On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

November 14th, 2007

National Security and the PC

Posted by Paul Murphy @ 12:18 am

Categories: Enterprise Policy, Government, Infrastructure, Security

Tags: Security, Integrated Circuit, PC, Paul Murphy

The best thing about being an intellectual right-winger is that I am, of course, always right -something that can’t generally be said for everyone. In particular it can’t be said for a guy named Lewis Page whose report: DARPA looking to verify imported military chips, on the Register starts off like this:

DARPA*, the mad-as-a-bottle-of-crisps Pentagon warboffinry operation, has struck again - this time awarding a $13m contract to the University of Southern California to develop technology which will ensure that imported integrated circuits (ICs) used by the US military are trustworthy.

As he notes, the material he’s using to express his ignorance came from an earlier report blogged on the Aviation Week site by Catherine MacRae Hockmuth. That report gives more information and cites original sources, quoting, for example, this bit, apparently from a 2005 report:

These trends have raised concerns regarding U.S. weapons systems reliance on high-performance ICs and the potential vulnerabilities of these systems caused by malicious manipulation of hardware and software processes that could render them inoperable at some future time. This situation is true for some ICs currently in use, such as Application Specific Integrated Circuits (ASIC), and for commercial-off-the-shelf (COTS) configurable parts, such as Field Programmable Gate Arrays (FPGA). Furthermore, protecting intellectual property and military secrets is problematic because these are often embedded in the design of ICs, and the manufacturer in the fabrication process often needs the details of the designs.

I hadn’t previously seen this report - but the relevance to PC security should be obvious. Commercially available Intel based personal computers are built with components whose contents you can neither audit nor trust. Do you know, for example, everything the software on your PC NIC card does? How about that cute little Chinese made router/modem your cable company just installed in your home? If your graphics card is supposed to have 128 “processors” in its array, can you prove that one of them doesn’t have a few extra circuits? If you run any hypervisor or other virtualization toolset, can you prove that it isn’t running as one instance of another?

I don’t think you can - and I’m very glad to see some serious people worrying about this because the bottom line is simple: if any programmable component of any network connected device in your business is untrustworthy, then so is your whole network.

Paul MurphyPaul Murphy (a pseudonym) is an IT consultant specializing in Unix and related technologies. See his full profile and disclosure of his industry affiliations.


Email Paul Murphy

Subscribe to Managing L'unix via Email alerts or RSS.

  • Talkback
  • Most Recent of 25 Talkback(s)
Well, yes it was Los Alamos but
the lab was operated by Lawrence Livermore Laboratories, a subsidiary of UC-Berkley. And, after about two years of misleading press releases and outright lies by the US Dept of Jutice and FBI, nothing... (Read the rest)
Posted by: fire1 Posted on: 11/19/07 You are currently: a Guest | | Terms of Use
And not Sun?  Erik Engbrecht | 11/14/07
That's right - although...  murph_zZDNet Moderator | 11/14/07
That's right - although...  aussieblnd@... | 11/14/07
Well, let's just go back to the abacus  jpr75_z | 11/14/07
Once again you mislead!  ShadeTree | 11/14/07
Nope (sorry happy )  murph_zZDNet Moderator | 11/14/07
What about the keyboard? Display? Network chips? Etc?  Erik Engbrecht | 11/14/07
Agreed - there are protections.. but  murph_zZDNet Moderator | 11/14/07
Actually, I think the threat is exaggerated  Erik Engbrecht | 11/14/07
Or a political solution to a political problem.  Anton Philidor | 11/14/07
oh? lets invent some numbers  murph_zZDNet Moderator | 11/14/07
So?  Erik Engbrecht | 11/15/07
I'd be more worried about the software  Richard Flude | 11/14/07
Re: open source - you bet - re hw vs sw? I don't think so  murph_zZDNet Moderator | 11/14/07
Chasing the hard option  Richard Flude | 11/14/07
For once, I agree  georgeou | 11/14/07
Hardware testing NEEDED  Mr_Dave | 11/15/07
RE: National Security and the PC  Steve Slick | 11/14/07
Hmmm, where did this idea come from?  fire1 | 11/15/07
China Spying in Taiwan With Hard Drive Firmware  ceh4702 | 11/15/07
Why Trust Universities in California  ceh4702 | 11/15/07
Trust  davisnewman | 11/15/07
No, that was Los Alamos (nt)  What the ...! | 11/15/07
Well, yes it was Los Alamos but  fire1 | 11/19/07
Because we have the  Linux User 147560 | 11/19/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here