and an external security team had gone into the claims in detail they found them to be untrue.
So, I have to ask, does anyone know if Bloomberg actually published the evidence they claimed they would release?
In the first article, Bloomberg quoted Joe Fitzpatrick. 5 days later [0] he said his quotes were taken out of context.
In the second article, Bloomberg quoted Yossi Appleboum, who on the same day the article broke suggested that he was misrepresented. [1]
Apple, Amazon, Homeland Security, and others have all said there was no evidence at all, and called for a retraction.
As it stands... Bloomberg were talking about something they didn't understand. There were and are some theoretical problems in hardware security. But the story as they broke it is completely false.
[0] https://risky.biz/RB517_feature/
[1] https://www.servethehome.com/yossi-appleboum-disagrees-bloom...
That means Apple and Amazon are more credible in this case, unless there is some super secret NatSec exception to securities law that we don't know about.
[1] Specifically, SEC Rule 14a-9 in conjunction with Section 32(a) of the Exchange Act.
Did you not hear about the phonetapping business [0]? There is no way that a government-sponsored secret hardware backdoor would get any executives in trouble.
SEC rules are not a reasonable protection - or even consideration - when dealing with the US spying apparatus. If there was a hardware backdoor program:
(1) There would be a secret exemption to SEC rules.
(2) There would probably be a secret "we will end you" threat if the execs revealed details. Snowden & Assange would be mentioned.
(3) Even ignoring those two points, the rules would be ignored and changed later if there were any legal difficulties.
[0] https://www.cnet.com/news/senate-endorses-retroactive-fisa-i...
[0] https://www.servethehome.com/yossi-appleboum-disagrees-bloom...
If secret chips were going to be used, they'd be very targeted in nature (like a fake Comcast modem that they give to a specific target) rather than something general.
In this case "anything" might mean transmitting a single bit of information that "this is an interesting box, come take a look".
[0] https://en.wikipedia.org/wiki/Unapproved_aircraft_part
[1] https://www.health.gov.il/English/Topics/PharmAndCosmetics/p...
I clicked through to the article on Physically Unclonable Functions (PUFs). [0] Neat idea. (I found the paper more readable than the article. [1]) Limited scope though. I don't imagine it's possible to use this approach for non-electronic items like medical-grade screws, for instance.
[0] https://semiengineering.com/pufs-promise-better-security/
[1] (PDF) https://spqrlab1.github.io/papers/holcomb_PUFs_date14.pdf
It's hard to audit devices. At least with networks the communication aspect is an actual physical phenomenon which can be measured and analyzed. At the same time, the military has encrypted radios which can hop frequencies hundreds of times a second. How do I even detect that? I don't think I can.
In the case of t article, the Rubicon has been crossed, and also features "cast" into the silicon can't be fixed (most of the time). But you're right, they aren't actually cast.
The ordinary view would be that "cast" refers generally to the making or composition of anything by any means. Compare a few senses from Merriam-Webster:
[v.t.] 3(a) to dispose or arrange into parts or into a suitable form or order - I shall cast what I have to say under two principal heads.
[n.] 2(a) the form in which a thing is constructed
[n.] 10(a) shape; appearance - the delicate cast of her features
I am guessing for secure applications the approach of the precursor is going to become very common.
Call me an extremist if you want, but few manufactured goods have seen the level of anti-end user engineering effort put into them than computers. And that's a sad thing to see.
There's a lot of overextensions of the concept of IP that of course make sense to lawyers, judges, and people who have high net worth derived from leveraging this artifice, but the whole thing probably should be reformed at some point if anyone cares about things other than extending the concept of ownership to ideas.
For example, I'm still not clear how I can simultaneously own a media product, like a VCR tape or CD, and not have a "license" from the studio (a non-governmental entity) to publicly exhibit it.
But I don't really see how you can compare this to an attack, unless you actually prove some measurable harm today. What exactly are they doing with your computer that harms you in any direct way?
I absolutely agree on your last point though. It is quite a tragedy when we think about the amount of human intelligence and hard work that has been thrown away on protecting systems from their own owners.
Remember the Sony root kit[1]?
So we agree that the measures were harmful in the past. Of course you wouldn’t ask if we were widely aware of current issues. I think we also agree that a lot of interesting things can be hidden from the user if you have access to the keys to the secured enclaves (or if you manage to break in). If this was ever exploited, we may know in a few years or never.
[1] https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...