Avoid all links to kicad-pcb.org – Use kicad.org
forum.kicad.info
forum.kicad.info
DigiKey is the real hero of this story:
> When the KiCad Project formally became a registered project under the Linux Foundation, we attempted to secure the rights to the original domain name from Dick without success.
> In the meantime, Digikey Corporation purchased the kicad.org domain name from squatters and donated it to the KiCad Project.
It’s too bad they didn’t start migrating to the kicad.org domain name earlier. Changing domains is always hard but they should have started the migration at first signs of trouble with the old domain holder, not after he had sold it away.
We actually offered to purchase the domain names from him. We don't know how much he sold them for but we were not given the chance to bid against whoever eventually bought them.
The annoucment is also on the kicad.org domain. https://www.kicad.org/blog/2021/10/Avoid-links-to-former-kic...
Dave at eevblog also runs one https://www.eevblog.com/forum/kicad/ (Chris and Dave both host The Amp Hour podcast), There is the Subreddit, there are also Chinese and Spanish forums on differnt domains too.
The kicad site also states that in order to have your forum listed on the kicad site "You do not misrepresent yourself as being an official KiCad entity". Having a subdomain for it could imply its "official" and break its own rule. https://www.kicad.org/community/forums/
Things have gotten way better since then. I have not heard any desire to have a centrally maintained forum, but will help however I can.
"The original KiCad domain name (kicad-pcb.org) was recently sold to an unnamed third party that is not affiliated with the KiCad Project or members of the KiCad Development Team. This sale was unexpected and may pose a risk to KiCad users. The new owners may simply post advertisements or (worst-case scenario) they may host malicious versions of the KiCad software for download."
Imagine someone using this as an attack vector to smuggle in exfiltration appliances in the form of hardware circuits in the KiCad software itself, so that the generated PCB files contain spyware in hardware form.
That would be a first of its kind: Supply chain attack at hardware level.
It would be like photoshop trying to sneak extra people into photos without the photographer noticing.
Doesn't mean the layers have to be rendered with the modified/malicious version of KiCAD. They could just try to hide it if they detect a layer with id=spyware.
I'm just saying that this would be a very sneaky way to infiltrate the hardware industry, because currently all installed versions rely on the old domain - and that's where they will pull their updates from, too. So pushing out a newer release with that "spyware" modification would be super easy to realize.
What I thought of is maybe it might be feasible to sneak in some circuits that reroute e.g. a network port's traffic to a specific public IP/CnC. Depending on how complex the PCB layout is, it could be feasible to encode or modify the modulation of easy network busses (aside from ethernet).
But I guess that would involve deployment of malicious firmware or availability of a specific "malicious" chipset, too, because ethernet is quite complex in the sense that there are too many physical parts necessary to implement it in hardware form.
I was just thinking about the Q&A pipelines in the industrial process. Usually they never validate anything because of proprietary/protected intellectual property contracts, so suppliers down the line always claim it's according to specifications and that is blindly trusted by the manufacturers.
Identifying something like this is much harder in the organizational sense, because it involves a lot of time for verification down the line, and involves a lot of organizational blamestorm before anything really happens to fix it.
Despite this, I very much doubt any software is going to be inserting those into designs automatically anytime soon!
[1]: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
Blanket automated modifying of hardware designs to add "spyware in hardware form"? I would say even "automated" part is impossible at the moment. I've never heard of automation that would understand a hardware design on a level that would be required for that.
In the end, the only modification with a good chance of being missed by the designer is the copper artwork on existing PCB layers. You might add an extra trace, or break an existing trace somewhere. But as soon as your hacked Kicad starts adding BOM items (like an extra "spyware" microprocessor or something) or even extra layers, I guarantee someone is going to notice very soon. If not for other reasons then because these things will add extra $ on someone's bill.
Actually adding a component is a bit too james bond, although maybe you could do 1 or 2 on some enormous board but even then that's a real stretch.
More and more manufacturers with online ordering show you images of what they think each layer looks like, and any modifications unless they are very slight will be detected then. You always review each layer in the manufacturers tool as there is a host of things that can go wrong (layer ordering, mirroring, alignment, copper vs solder mask vs silkscreen layer types).
Adding extra components is out too, as the Bill of Materials is exported to CSV, then imported into several component suppliers websites. Any non-basic component is carefully scrutinized for need as they are expensive (and these days hard to get) and to make sure you have everything you need to actually build the board as any non-trivial board requires multiple suppliers to provide all of the components. Even if you missed it then, assembly charges a significant amount per unique component they have to place on the board (eg: placing same resistor twice is cheaper than 2 different resistors).
Once the board is assembled, it will then likely undergo EMI testing to comply with various countries limits on how much RF can leak out of the product. In quite a few cases, final testing is done by a 3rd party lab. This basically limits whatever data exfiltration method to be short range.
If someone wanted to be evil, they would have much better luck on the software side of the product rather than at the board level.
You could manipulate PCB traces in such a way as to leak data over RF? No topological change to the circuit and very hard to pin down.
And then
> Please do not contact Dick about this. He cannot undo the damage at this point
There's got to be more to this story. What happened?
*Dick
All three show in their results only kicad.org (Google: https://archive.md/07hCs, Bing: https://archive.md/vFb0V, DDG: https://archive.md/fpOHO).
Judging by whois and what's currently served at kicad-pcb.org, it simply expired (on October 15) and is currently parked by GoDaddy.
> Updated Date: 2021-10-15T19:11:24Z
> Registry Expiry Date: 2023-04-12T13:37:29Z
It has been updated on the 15, sure, most probably the date it has been sold, but the expiry is in 2 years.
What if I don't sell watered-down cola, but Pepsi? Would they still have a case, and could the resolution of that case include me losing the domain?