Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Meet FPGA: The Tiny, Powerful, Hackable Bit of Silicon at the Heart of IoT

Field-programmable gate arrays are flexible, agile-friendly components that populate many infrastructure and IoT devices - and have recently become the targets of researchers finding vulnerabilities.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
MatthewG570
50%
50%
MatthewG570,
User Rank: Apprentice
9/6/2019 | 8:26:17 AM
HDL / Bitstreams and other ramblings
I started reading this article instead of just skimming it when I came across the use of "hardware definition language" as hardware description language is considerably more common in the 21st century.  Calling a bitstream HDL is like calling an ELF binary file assembly language code at best. Bitstreams are incredibly difficult to hack, though not impossible. Machine code for a CPU is easy, bitstreams are a whole different animal, making exploiting FPGAs much more difficult and typically requires completely re-writing the NVM on which the bitstream resides via JTAG or some other means. Specialized hardware is almost always required to exploit an FPGA, except in the increasingly common scenarios where USB to JTAG interfaces are put on the product itself just as they are on many developer kits.

FPGA experts are not common. Care needs to be taken in not only the development of the HDL but also the electronic circuit design around the FPGA to harden a system. Careless HDL developers using reference hardware designs from FPGA manufactureres will result in many more exploits akin to those found to date. 

 
   OVER THE EDGE
Building Cybersecurity Strategies in Sub-Saharan Africa

Filmed for Dark Reading News Desk at Black Hat Virtual.

LAURA TICH: We have that imbalance, where the big organizations are more protected, where the smaller ones -- which are the most common businesses in the region -- they are least protected... Sometimes they do get the tools, they do get the funding to buy some critical tools, but there's a lack of skills to handle or people who understand how to work those tools. So there are a lot of factors that contribute to our growth -- or lack thereof -- in the cybersecurity industry.

 

Name That Toon: 'Rise' and Shine
Flash Poll