Hacker News new | ask | show | jobs
by jmnicolas 1704 days ago
But how can I be sure the chip I have in my hand is built upon this code and that no blob has been added?
1 comments

By (1) purchasing anonymously from retail sources, and

(2) having researchers with anonymous retail samples verify through decapping and inspection. I believe der8auer in Germany does die shots -- it would not be a bad idea to kick start this kind of research for community assurance purposes.

It's difficult to prove there's no hidden logic, but it's also not trivial to hide complex logic needed to introduce covert undetectable vulnerabilities (probably around things the RNG source or crypto).

Also assuming you're a high value target, otherwise this is mostly going too far.