Can you reverse engineer an ASIC?

(blog.janestreet.com)

47 points | by bschne 4 hours ago

9 comments

  • zoenolan 57 minutes ago
    I thought the article was going to be about how people scan chips

    Rapid Chip Reverse Engineering Using Laser, Focused ion beams, and Scanning electron microscope https://academic.oup.com/mam/article/30/Supplement_1/ozae044...

    FIBs are also used to test modifications before doing a respin. I'm still in awe that matter can be manipulated so precisely

  • zie1ony 1 hour ago
    At my uni, 15 years ago, one postdoc reverse engineered NVIDIA chip and wrote more performant compiler. He did that by connecting oscyloscops to all chip's outputs and started with applying random current on inputs. Using ML and his genius he rediscoverd all opcodes including a few hidden ones. Eventually he got hired by some company that was doing a lot of GPU on supercomputers.
    • inigyou 1 hour ago
      You can't do that by applying random inputs to any single-chip GPU - it has far too much state. I can see that perhaps it worked on some of the early multi-chip cards - where one chip was a texture sampler, and so on.

      You'll have more luck reverse engineering the software driver first. They're not hidden, you can just open the driver files in Ghidra, the almost-universal tool for open-sourcing proprietary code. Hidden opcodes can be discovered first by just trying all the opcodes you couldn't discover any other way. You only need to go to the physical level if they're really hidden.

      • sigbottle 1 hour ago
        To be fair, Ghidra was released in 2019 and in general knowledge was still hard to find even back in 2010 I feel (well, compared to 2026 in the age of AI)
        • inigyou 1 hour ago
          Before that there was, and still is, IDA Pro. Works largely the same but costs a lot, on the order of $1000/seat/year. Useless for hobbyists unless pirated, but reasonable if it's your job. Probably had academic discounts.
    • tverbeure 1 hour ago
      There is absolutely no way that happened. 15 years ago, we're talking Fermi class GPUs and chips with hundreds of millions of bits of on-chip state and much more if you include the DRAM.

      You can't tease out the right information by applying random inputs. Which input would you even use? The PCIe interface? You'd first "randomly" need to get past its complex training sequences...

      Your postdoc probably wrote micro-benchmarks of some sort. That is a common technique.

      • kjs3 44 minutes ago
        And you don't use an o-scope in anycase, since you'd need...what...a thousand of them to watch all the signals. You'd use a logic analyzer. I think I read somewhere that those older nvidia chips had something like 2000 BGA balls, and Tektronix does make an LA that can scale to 2000-something channels (TLA7000), for a modest US$500k or so. Then you gotta figure how to mount the thing to attach the probes.

        So...agreed...far more likely there was a software solution of some kind if this happened.

    • pixelatedindex 36 minutes ago
      “oscyloscops” is a way better spelling I gotta say.
  • mentat 47 minutes ago
    30 minutes with /goal for the solution from Sol w/ high.
  • whitten 2 hours ago
    Is there something like an Extract-SPICE tool that takes a circuit and gives you back a text rendering of it ?
    • Joel_Mckay 1 hour ago
      Practically No, the stack-up of metal layers often hides the gate structures underneath, and the billions of process cells may not all be the same.

      Theoretically Yes, as an ion-beam-mill and electron-microscope combination machine can slice up semiconductors layer-by-layer. Given these machines can often also give precise x-ray analysis material data, the exact makeup of the chip can be extracted by competitors given enough time. =3

      • saltcured 1 hour ago
        Now you're making me imagine some kind of 3D-scanning, confocal x-ray fluorescent spectroscope.

        Or maybe some kind of hybrid of x-ray microtomography and spectroscopic analysis all in one.

        But, maybe the energies involved would be about the same destructive power as some microtome slicing technique...

  • NooneAtAll3 2 hours ago
    looks like they didn't post any blog post about 2nd NN challenge (https://huggingface.co/spaces/jane-street/droppedaneuralnet)

    I was waiting for some writeup about permutation decyphering

  • q3k 1 hour ago
    In a simplified scenario (not too far from this)? Yeah, we've done that in CTFs almost a decade ago.

    https://blog.dragonsector.pl/2017/10/?m=1

    • inigyou 1 hour ago
      From where do I know the name Dragon Sector and q3k? You aren't the ones who hacked the train DRM, are you? Or maybe active in the demo scene? Or maybe I'm just confusing you with TRSi?
      • q3k 1 hour ago
        Maybe. :)
  • IshKebab 2 hours ago
    That sounds like a fun challenge. Feels a lot more tractable than the neural net one.
  • ck2 2 hours ago
    people who can do this stuff are super-smartypants

    but reminds me how we're going to find out on an industrial level when the Saudis give China some nvidia chips they were grifted

    they've cloned lots of chips before but nothing that advanced

    • inigyou 1 hour ago
      You can do this. If you commit the whole next month to it you'll make quite some progress. But you won't.
      • bofadeez 25 minutes ago
        Just use Fable and get it done in 1-2 hours. It's only $1 per M tokens and way more competent than you will ever be.
    • inigyou 1 hour ago
      China has no shortage of Nvidia chips. It costs nothing (relatively) for someone to just buy a 5090 off the shelf and send it there.
  • inigyou 1 hour ago
    Is this the chip they used to steal money from the Indian stock market until they got banned from India?
    • perching_aix 1 hour ago
      They're not banned; their trading restrictions were temporary and have been since lifted, once the allegedly unlawful gains were deposited into escrow, just like SEBI demanded. They simply did not resume trading there even afterwards, for the obvious operational risk reasons.

      Their market manipulation is further alleged, not settled. It was also not a high-frequency trading thing, so no, it wouldn't have required anything technically advanced like this either (not that this chip would exist yet anyhow).

      It's so tiresome to read asinine comments like this, that are clearly not submitted in earnest. I have a hunch it took me way more effort to investigate your insinuations than you've ever spent thinking about this.