3 ms·
Absolutely. NICs in general are a very fruitful vector for persistence, and had been extensively studied by the NSA. Generally, anything with a microcontroller
by AlyssaRowan 12y ago
Absolutely. NICs in general are a very fruitful vector for persistence, and had been extensively studied by the NSA.
Generally, anything with a microcontroller that might run firmware (BIOS or UEFI), access DMA (via PCI, PCIe, FireWire) or be a storage peripheral that might pass code to the boot process (HDD/SSD/CD/DVD/BD/Flash drive/memory card firmware, including USB) or input (USB) is a potential problem.
That is a pretty damn big attack surface, and civilian researchers are able to do this too (the only big advantages Nation State Adversaries really have is funding and occasionally vendor cooperation, although I'd expect that to be rare in this case for operational security reasons - they might get datasheets under false pretenses, however, but so could we, we just wouldn't get away with it if caught <g>).
The TPM arch isn't so much of a problem here as trying to be a solution, but it falls short and has down sides too.
Supply chain integrity is a huge, possibly unsolvable problem. I'd be interested to see however some solutions to massively complicate any such attack, like an open trusted processor which boots ROM externally readable in hardware with no override and keeps secure hash chains of the firmware that loads - again, which would be externally verifiable with no way to override in firmware. That would put a crimp in their day.
- sliverstorm 12y agoSupply chain integrity is a huge, possibly unsolvable problem. One of the arguments for domestic manufacture of at least some keystone parts, and one of the reasons IBM is still in the fab business.
- AlyssaRowan 12y agoSince those who say "domestic" usually mean USA, I'm guessing you live there. Bad news: your government is one of the attackers. (So is mine, unfortunately.) I take it you've seen the NSA interdiction guys taking discreet hacksaws to Cisco parcels en route to 'implant' (backdoor) them by now? Did you think that was something that only happens abroad?
- sliverstorm 12y agoIt's not something that only happens abroad, but to my (admittedly limited) knowledge the US is a less severe problem for a US company. That is, they snoop on you, yes. But they don't sell you shoddy knock-offs instead of real parts, they don't give intel on you to your competitors, and they don't actually attack you Stuxnet-style. (that I know of) I could be way off base, but as a US company I'd much prefer a US gov't backdoor to a Chinese gov't backdoor, and supply chains contaminated by knock-offs is a nightmare unto itself. P.S. Yes, I'm in the US, and yes, you're right about "domestic" P.P.S. IBM's fab (to my knowledge) mostly exists to serve the US gov't anyway. At least for the NSA themselves, the advantages to domestic production are there :)