Sergei Skorobogatov, a postdoc in the Security Group at the Computer Laboratory of the University of Cambridge has written up claims that reprogammable microchips from China contained secret back-doors that can be used to covertly insert code:
Claims were made by the intelligence agencies around the world, from MI5, NSA and IARPA, that silicon chips could be infected. We developed breakthrough silicon chip scanning technology to investigate these claims. We chose an American military chip that is highly secure with sophisticated encryption standard, manufactured in China. Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip. We scanned the silicon chip in an affordable time and found a previously unknown backdoor inserted by the manufacturer. This backdoor has a key, which we were able to extract. If you use this key you can disable the chip or reprogram it at will, even if locked by the user with their own key. This particular chip is prevalent in many systems from weapons, nuclear power plants to public transport. In other words, this backdoor access could be turned into an advanced Stuxnet weapon to attack potentially millions of systems. The scale and range of possible attacks has huge implications for National Security and public infrastructure.
Key features of our technology:
* scans silicon/hardware for backdoors, Trojans and unexpected behaviour
* low cost
* very fast result turnaround time
* high portability
* adaptable - scale up to include many types of chipFurther funding is needed for us to progress to testing further silicon chips and to develop better search algorithms which would allow us to detect possible spy systems or vulnerabilities in a greater range of systems.
Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China), or indeed if the specifications themselves contain a deliberately inserted potential threat.
This block of text is undated, though it appears on a page whose last-modified date is reported as 14-05-2012. I couldn't find any further information on which chips were affected or the methodology used to discover the backdoors.
Hardware Assurance and its importance to National Security (via MeFi)
I write books. My latest is a YA science fiction novel called Homeland (it's the sequel to Little Brother). More books: Rapture of the Nerds (a novel, with Charlie Stross); With a Little Help (short stories); and The Great Big Beautiful Tomorrow (novella and nonfic). I speak all over the place and I tweet and tumble, too.
More at Boing Boing
-
http://twitter.com/fossilfuels Funk Daddy
-
http://artdonovan.typepad.com Art
-
HahTse
-
http://twitter.com/fossilfuels Funk Daddy
-
benher
-
-
Catbeller
-
http://tryingsense.blogspot.com/ R_Young
-
-
http://twitter.com/enkiv2 John Ohno
-
-
soylent_plaid
-
dragonfrog
-
Rindan
-
http://twitter.com/ccllyyddee User Signin
-
http://profile.yahoo.com/VAGTDSVES57USWD4HT6C2KXF5I jerome_ml
-
http://tryingsense.blogspot.com/ R_Young
-
-
-
-
John Maple
-
http://twitter.com/fossilfuels Funk Daddy
-
SomeGuyNamedMark
-
Roman Berry
-
http://twitter.com/enkiv2 John Ohno
-
-
http://www.facebook.com/people/Jānis-Soliņš/100001271292667 Jānis Soliņš
-
HahTse
-
invictus
-
-
http://www.brainwavez.org/about/people/watson_mandy_j.html Mandy J Watson
-
awjt
-
http://twitter.com/enkiv2 John Ohno
-
-
-
AlecMuffett
-
CLamb
-
http://twitter.com/beep54orama B E Pratt
-
-
kenneth conlow jr
-
http://artdonovan.typepad.com Art
-
http://twitter.com/incarnedine_v Dan Hibiki
-
-
Shinkuhadoken
-
Paul Renault
-
http://www.facebook.com/alasdair.lumsden Alasdair Lumsden
-
SomeGuyNamedMark
-
http://twitter.com/enkiv2 John Ohno
-
-
Slowermo
-
Culturedropout
-
-
Joe Foran
-
bardfinn
-
bja009
-
bardfinn
-
dragonfrog
-
-
jerwin
-
Steve Taylor
-
-
-
Glippiglop
-
SvenOrtmann
-
http://twitter.com/enkiv2 John Ohno
-
-
John Vance
-
bardfinn
-
-
bardfinn
-
Ryan Lenethen
-
http://twitter.com/enkiv2 John Ohno
-
-
http://twitter.com/regularfry Alex Young
-
solpatrol
-
http://twitter.com/incarnedine_v Dan Hibiki
-
dragonfrog
-
http://www.facebook.com/liz.g.dichiara Liz Gasek Dichiara
-
-
kraken17
-
dragonfrog
-
-
koko szanel
-
Glippiglop
-
spacedmonkey
-
http://twitter.com/enkiv2 John Ohno
-
-
-
MrQuagmire
-
nixiebunny
-
bardfinn
-
http://twitter.com/enkiv2 John Ohno
-
-
Sigmund_Jung
-
http://twitter.com/beep54orama B E Pratt
-
-
http://lemoutan.blogspot.com/ Lemoutan
-
http://www.facebook.com/profile.php?id=679549499 Michael Birch
-
http://www.facebook.com/profile.php?id=1627807433 Gerry Syler
-
http://twitter.com/richsadams richsadams
-
bardfinn
-
jerwin
-
invictus
-
-
-
http://profiles.google.com/marc.k.mielke Marc Mielke
-
bardfinn
-
-
http://www.facebook.com/john.bodart John Bodart
-
http://twitter.com/enkiv2 John Ohno
-
-
yri
-
http://www.facebook.com/people/Serendipity-Seraph/100000693617592 Serendipity Seraph
-
http://twitter.com/AccusedWizard Gleep-Glop
-
charles porcaro
-
dragonfrog
-
-
stuck411
-
http://www.leidentech.com leidentech
-
http://twitter.com/milkymistvj RTC Milkymist
-
http://twitter.com/enkiv2 John Ohno
-
-
Palomino
-
http://twitter.com/enkiv2 John Ohno
-
Culturedropout
-
Lion Kimbro
-
http://www.cyberspice.org.uk/ Cyberspice
-
http://twitter.com/Zenawoo Alicia Tabbara
-
benher
-
Jeff The Riffer
-
Antinous / Moderator
-










