I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
I'm less curious about whether overseas silicon is backdoored than I am in how exposed the attack/activation surface for those backdoors are.
"Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip" - er, what? So either they have some approach for turning silicon into a machine readable form, in which case "code breaking" makes no sense, or they're attacking the chip via its interfaces. Why mention both? Because "advanced code breaking" sounds cool.
"In other words, this backdoor access could be turned into an advanced Stuxnet weapon to attack potentially millions of systems" - advanced Stuxnet weapon? This is blatant namedropping, Stuxnet is irrelevant here being a piece of software.
"The scale and range of possible attacks has huge implications for National Security and public infrastructure." - "this is a general purpose chip that happens to be used in military applications".
"adaptable - scale up to include many types of chip" - implies there are complexity limits, so likely they've applied their process to some relatively simple piece of silicon, again suggesting some boring chip.
"found a previously unknown backdoor inserted by the manufacturer. This backdoor has a key, which we were able to extract." - hardly uncommon, in fact the Intel CPU I'm typing this on has such a feature - for encrypted microcode updates.
Until there are more details, this vague news article is just dressing.
Having said that, I take issue with almost every point you made:
* Both Chris Tarnovsky and Karsten Nohl have, supported so far as I know by none of the resources of a major university, given security conference talks on processes for "Turning silicon into machine-readable form". Nohl actually has an open source package to help do it. There's nothing incredible about that claim.
* I'm not sure I follow how the most famous act of computer-aided industrial espionage isn't germane to hardware backdoors. Researchers put their work into context so people outside the field will take it seriously.
* The military uses Microsoft Windows and Red Hat Linux, too, both of which are general-purpose packages. You think a universally distributed backdoor in either that had escaped detection until 2012 wouldn't be relevant to national security?
* Go read Tarnovsky's blog, where he has blogged about extracting keys from silicon.
The only point you've made here that I agree with is that the attack/activation surface of these illicit features is likely to be more important than anything else.
The point is that hardware reversing is not an incredible claim.
That claim about 99% of chips being manufactured in China is very easy to verify as being utterly false. I have to wonder about the trustworthiness of the rest.
- kryptiskt, http://news.ycombinator.com/item?id=4030818
It has actually not been "very easy" for me to verify this, but I did find something saying that in 2009, China had 9% of the world's production capacity, which makes me strongly doubt that they are now 99% of the actual manufacturing amount: http://www.manufacturingnews.com/news/10/0212/semiconductors...
@tptacek: Care to provide references for why Cambridge Security Lab is as big a deal as you're making them out to be, and why we should overlook this blatantly exaggerated fact they cited?
Taiwan is a major US ally, so if this backdoor is real, then there will be trouble. It would be best for all parties involved for this to turn out to be a false alarm.
Taiwan is not a "major" US ally, rather the US is Taiwan's major ally. The US has several other regional countries it has a significantly greater alliances with, such as Japan, South Korea and Philippines. Though through an act of Congress, the US may (depending on the situation) have some obligations to aid Taiwan in its defense if attacked by mainland China.
As a random but relevant example, Foxconn is a Taiwanese company but much of its manufacturing capacity is on the Chinese mainland.
Taiwan is politically an ally of the US, but economically it is much more closely aligned with China.
"Renegade province" is the official stance, but you're right, it is much more complex. In practice Taiwan is autonomous, and the degree of interaction with the mainland is a big political issue -- there were no direct flights between Taiwan and the PRC until just a few years ago. And yet, as you say, Taiwan is economically interlocked with China.
It is interesting to see the discussion here and elsewhere focus on China as a bogeyman. I suppose the news fits into the narrative that has been constructed about Chinese espionage and such.
This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.
I never evaluated any project at all, just asked why anyone should take you or this web page seriously, and you have been nothing but dismissive in response.
On top of that, he also has a history here of useful and insightful commentary on security issues. That's also why anyone should take him seriously.
The reason he's responding dismissively to you is probably that you keep attacking the OP for irrelevant niggles. The sort of reasoning you're employing here would lead someone who saw a speech by Albert Einstein to dismiss it by saying, "Bah, he can't even be bothered to do his hair well. Why should I think he does his research any better?" Attacking Einstein's hair does not make his ideas any less valid. If you had material objections to the OP, you'd probably get a more congenial response.
3: I will admit, I had read his other responses in this thread, and intentionally chose to provoke a dismissive response by presenting something on the verge of being immaterial. I even apologize to anyone at the Cambridge Security Lab for any disrespect.
I don't apologize for being irreverent towards tptacek and the Cambridge Security Lab. I still think my core point, "This security lab's tendency to exaggerate the seriousness of the security problem they've identified is exactly what is in question here.", was a totally material response to his original comment, "Cambridge Security Lab is not fucking around.". I also think (and intended) that even though I was trying to provoke him, my response was totally congenial and had a material point and therefore acceptable, while he should not have been so dismissive in response, to me and to everyone else.
http://en.wikipedia.org/wiki/Ross_J._Anderson http://en.wikipedia.org/wiki/Markus_Kuhn http://en.wikipedia.org/wiki/Steven_Murdoch
...and http://www.lightbluetouchpaper.org/ ; I am unaffiliated with Cambridge other than knowing a few of the people there.
"These are good guys. This paper is the real deal."
I appreciate what you bring to HN, but that this is the top comment worries me, particularly when it comes to security of all things. There's valuable comments that are contrary to your opinion surrounding you, and I wish you'd explain your side a bit more clearly in cases like this.
It isn't just this particular instance that is driving my comment (in which I acknowledge your reputation, and nobody else's, a small oversight in your reply). The driving force is more your showing up in threads, saying something either plainly obvious or, worse, absolutely confusing, and then expecting your reputation to carry your comment the rest of the way. Most of the time, the reasoning behind your comment is completely unclear. It isn't avoiding drama to elaborate, it's making your point clearer and not relying upon a name you've created for yourself in this community when the rationale behind your opinion is unclear to those of us without your ability. The other comment that annoyed me recently, and most front of mind, was this one about nginx[1]:
"This is a very bad bug, and you should fix it ASAP. Don't wait."
Two things here:
1. Thank you, Captain Obvious. What an enlightening comment.
2. What does "very bad" mean?
The actual situation related to that vulnerability was much more complex, and the threat fairly small. You, however, glossed right over that and skipped to basically informing the lay to panic, then got really snarky when people questioned you on the motivation. I don't believe that making the lay panic is the right way to achieve greater security, regardless of your credentials, and this is one of those cases where the reasoning behind your comment would have gone a long way.Think about what a novice admin walks away from that comment with. Yes, he upgrades, awesome. That's exactly what we expect of administrators. There's something more sinister underlying your end result, though, which is that you've trained an administrator to act on what you and other security professionals say when it comes to security, without any explanation or reason. Security would be a much better place if people started gaining the ability to think for themselves and understand the issue, and you're working to reverse that. I see this crap with bcrypt, too. "Just use bcrypt." "Why?" "Because smart people said so." Now what if you fuck up? What if you give bad advice?[2] Half of this community is going to take you at face value, because you don't present supporting facts for your position to be debated openly. Because it's 'tiring'.
You are quite unmatched in the security arena with your technical prowess. There's no question of that. It's comments like these, however, that make me annoyed that you're using said reputation inappropriately, and any questioning you receive on the matter leads to single-sentence snark like the pointless gray comment in this thread. Before asking why I commented, consider your own comments and the different standard you hold your own commentary to in this forum.
[1]: http://news.ycombinator.com/item?id=3709269
[2]: I fully expect a snarky reply to this hypothetical, so make it good.
I think if you use the search box at the bottom of the screen, you'll have no trouble at all finding thousands and thousands of words spelling out in great detail what I think about bcrypt.
I am a person, not a web service. You cannot file bugs every time I don't provide exactly the comments in exactly the tone you're looking for. Or, as you're amply demonstrating, you can, but it's unlikely to do you any good.
If tptacek or anyone else wants to speak in Zen koans and leave it up to motivated readers to figure out what he meant, so be it. No one owes anyone anything here, and you should think of it as a chance to sharpen your research and investigative skills.
But seriously, omit the entitlement and drama. It's the last thing HN needs.