Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

61–70 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#61
post #47

How common is it for a seemingly standard security audit to inspect motherboards with such level of detail or at all? They likely needed to have the exact official schematic of the motherboard to compare every single detail of the hardware with.

While you may find a particular attack if you're looking for, in general, it's impossible for even the most thorough audits to check for the whole class of such attacks. You're not going to look into the chips. Well, you can, but that's prohibitively expensive and destructive - even if you could check that this chip was okay, then you still have to throw it out after analysis and plug in a different one.

The only feasible thing to do is thorough audits of all the supply chain for every component in your system, ensuring that your supply chain does not include even a single chip from an "untrustworthy" supplier, and even then it reduces the chances of an attack but does not eliminate it.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#62
post #37

Earlier quoted context omitted.

I've worked on systems deployed in the financial sector in high risk environments. This sort of monitoring doesn't happen in the real world.

Intrusion Detection Systems are basic network security 101 type stuff. I'd be surprised if anything that was really "high risk" didn't use an IDS.

[deleted]

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#63
post #29

Earlier quoted context omitted.

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

It sometimes feels like certain hardware protocols were designed to be insecure. I remember reading about IPMI issues back in 2013: https://www.itworld.com/article/2708437/security/ipmi--the-m...

SuperMicro hardware in particular always struck me as such. Asking users to pay a license fee to be able to update the BIOS on their devices (after paying tens of thousands for the hardware itself) is a kick in the teeth.

https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S...

http://www.supermicro.com/products/nfo/SMS_SUM.cfm

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#64
So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner.

Technically you could embed and power an RF front-end inside a “flavored” balun to intercept or alter any communication passing through that front-end or even use the antenna to communicate during the down time. So this literally would hack Wifi / Bluetooth at low level and inject code and at the same time create a mesh network of malicious devices to relay information. Welcome to IoT Cyberwarfare.

But this clever hack is probably not limited to RF and is likely to also be embedded in transformers used for isolating Ethernet lines. Common mode chokes (some SMD chokes also look like the chip they are showing) or even some integrated ESD protection solution would be an ideal target as they are inserted in series of the signal.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#65

> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?

I'm pretty certain they do. AMD's PSP and Intel's ME are really shady and are still enabled in every CPU sold today (and full of disclosed and undisclosed flaws for that matter).

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#66

>Amazon’s security team conducted its own investigation into AWS’s Beijing facilities and found altered motherboards there as well, including more sophisticated designs than they’d previously encountered. >...the malicious chips were thin enough that they’d been embedded between the layers of fiberglass onto which the other components were attached >...that generation of chips was smaller than a sharpened pencil tip,…

> I hope this corrects the mistaken believe that China can't home grow sophisticated tech.

There's nothing particularly sophisticated about what they did, especially given what China has access to as one of the central hubs of tech manufacturing. There are two dozen nations (or more) that could do this from a strictly technical standpoint (few have the kind of required supply chain access to pull it off at scale in actuality). It's the audacity that is primarily impressive. China is encouraging all of their richest trading partners to further isolate them when it comes to supply chain and advanced tech. They're confirming for the 107th time what everyone already believes.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#67

The only interesting thing about this is left out. Who planted it is clear (someone told to do so) but not a single time is it questioned who they planted it for. Smells like false flag to me. We think China does X Y and Z but we know the US does X Y Z and the rest of the alphabet. So unless something specific is leaked that shows who actually ordered this, logic would point at the US.

> logic would point at the US

But then, since the logic points to the US it only stands to reason that is a false false flag! Why those wiley spies in Beijing really are clever. Discredit The USA and plant spy chips in important computers!

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#68

The only interesting thing about this is left out. Who planted it is clear (someone told to do so) but not a single time is it questioned who they planted it for. Smells like false flag to me. We think China does X Y and Z but we know the US does X Y Z and the rest of the alphabet. So unless something specific is leaked that shows who actually ordered this, logic would point at the US.

> ...but not a single time is it questioned who they planted it for...

The article and some accompanying reporting on Bloomberg audio/video segments says the attack seems targeted relatively specifically towards nearly 30 organizations (only US-based organizations were mentioned as targets, unknown if the list included organizations based in other nations). One known vector was through four subcontractors in China that built the boards for Supermicro's main Shanghai factory, specifically by bribing and/or coercing managers of those subcontractors' factories to go along with accepting the chip shipments and to make changes to the plant floor from the design to perform the chip insertions.

Designing and building a chip like this and then mounting the logistical effort to performing the insertions costing some non-trivial funds, coupled with the known targets, (Amazon didn't seem specifically targeted, Elemental a company they acquired was, who notably has US national security clients), form the circumstantial allegation that a PLA spy unit was behind the attack. You are correct that this doesn't entirely rule out a false flag possibility, but until we get more details about this, we're operating in the dark.

A false flag is an interesting supposition, but how would the US benefit from successfully convincing the world of the false flag's cover story?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#69

The only interesting thing about this is left out. Who planted it is clear (someone told to do so) but not a single time is it questioned who they planted it for. Smells like false flag to me. We think China does X Y and Z but we know the US does X Y Z and the rest of the alphabet. So unless something specific is leaked that shows who actually ordered this, logic would point at the US.

The article specifically mentions the PLA as the bad guy. So that part was not left out. The whole story is hearsay so far. It's plausible, but best read with a good dose of salt.

If we believe the story up to the point where subcontractors are forced into planting the chips, we must accept that it's easiest and least risk for Chinese government actors to force them into it. Mounting a false-flag attack at Chinese subcontractors would be exceedingly difficult for foreign agents. They'd likely blow their cover when trying to represent Chinese officials.

If you want an alternate version, I suggest you start with the easiest: The whole thing didn't happen. And Bloomberg is a victim of propaganda.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#70

It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…

[deleted]
Post reply on HN