BlueHat IL 2019 - Andrew "bunnie" Huang - Supply Chain Security: "If I were a Nation State...”

  Рет қаралды 18,342

Microsoft Israel R&D Center

Microsoft Israel R&D Center

Күн бұрын

Where did your computer come from? How many hands could have touched your machine before you powered it on for the first time? They say it takes a village to raise a child; it takes several countries to build a cutting-edge computer. Last October, a report released by Bloomberg Business Week dramatized the security risks incurred by our increasingly global supply chains. Although many details of the report have failed to hold up under scrutiny, the basic scenario is realistic.
In this talk, we will calibrate expectations about how difficult (or easy) it may be for actors ranging from rogue individuals to Nation-States to infiltrate various points of our global supply chain.

Пікірлер: 10
@Foggen
@Foggen 5 жыл бұрын
The component substitution thing is something I had to deal with in my last job. The STB hardware partner quietly substituted an off-brand voltage regulator that was being used to deliver power to a QAM tuner module, but would overheat under normal load. As a result the production boxes (and not the dev boxes!) would mysteriously lose lose tuner lock after being plugged in for about 30 minutes. We chased down all kinds of possible firmware and SOC overheating issues, but eventually I noticed that this one tiny component looked slightly different and was able to prove that it lost voltage when hot. The result was the hardware partner having to send an engineer with a heat gun to stand there and hand-swap 5000 surface mount components in a dimly lit shack on the customer's home island. What a fiasco.
@delcapslock100
@delcapslock100 4 жыл бұрын
Amazingly clear and detailed insights into the supply chain security threat.
@praxis22
@praxis22 5 жыл бұрын
Cory Doctorow sent me here, 45 mins well spent. Cheers!
@Supplychains
@Supplychains 5 жыл бұрын
Wow! I really enjoy this video :)
@sonithkumar5832
@sonithkumar5832 5 жыл бұрын
Pity this doesn't have more viewers. :(
@akiko009
@akiko009 5 жыл бұрын
Agreed as to the comments on the Supermicro hack. The implant as described in the BW article made no sense, and given that something appears to have happened, it was obviously one of the other attacks and the friendly government alphabet soup doesn't want to give away methods as if they were that secret. One of the best ways to reduce (or at least shape) the attack surface is to stick to sourcing and manufacturing in the US. Digitally signed reel labeling and tracking should be a common best practice for active components. And caveat emptor to anyone who uses closed source hard/soft/firm/etc. -ware developed in China.
@kellyanquoe
@kellyanquoe 5 жыл бұрын
if we could merge this into a rave format people might watch. he is kinda hot
@tonylee5168
@tonylee5168 Ай бұрын
So you were using a China brand "Lenovo" laptop to present security!!!???
@imbw267
@imbw267 5 жыл бұрын
In short, everything is terrible and we're all screwed.
@kefsound
@kefsound 4 жыл бұрын
Microsoft Israel? Urgh
36C3 -  Open Source is Insufficient to Solve Trust Problems in Hardware
1:00:46
3M❤️ #thankyou #shorts
00:16
ウエスP -Mr Uekusa- Wes-P
Рет қаралды 14 МЛН
Looks realistic #tiktok
00:22
Анастасия Тарасова
Рет қаралды 96 МЛН
I CAN’T BELIEVE I LOST 😱
00:46
Topper Guild
Рет қаралды 108 МЛН
The Hacktivist, Award Winning Short Film Documentary
35:07
Singularity University
Рет қаралды 524 М.
GOD MODE UNLOCKED - Hardware Backdoors in x86 CPUs
51:00
Black Hat
Рет қаралды 307 М.
Guarding Against Physical Attacks: The Xbox One Story - Tony Chen, Microsoft
58:05
Platform Security Summit
Рет қаралды 74 М.
BlueHat IL 2019 - Luca Todesco (@qwertyoruiop) - Life as an iOS Attacker
43:12
Microsoft Israel R&D Center
Рет қаралды 14 М.
The Thirty Million Line Problem
1:48:55
Molly Rocket
Рет қаралды 244 М.
35C3 -  Modchips of the State
36:52
media.ccc.de
Рет қаралды 40 М.
Technology is Not Magic - bunnie Huang, Bitmark Ambassador #2
7:27
Самый дорогой кабель Apple
0:37
Romancev768
Рет қаралды 337 М.
Спутниковый телефон #обзор #товары
0:35
Product show
Рет қаралды 2,2 МЛН
iPhone 16 с инновационным аккумулятором
0:45
ÉЖИ АКСЁНОВ
Рет қаралды 8 МЛН