Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Justa; jrestrepo; NVDave
So now we all agree! Like I was saying...

That is from your "rebuttal" link, Justy.

Ok? So now we can all agree that the article of the original thread is about fraudulently copied functional equivalents, and not Chinese espionage like Sergei Impliedalotovstov says he's not alluding to. And we can agree that your rebuttal's author Sergei found a method to read out Actel's FPGA programming....which would allow certain data to be read if you could clip wires onto that physical system.

Wooptiedoo! Anyone who has ever fired up an evaluation board with a microcontroller or FPGA from Actel or Xilinx has known this for decades.

I've already mentioned upthread a more glaring, public, non-hidden problem with FPGAs which have the ability to be programmed via serial links and networks. So yeah, those systems could be vulnerable to cyberattacks from Korea or Russia or Israel or China. But that is coming from insecure design and development of the intended, advertised product MADE IN THE USA. Not Chinese "backdoors" in resistors!

But Sergei Wrotealotovrot did a smart thing by fanning the espionage flames. Otherwise his "expose" of an obvious internal exploit for a particular US design would've gotten ho-hum interest from anyone who knew anything about JTAG programming of FPGAs. BTW, you realize that the engineers who implemented that JTAG logic function have a design spec internally, and they have a Verilog or VHDL description of it, and tested it internally. Anyone who worked on that project knows everything Sergei Didalotovnada learned, and was not under any kind of military clearance, and might not have even had a non-disclosure agreement with respect to emailing it to a colleague, customer, student or chinese spy!

176 posted on 05/30/2012 12:54:31 PM PDT by sam_paine (X .................................)
[ Post Reply | Private Reply | To 174 | View Replies ]


To: Justa; jrestrepo; NVDave
Let me try another analogy since not everyone is a JTAG jockey.

There is an OBD-II test port under your dash in your car. Sergei Solderingiron could go to the dealer with your car and tap on to the link while the dealer connects his diagnostic computer, and Sergei could write a paper about undocumented OBD-II registers on your particular ECM.

That ECM and/or other chips in the car may be made in part or in whole in China. Some of the components may even be fraudulent copies of legitimate chips.

Sergei may have another interesting paper, and Sergei may be able to even write some registers to lean out your engine and burn a valve if you let him in the car and let him reprogram it.

But nobody in Beijing can flip a switch and make your car go dead in an intersection!

Test Port ≠ Remote Backdoor

177 posted on 05/30/2012 1:10:13 PM PDT by sam_paine (X .................................)
[ Post Reply | Private Reply | To 176 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson