3 ms·
> the only way to ensure that back doors haven't been added at the hardware level is to decap and manually validate every chip. Not good enough. It's possible
by AnIrishDuck 13y ago
> the only way to ensure that back doors haven't been added at the hardware level is to decap and manually validate every chip.
Not good enough. It's possible to insert trojans by changing the dopants on the silicon [1], which can't be detected with the decap-and-scan method. From the paper:
> our dopant Trojans are immune to optical inspection, one of the most important Trojan detection mechanism.
You really need to trust the people making your hardware, full stop. There are too many holes with even a trust-but-verify approach.
[1] http://people.umass.edu/gbecker/BeckerChes13.pdf http://people.umass.edu/gbecker/BeckerChes13.pdf
- jacquesm 13y agoThat totally blows me away. What you see really isn't what you get, even if it looks just the same as before.
- r4pha 13y agoThis is really scary. The fact that the collected data must be sent either through the wire or through the air at some point would make the trojan detectable - perhaps when it's a too late, but still detectable - wouldn't it? A related history was posted on reddit a few days ago, about a user identifying his HP notebook sending away his built-in microphone data [0]. [0]: http://www.reddit.com/r/RTLSDR/comments/1le3if/so_i_discovered_that_my_hp_laptop_leakstransmits/ http://www.reddit.com/r/RTLSDR/comments/1le3if/so_i_discover...