Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> and run it in an FPGA (or if you're rich, an ASIC)?

An FPGA contains way more junk than just the gate array these days.

And I don't know why you would trust Xilinx or Altera (who are way more dependent on government orders than Intel) over Intel. Or any fab, for that matter.

I think it's reasonable to be paranoid, but at some point one should do a cost-benefit analysis of the measures one is willing to indulge in. Because ultimately you will have to trust someone blindly, and that is true for both people and machines.



The back door would have to do some complicated pattern matching against the bitstream to identify potential "hook" or extraction points. Of course, built in crypto modules could not be trusted. I wouldn't trust much more than the LUTs! I could even see how a multiply block may be backdoored.


Of course, I am ignoring the proprietary tool chains in all of this. But again that depends on being able to find interesting stuff in your IP to backdoor. I would recommend using vendor IP as little as possible.

Don't use a vendor Ethernet module! I could see that as a great place to attach a scan-chain backdoor.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: