BlueHat IL 2019 - Andrew "bunnie" Huang - Supply Chain Security: "If I were a Nation State...”

Поделиться
HTML-код
  • Опубликовано: 26 дек 2024

Комментарии •

  • @Foggen
    @Foggen 5 лет назад +12

    The component substitution thing is something I had to deal with in my last job. The STB hardware partner quietly substituted an off-brand voltage regulator that was being used to deliver power to a QAM tuner module, but would overheat under normal load. As a result the production boxes (and not the dev boxes!) would mysteriously lose lose tuner lock after being plugged in for about 30 minutes. We chased down all kinds of possible firmware and SOC overheating issues, but eventually I noticed that this one tiny component looked slightly different and was able to prove that it lost voltage when hot. The result was the hardware partner having to send an engineer with a heat gun to stand there and hand-swap 5000 surface mount components in a dimly lit shack on the customer's home island. What a fiasco.

  • @delcapslock100
    @delcapslock100 4 года назад +2

    Amazingly clear and detailed insights into the supply chain security threat.

  • @praxis22
    @praxis22 5 лет назад +2

    Cory Doctorow sent me here, 45 mins well spent. Cheers!

  • @tonylee5168
    @tonylee5168 6 месяцев назад

    So you were using a China brand "Lenovo" laptop to present security!!!???

  • @sonithkumar5832
    @sonithkumar5832 5 лет назад +1

    Pity this doesn't have more viewers. :(

  • @akiko009
    @akiko009 5 лет назад +2

    Agreed as to the comments on the Supermicro hack. The implant as described in the BW article made no sense, and given that something appears to have happened, it was obviously one of the other attacks and the friendly government alphabet soup doesn't want to give away methods as if they were that secret.
    One of the best ways to reduce (or at least shape) the attack surface is to stick to sourcing and manufacturing in the US. Digitally signed reel labeling and tracking should be a common best practice for active components. And caveat emptor to anyone who uses closed source hard/soft/firm/etc. -ware developed in China.

  • @Supplychains
    @Supplychains 5 лет назад

    Wow! I really enjoy this video :)

  • @kellyanquoe
    @kellyanquoe 5 лет назад +1

    if we could merge this into a rave format people might watch. he is kinda hot

  • @imbw267
    @imbw267 5 лет назад +3

    In short, everything is terrible and we're all screwed.

  • @kefsound
    @kefsound 5 лет назад

    Microsoft Israel? Urgh

  • @neednotapply_tv
    @neednotapply_tv 3 месяца назад

    Great Talk!
    Really Blew my mind!📟🤯