ORSHIN Series Month #1: Pulling Back the Curtain on Hardware (In)Security
ORSHIN Series Month #1 Recap: Pulling Back the Curtain on Hardware (In)Security
Welcome to the first monthly summary of our ongoing ORSHIN Series. These detailed insights are published directly on LinkedIn via the official Texplained account, which you can follow here for all current and future updates.
Over the last few weeks, Texplained has begun a deep dive into the physical reality of hardware security. As direct contributors to the EU-funded ORSHIN project (Open-source ReSilient Hardware and software for Internet of thiNgs),our mission is to expose the critical gaps in how the industry evaluates and protects silicon.
While cybersecurity discussions often center on software patches and firewalls, we are focusing on the foundation: the chip itself. Unlike software, you cannot send an over-the-air patch to fix compromised hardware.
Here is a look back at the ground we covered in Month #1, moving from “Security by Obscurity” to the realities of modern physical attacks.
1. Asking the Uncomfortable Question
We kicked off the series by challenging a long-standing industry benchmark. For decades, manufacturers and integrators have relied on Common Criteria (CC) to declare a chip “resistant.”
We posed the uncomfortable question: Is “certified” silicon actually secure—or just expensive to audit?
We set the stage for the series by highlighting the disconnect between a theoretical certification model and the real world, where attackers regularly reverse-engineer and clone certified chips. Security through obscurity is no longer a viable defense.
2. Open Design isn’t Weak. It’s Battle-Tested
With Post #2, we immediately addressed one of the biggest myths in silicon security: does opening a chip’s blueprint (Open Source Hardware) make it easier to hack?
As RISC-V and Open Source Hardware (OSH) explode, the industry is split. Legacy players insist that hiding your silicon layout keeps it safe. They are wrong.
We explored the core philosophy we are driving inside the ORSHIN project:
- Obscurity is an illusion: Hiding your layout only breeds false confidence. Modern reverse-engineering tools will extract your netlist regardless.
- Security by Design: Real hardware resilience means your chip stays unhackable, even when the attacker holds the full blueprints.
- Community Audit: When silicon is open, thousands of expert eyes audit the architecture, crushing bugs before the design ever touches the foundry.
Open Source Hardware isn’t a vulnerability. It’s the fast track to true digital sovereignty.
3. The Great Illusion: Closed vs. Open Chips
Post #3 deepened the comparison, proving that from the perspective of a well-equipped attacker, the difference between a closed-source and open-source chip is merely time.
Legacy arguments for closed hardware crumble when faced with physical reality:
- The netlist is never secret: A determined attacker uses full reverse engineering to extract the netlist, effectively turning a closed design into an open one.
- Imaging obstacles have collapsed: Tools like Texplained’s ChipJuice software suite drastically accelerate SEM image extraction and vector alignment.
Security through obscurity is an expensive illusion. True protection requires a layout that can withstand analysis, even when public.
4. Anatomy of a Hack: Why Reverse Engineering is the Multiplier
In Post #4, we demonstrated the combined threat model. Attackers do not rely on a single technique.
Reverse engineering acts as a “treasure map,” allowing attackers to locate internal architecture and register layouts with surgical precision. Armed with this map, they no longer act blindly. They can guide sophisticated attacks, such as Laser Fault Injection (LFI), with extreme accuracy, eliminating trial and error.
Looking Ahead
Month #1 was about establishing the gap between theoretical certification and physical reality. We have shown that obscurity is not protection, and that Open Source transparency is the path to truly resilient silicon.
As we move into Month #2, the ORSHIN series will continue to push the boundaries. We will dive deeper into how automated netlist extraction empowers digital forensics and explore why verifying physical silicon against supply chain trojans is essential for true sovereignty.
Make sure to follow Texplained on LinkedIn so you don’t miss the upcoming posts in this series!
#HardwareSecurity #CommonCriteria #ReverseEngineering #CyberSecurity #ORSHIN #Texplained