Hardware Security: From Sand to Stone by Quintus Kilbourn | Devcon SEA
Devcon·Thu, Oct 9, 2025, 12:00 AM
Speaker
All software runs on hardware. The assumptions on which many of our systems rest are often shakier than we realise. This talk explores hardware security, its shortcomings and the path to a firmer foundation. Speaker(s): Quintus Kilbourn Skill level: Intermediate Track: [CLS] d/acc Discovery Day: Building Towards a Resilient Utopia Keywords: Decentralization, Hardware wallets, Security Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] hello everyone um my name is quintis I'm from the flashboards research team and today I'll be talking about secure Hardware um the sort of premise and the context for this talk is that uh as the quote goes software has eaten the world and as most of you may know software doesn't run literally in the cloud uh it always runs on some actual so some actual hardware and so all of the digital technology that we rely on uh today um actually means that we rely on Hardware uh and so this applies to the cars that keep us on the roads the planes that keep us in the skies our Hardware wallets and our you know somewhere safe I guess your your password manager on your phone the server your bank runs on all of that um every time we use these Technologies we make the assumption that the hardware that is supporting this this technology is actually working in the way we expect it to work um and is not actively working against us um but this Foundation is not nearly as secure or rather we have no reason to believe that is secure um and that's kind of the the topic of the talk today so this is um from Ledger's website for those of you who may not know Ledger is a very popular Hardware wallet now Ledger has every incentive to convince their customers that they are super secure and that the hardware um is you know serving you and protecting your keys um but if you if you look at their website what is actually the case is that even their low-level software some of it has to be closed along with the full Hardware design um so this means that you are trusting the U Hardware providers your trusting Ledger um that the um Hardware is not uh doesn't come with a back door that it actually has the defenses that you expect it to have um and this isn't a a ledger specific issue um because of the difference between the open Hardware uh open source design open fabrication process um because of the difference between that cluster of things and the closed alternative Hardware companies have this choice between more secure more performant more cost efficient um products and improving their trust assumptions and the difference is so stock that pretty much everyone has to at some in some way choose the more efficient outcome and uh take on board these trust assumptions now the the reasoning behind this is is um quite sound in some in some regard the user mistakes software bugs um all the thousands of hackers out there who don't have access to your device these are more legitimate threats and if we were trying to secure a system tomorrow these are the attacks we'd spend most of our time on um the more difficult attacks uh that can be executed by fewer actors are much less likely and these are the the attacks require access to the hard Ware or um to be implanted in the manufacturing process but I don't think that this is actually a good reason to dismiss um worrying about Hardware security and one reason for that is that they actually just have been a lot more um vulnerabilities than people have realized or that you know I was aware of before I looked into this um and you have to ask yourself if there are examples of governments implanting back doors into Hardware of um you know corporations potentially under the influence of governments uh implanting these kinds of back doors um what reason do we have to believe in this world where all of the hardware is closed anyway that there aren't like active Hardware back doors active troan Among Us right now like in this room um and then another angle to this is just that you may not expect a hardware manufacturer or someone in the hardware supply chain to be malicious but they could just be lazy they could be selling you chips that are not um up to scratch uh and so you expect to get a certain level of of uh protection when you buy this this hardware and in reality it is just a much lower uh much lower degree of protection and you have no way of of validating this or it's much harder to validate and this is um an example from one particular study a couple years ago so one part of my motivation here is like this old piece of wisdom that uh if you're going to build something you want to make sure that the assumptions that this system eyes on are strong because when the going gets tough uh and your foundation is not strong things collaps pretty remarkably um and I guess the image I always have in my mind as you think of all these these cars on the roads all everyone who's using a ledger so so such so much value in the crypto ecosystem um that's you know could be attacked in one uh felt swoop I guess but another more optimistic take on this uh sort of securing this this uh rant I I would say this talk is um in favor of securing Hardware is that there is um a growing movement uh I guess in the crypto ecosystem and outside of it like the open quote I have up there to use um assumptions in Secure Hardware to actually do more than we have been able to today um we are in an industry of improving uh trust assumptions and secure Hardware provide us provides us with another primitive to improve these trust assumptions and unlock new use cases um and so if if if we are able to improve these uh trust assumptions in the hardware um we will actually be able to do more with that uh to fac to facilitate trust in more performant use cases that cannot be served by traditional cryptography or to uh bolster the security that um um yeah to Bolter the security assumptions that go behind the software Crypt cryptography uh schemes we use like uh you know honest majority assumptions and NPC protocols so I'm not here today to just say that this is something that we should pay attention to I am here to say that this is something we should pay attention to and that it is something that we actually can do something about there is no technical reason or yeah no obvious technical reason that we cannot uh address this problem and to make that case I'll I'll briefly go through some of the research that's out there today um that taken to its completion con constitutes some of the puzzle pieces that we can put together to solve this problem so we can break break out this problem for um most Hardware uh into two sub problems and then I'll I'll speak about two other ones but um the first is taking a piece of hardware and being a able to actually look at it and see what is going on Imaging this piece of hardware and the other is having something to compare that image too there's no point in being able to look at a piece of hardware and see all of these you know wires and transistors and uh not being able to compare that to something for which we understand the logic so first understanding the Imaging um I'll point to one sort of research Direction uh pursued by a guy a legend uh called bunny um and for context what has been the issue in the uh Hardware Imaging world for a while or like one of the issues um is that Imaging techniques are destructive or very very expensive um what bunny has pioneered is using shortwave infrared light to image chips without having to destroy them without having them to ship them to having them shipped to a facility in Switzerland the size you know several homes um and this is actually something that we ideally could scale uh so that there's testing facilities in you know multiple in a city and maybe some running at home if you're very serious about it um as for a reference this is a this is a really challenging problem and probably the one that we as an ecosystem can put um much of our weight behind um currently as I was alluding to earlier so so much of the technology that we rely on is closed um and there are projects that are taking this problem on headon and are directly working on either developing their own open- source IP or on I guess purchasing from other people um and they are moving this barrier of trust lower and lower and lower but still they have not been able to open um open source the information we'd need to be able to assert that this uh this piece of Hardware does not contain contain a hardware back door and their motivations are are pretty pretty uh pure from the other open source uh angles they want people to be able to iterate on their designs and to not be worried about vendor lockin but the security angle is still not completely addressed and so one thing we can keep we we can do is we can add our weight to this um to this movement and and push for completely open source designs but there are also um many pragmatic ways to get around this problem um in which we navigate uh without going into the details we navigate this problem of having um you know Fabs which don't allow for the low-level design descriptions of chips to be made public um to to uh circum circumvent these these closures using ZK proofs of uh chip validity and and other forms of proofs and I'll I'll link to something at the end that goes into that and so the sing these two problems solves the the easy case and so um this solves a case for Hardware that you have physical custody of this is for your phone for your leder um and this solving this has already like changed the world I would say um but I was talking about tees earlier uh and using um secure Hardware to be able to assure someone who doesn't have physical access to the device that the hardware is is uh operating correctly to address this problem we need to solve two other sub problems one is how we generate a key and tie it to the hardware in such a way that we can be convinced that the key is not compromised and is is uniquely available to the logic and the hardware um the sort of magic answer here is Puffs which are really interesting technology that use the inevitable Randomness in the uh manifestation of the chip in the physical chip to uh create a secret and so anyone trying to investigate the chip to get to the secret inevitably disturbs the chip structure destroying the key um pretty cool technology uh and one that has actually been tested out there there are existing Puffs in the world today uh it's not like Spacey magic um then on the attestation front the question is how do we uh now allow someone to investigate a physical chip and then convince a remote user who doesn't have access to the physical chip that this chip is is what they expect it to be um and in order to do this uh there are actually some investigation protocols some verification protocols that we can Implement where the user has to only assume that some threshold of actors in a committee is honest or rational uh and there's you know we've proposed oneic specific protocol for doing this but there are many um improvements that can be made to it and so I'll I'll encourage you to to have a look at that the real point that I was make that I wanted to make today is that look this is a a very important problem and it is a problem that we can solve we've mapped out some of the technologies that can solve these problems we've mapped out the these sub problems that need to be addressed to enable these Technologies what's really left um and obviously there's a lot of work left is energy to do it buying from the community and if they if that the large Hardware companies that make trillions of dollars in their incumbent position with the world relying on them trusting on them have no incentive to move from where they are in their comfortable position if there are if there are a group of people who can move the needle and breathe energy into this it should be the group of people who are working on trustless Technologies and the group of people who are trying to improve the trust assumptions in the world and have the ideological orientation of the people in this conference venue so this should be something that we care about because it's it is an important thing that we actually can make a difference in and so I guess my my first call to action is to go look at this post that um several of my co-authors and I put out where we go into more detail about what I was describing now um there are many there are several academic research teams that are moving the frontier they need funding there are several problems that people with the like formal method skill sets with Hardware design skill sets in this room can address and I think even more broadly just having this be acknowledged as an important
Automatic transcript — names and jargon may be misspelled.