4 ms·
The attack is carried out on an existing product, an open source chip OR1200 that has its schematics generally available.
by lsb 10y ago
The attack is carried out on an existing product, an open source chip OR1200 that has its schematics generally available.
- flyinglizard 10y agoCalling it an "attack" is no less of an hyperbole than changing the sources of nginx to introduce a remote exploit. What this team did is to create a compromised version of an open source product. They engineered it to be defective in the first place. This is nothing beyond a thought experiment.
- ethbro 10y ago> They engineered it to be invisibly defective in the first place. That's the difference and the interesting part. Unless most people who aren't me decap their chips and go over them with an electron microscope before use...
- hexane360 10y agoA compromised version that isn't noticeably different from any other version, which could be surreptitiously deployed on a large scale.
- impdmnt2Prgrss 10y agoThere is a crucial difference between hardware development and software development that you are missing: hardware has several stages of development/implementation that spans several parties only connected by business contracts. If you want to squeeze the attack into your analogy, it would be as if a compiler writer was malicious an added an attack to any/all nginx binaries without modifying the original source code.