← 返回 Avalaches

今年的 Defcon 駭客大會打破傳統,不僅提供精心設計的會議徽章,更將重點放在硬體內部,由知名硬體駭客 Andrew "bunnie" Huang 打造了名為 Baochip-1x 的開源晶片。這款微控制器歷時三年開發,旨在提升運算的安全性、透明度與信任感,其作業系統、韌體與處理器核心等原始碼皆已在 GitHub 上公開。有別於傳統封裝在不透明塑膠中的晶片,Baochip 的設計允許紅外線穿透矽晶片背面,讓研究人員能直接以視覺檢查其內部結構,確保製造過程中沒有被植入後門,解決了長久以來的供應鏈信任問題。

打造這款晶片的契機源自於 Crossbar 公司與 Huang 的合作,雙方透過共享晶圓製程大幅降低了高昂的製造成本,而 Defcon 創辦人 Jeff Moss 的願景則促成了這款晶片在徽章上的首度大規模發行。Moss 強調徽章應該具備超越大會期間的實用價值,因此 Baochip 的核心模組被設計為可拆卸式,能夠作為 FIDO 硬體安全憑證或密碼管理器使用。它內建的低解析度相機專為掃描 QR code 以進行身分驗證而設,完全符合大會的隱私規範,同時徽章仍保留了互動性強的 LED 燈光功能,鼓勵與會者進行社交互動。

在安全性方面,這款晶片運行以 Rust 編寫的作業系統,具備安全啟動功能、真亂數生成器,並採用了比傳統快閃記憶體更難以被實體提取資料的電阻式記憶體(RRAM)。儘管 Huang 對其抵禦遠端攻擊的能力深具信心,但他也不諱言,擁有龐大資源與精密硬體分析實驗室的對手仍可能將其攻破。透過在 Defcon 發表,Huang 期待與會者能對這款晶片進行壓力測試並找出潛在漏洞,從而在未來推動其支援 Linux 或發展成硬體安全模組(HSM),讓開源安全晶片的技術持續進化。

Breaking from tradition, this year's Defcon hacker conference shifts the focus from elaborate badge designs to the internal hardware by introducing the Baochip-1x, an open-source chip created by renowned hardware hacker Andrew "bunnie" Huang. Three years in the making, this microcontroller aims to advance computing security, transparency, and trustworthiness by publishing its operating system, firmware, and processor core source code on GitHub. Unlike conventional chips encased in opaque plastic, the Baochip's packaging allows infrared light to pass through the back of the silicon, enabling researchers to visually inspect its internal structures and verify that no backdoors were introduced during manufacturing, thus solving a longstanding supply-chain trust issue.

The creation of this chip was made possible through a collaboration between Crossbar and Huang, who shared manufacturing runs to significantly reduce the exorbitant costs of fabrication, while Defcon founder Jeff Moss's vision led to its first major distribution. Emphasizing that the badge should have a practical life beyond the conference, Moss ensured the Baochip's core module is detachable so it can function as a FIDO hardware security token or password manager. Its built-in, low-resolution camera is designed specifically for scanning QR codes for authentication systems, strictly adhering to the conference's privacy rules, while the badge still retains interactive LED light features to encourage social engagement among attendees.

Regarding security, the chip runs a Rust-based operating system and features secure boot, a true random number generator, and resistive RAM (RRAM), which makes the physical extraction of stored data much more difficult than conventional flash memory. Although Huang is highly confident in its resistance to remote attacks, he acknowledges that adversaries with massive resources and sophisticated hardware-analysis labs could still potentially defeat it. By launching at Defcon, Huang anticipates that attendees will stress-test the chip and expose zero-day vulnerabilities, ultimately helping to refine its security and driving its future evolution to support Linux or become a robust Hardware Security Module (HSM).

2026-08-03 (Monday) · afd2cbe2b34af0826df1f1f7e7bf3e8d2adce35f