The Open University Relevant Knowledge programme is here.

B2fxxx

By Ray Corrigan
 


RSS Feed

Atom Site Feed




Arabic German Portuguese Chinese Italian Russian Japanese Spanish French Korean (About)


Aaron Swartz
Abusable tech ATAC
Academic Copyright
AdviceNow UK Advice service
A copyfighter's musings
Alex Salkever's Security Net
American Prospect
Andrew McLaughlin
Ariadne
Atlantic Monthly
Ananova
ARCH
ALA Info-Commons blog
Bag and baggage
BALII
Balkanization
Battle Searchblog
BBC
Berkeley IP Blawg
Berkman Center
beSpacific
Bhopal Justice Campaign
Bitlaw
Blawg Republic
Blogbook
Blogs at Harvard
Blogscript
Blogzilla Ian Brown
BNA net news
BNA Web Watch
Boingboing
Censorware Project
CDT
Chilling Effects Clearinghouse
Chronicle of Higher Education
CIA Factbook
City of Sound
Cluebot
CNN
CNet News
Consensus at Lawerpoint
Copyfight
Copyfutures
Copyright Colloquium
Copyright Readings blog
Cornell's LII
Corner House
Creative Commons
Criminal waste of space
Crypto-gram
Current bytes in brief
CyberRights UK
Cyberspace law
Daily Whirl
Dan Gillmor
Darknet J.D. Lasica
David Isenberg
disLEXia
Doc Searls
Don't link to us
Drew Clark
Economics of Privacy
Economist
Ed Techie
EDDix top 50 blawgs
E-evidence
EFF
EFF Deeplinks
EFF Minilinks
Elizabeth Rader
EPIC
Ernie the Attorney
Electronic Telegraph
Equal vote blog
Ethical Spectacle
EU Law Web Log
EUpolitix
Euractiv news
EUR Lex index
http://Euro-Copyrights.org/
Europa
EU Commission Pressroom
Europemedia
Evoting-experts.com/
Feedmelegal
footnotes
Fravia web searchlore
Freedom to Tinker
First Monday
Financial Times
Findlaw
FIPR
Froomkin
Froomkin blog
Furdlog - Frank Field
Gigalaw
GILC
Global Voices
GovNet newsfeed
Greplaw
Groklaw
Harvard Jolt
How Appealing
Ian Clarke's blog
ICANN Watch
Ideal e-government
ID theft protection blog
Importance of
INDICARE on drm
INDUCE Act blog
Infolaw
Inforlaw What's New blog
Infosoctech Alan Cunningham
Instapundit
International Herald Tribune
Internet censorship explorer
Internet Legal Resource Grp
Internet Scambusters
IP Central weblog
IPKat
IP Matters
IPRsonline portal
IP Watch
ITN
James Boyle
Jennifer Granick
Jessica Litman
JILT
Jurist
Jurist Paper Chase
Justice Talking
Kim Cameron's Identity blog
Kuro5hin
Law.com
Lawmeme at Yale
Law Society Gazette
Legal Affairs
Legal Theory (Solum) Blog
Lessig weblog
Lex Ferenda
Lex in the city iNews
Librarians' Internet Index
LibraryLaw blog
Linux Journal
Madisonian Theory
Martin W
Mercury News
Memex
Mindjack
MIT Technology Review
MSNBC
Napsterization
Newsforge
No2ID
Nolo Law Center
The Ndiyo Project
New York Times
NTK
Ofcomwatch
OneWorld
Online Journalism Review
On Lisa's Radar
Once upon a time...
On the Commons - Bollier
On the Identity Trail
Open Access News
Open Rights Group
O'Reilly
OUseful
Overlawyered UK
Pangloss Lilian Edwards
P2P policy course Berkeley
Policy Power Tools
Politech
PLoS
Posner & Becker Blog
Privacy & economics
Privacy Journal
Privacy Policy
Walt Mossberg
Phil Agre
Public Knowledge
Quicklinks
Reason
Red Herring
Reporting Civil Rights
RIP archive at FIPR
Roger Clarke
Ross Anderson
Rufus Pollock
Salon
Samuelson's cyberlinks
SANS Computer Security
Sarah Carter's lawlinks
ScadPlus Activities of the EU
SCOTUS blog
Scripting News
Shifted Librarian
Shirky
Siva Vaidhyanathan
Siva Vaidhyanathan Googlization
TalkLeft
Village Voice
Volokh Conspiracy
SciDev Network
Security Focus
Seltzer blog
Seth Finkelstein
Shifted Librarian
Silicon Valley
Slashdot
Slate
Snopes Urban legends
Spyblog
Stephen Fry
STLR
Susan Crawford
American Prospect Weblog
Tech Law Journal
The CATO Institute
The Blog of Doom
The Corner House
The Green Bag
The Guardian
The Industry Standard
The Nando Times
The New Republic TNR
The Register
The Times
The RISKS Digest
The Trademark Blog
Tony H
Townhall
UCLA Cyberspace Law
UEA law blog
UK Court Service
UK Criminal Justice blog
UK FOI blog
UK Human Rights Archive
UNESCO copyright site
Urban Legends
USACM blog
VUNet
Weatherall's law
Wikipedia
WIPO
WIPO CLEA
WJIN
xkcd
ZDNet


 

This page is powered by Blogger. Isn't yours?

Sitemeter count:

One click on a button helps feed the hungry



      Tuesday, May 13, 2008

 
From the NYT: F.B.I. Says the Military Had Bogus Computer Gear
"Counterfeit products are a routine threat for the electronics industry. However, the more sinister specter of an electronic Trojan horse, lurking in the circuitry of a computer or a network router and allowing attackers clandestine access or control, was raised again recently by the F.B.I. and the Pentagon.

The new law enforcement and national security concerns were prompted by Operation Cisco Raider, which has led to 15 criminal cases involving counterfeit products bought in part by military agencies, military contractors and electric power companies in the United States. Over the two-year operation, 36 search warrants have been executed, resulting in the discovery of 3,500 counterfeit Cisco network components with an estimated retail value of more than $3.5 million, the F.B.I. said in a statement.

The F.B.I. is still not certain whether the ring’s actions were for profit or part of a state-sponsored intelligence effort. The potential threat, according to the F.B.I. agents who gave a briefing at the Office of Management and Budget on Jan. 11, includes the remote jamming of supposedly secure computer networks and gaining access to supposedly highly secure systems. Contents of the briefing were contained in a PowerPoint presentation leaked to a Web site, Above Top Secret."

Dan Wallach makes the point over at Freedom to Tinker that the key story here is the integrity of the supply chain.
"The really interesting story is all about the supply chain. Consider how you might buy yourself a new Mac. You could go to your local Apple store. Or you could get it from any of a variety of other stores, who in turn may have gotten it from Apple directly or may have gone through a distributor. Apparently, for Cisco gear, it’s much more complicated than that. The U.S. government buys from “approved” vendors, who might then buy from multiple tiers of sub-contractors. In one case, one person bought shady gear from eBay and resold it to the government, moving a total of $1M in gear before he was caught. In a more complicated case, Lockheed Martin won a bid for a U.S. Navy project. They contracted with an unauthorized Cisco reseller who in turn contracted with somebody else, who used a sub-contractor, who then directly shipped the counterfeit gear to the Navy. (The slides say that $250K worth of counterfeit gear was sold; duplicate serial numbers were discovered.)

Why is this happening? The Government wants to save money, so they look for contractors who can give them the best price, and their contracts allow for subcontracts, direct third-party shipping, and so forth. There is no serious vetting of this supply chain by either Cisco or the government. Apparently, Cisco doesn’t do direct sales except for high-end, specialized gear. You’d think Cisco would follow the lead of the airline industry, among others, and cut out the distributors to keep the profit for themselves.

Okay, on to the speculation. Both the New York Times and the FBI presentation concern themselves with Trojan Horses. Even though there’s no evidence that any of this counterfeit gear was actually malicious, the weak controls in the supply chain make it awfully easy for such compromised gear to be sold into sensitive parts of the government, raising all the obvious concerns.

Consider a recent paper by U. Illinois’s Sam King et al. where they built a “malicious processor”. The idea is pretty clever. You send along a “secret knock” (e.g., a network packet with a particular header) which triggers a sensor that enables “shadow code” to start running alongside the real operating system. The Illinois team built shadow code that compromised the Linux login program, adding a backdoor password. After the backdoor was tripped, it would disable the shadow code, thus going back to “normal” operation.

The military is awfully worried about this sort of threat, as well they should be. For that matter, so are voting machine critics. It’s awfully easy for “stealth” malicious behavior to exist in legitimate systems, regardless of how carefully you might analyze or test it. Ken Thompson’s classic paper, Reflections on Trusting Trust, shows how he designed a clever Trojan Horse for Unix. [Edit: it's unclear that it ever got released into the wild.]

[...]

In summary, it’s probably a good thing, from the perspective of the U.S. military, to discover that their supply chain is allowing counterfeit gear into production. This will help them clean up the supply chain, and will also provide an extra push to consider just how much they trust the sources of their equipment to ship clean software and hardware."