4 ms·
Are we ready for Stuxnet round 2?
by engcoach 3y ago
Are we ready for Stuxnet round 2?
- bob1029 3y agoI don't think something so sophisticated would be required in this case (but it would definitely do the trick). Semiconductor manufacturing is easily the most fragile industry on earth, inclusive of nuclear and aerospace. If you wanted to completely cripple a fab, you wouldn't need a fancy computer program. All you would need to do is sneak some copper dust into a filter for an air handler and wait for chaos to emerge from yield analysis a few weeks (or months!) later. It wouldn't take much. An amount trivial to get past security. IIRC, Intel had incidents that could be traced back to fertilizer being spread a few counties over. The amount of time it takes to perform this defect analysis is what an intelligence agency would want to target in its activities. Without stable root cause analysis, no practical forward decision making can happen. You can easily get trapped in a vicious cycle of complexity. Getting the fab clean again from this kind of contamination would be like starting over in many ways. You'd have to redo some recipes (because you'd have to throw away some tools) and many of your statistical baselines would be completely fucked - semiconductor mfg relies on statistical process control that takes time to settle, which is why you hear this term "ramping" a lot in the business. For flash memory or older LSI process nodes, you could recover a lot faster. When you are already operating at the bleeding edge, the slightest amount of malice is like the end of the universe by comparison.
- nebula8804 3y agoFascinating comment...but whats preventing China from performing the same actions against EU or American rivals? Surely the second biggest economy has the "potential" capability to damage their rivals in similar ways no?
- bob1029 3y ago> whats preventing China from performing the same actions against EU or American rivals? Nothing other than the automation rate. If a factory can achieve 100% full-auto (which we are pretty much at already), security becomes much easier to manage. I believe US/EU facilities achieve higher automation rates than China in practice, but that is an assumption based upon former experience in the industry. I haven't gone through fab security in over a decade, but I suspect protocols are much more intensive now.