free hit counter

Monday, June 14, 2010

shanzhai!



I knew about the gray market in China for cloned, counterfeit, or other wise dubious electronics for the burgeoning Chinese middle class, but didn't know it had it's own term: shanzhai

This EETimes article talks in detail about how shanzhai has evolved in the last few years: Inside a Shan Zhai GPS unit and the back door to market leadership


This is why security in embedded systems is important. Even if, as the article above contends, the shanzhai industry is moving beyond cloning other people's IP and innovating on their own, there is a group of companies with proven track records in doing what ever it takes to get the BOM cost of a device down into the range that will satisfy the huge demand from the Chinese middle class.

As a side note, Ideo even identifies shanzhai as a design pattern!

Labels:

Thursday, February 04, 2010

Software Security: cooler than once thought



So I used to think software security was a nuisance, getting in the way of what you really want to do. However, now I'm starting to see the light, and am finding it fascinating.

Companies are spending tremendous amounts of money developing and using software IP and thinking they're protected just because it's packaged in a chip and not on some windows machine hooked up to the internet. However, just because it's in silicon doesn't mean it's safe.

This is a good intro article:
Software protection introduction

Glitch attacks, as introduced in Glitch Attacks Revealed , and really explained in “The Sorcerer’s Apprentice Guide to Fault Attacks” by Bar-el et al, explains why encryption done on an insecure processor without any countermeasures may be due diligence but is not protection against a determined attack.

These guys at FlyLogic talk about relatively low budget (<$5k) methods for de-capping and etching away metal layers to do things like find UV-resetable fuses, bridge burned out fuses with micro-probe wire, and read ROM bits directly. A ”backdoor” has been discovered by Flylogic Engineering in the Atmel AT88SC153 and AT88SC1608 CryptoMemory.

Labels:

Monday, January 08, 2007

security lifecycle

Security isn't something I like to think about, but for applications that have a large number of users it's a real consideration.

This artical talks about not just about the act of 'securing code', but about integrating it into your development process.


How Do They Do It? A Look Inside the Security Development Lifecycle at Microsoft -- MSDN Magazine, November 2005

good links:
application verifier
PreFast
SAL

Labels: ,