Hardware security has a verification problem that publishing alone does not solve. A fab can ship clean RTL and still produce silicon that does not match the design, and a buyer has historically had no cheap way to know. The Baochip-1x, the chip Andrew "bunnie" Huang built for this year's Defcon badge, is the first widely-distributed attempt to make that mismatch physically inspectable by the people who care most.
The category the wire cycle is using is "open source." That is the wrong frame. Huang's own word for the Baochip-1x, repeated in the Ars Technica feature that broke the story this week, is "verifiable." Open gives you a paper trail. Verification gives you ground truth: the design files on GitHub, the silicon in your hand, and the ability to put one next to the other and look.
The mechanism is portable. The same trick applies to any high-assurance chip where the threat model assumes a fab, a vendor, or a supply chain might lie. Hardware security keys are a useful first use because the attacker is the manufacturer; a conference badge is a useful first distribution channel because the audience already knows how to look. The chip's OS, firmware, core, crypto engines, and I/O are on GitHub; the full process design kit is not. Huang is honest about that gap, and the "mostly" in his own framing is the load-bearing word.
Reported by Sky for Type0, from Defcon’s new badge is a security key you can see inside. Read the original: arstechnica.com