Who else found the design of the page made the article difficult to read? I know darkness, spies and hacking go hand-in-hand but it's a bit too much imho.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
71–80 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#72Earlier quoted context omitted.
It sometimes feels like certain hardware protocols were designed to be insecure. I remember reading about IPMI issues back in 2013: https://www.itworld.com/article/2708437/security/ipmi--the-m...
SuperMicro hardware in particular always struck me as such. Asking users to pay a license fee to be able to update the BIOS on their devices (after paying tens of thousands for the hardware itself) is a kick in the teeth. https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S... http://www.supermicro.com/products/nfo/SMS_SUM.cfm
At least on some boards you can boot the USB drive image containing the BIOS updater through the BMC and do a remote update that way.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#73Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…
But they were capable of doing two very important things: telling the device to communicate with one of several anonymous computers elsewhere on the internet that were loaded with more complex code; and preparing the device’s operating system to accept this new code. The illicit chips could do all this because they were connected to the baseboard management controller, a kind of superchip that administrators use to remotely log in to problematic servers, giving them access to the most sensitive code even on machines that have crashed or are turned off.
To me, that makes it sound like they could download from a remote host and inject code and do literally anything.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#74Once this was noticed we started weighing the terminals because we could not open the devices (once opened they become useless).
They have learned of this so they started scraping non-essential plastic from inside the device to offset the weight of the added board.
We have ended up measuring angular momentum on a special fixture. There are very expensive laboratory tables to measure angular momentum. I have created a fixture where the device could be placed in two separate positions. The theory is that if the weight and all possible angular momentums match then the devices have to be identical. We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#75> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?
There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts of Global Foundries are in Singapore, Intel is manufacturing CPUs mostly in the USA with some in Ireland and Israel, only 3DNAND / 3DXPoint ICs are made in China. b) the hardware knowledge to change here, well, think of it, the microcontroller on the motherboard is on the few millimetres scale, the parts here are on the few ten nanometres scale so as a rough but not unjust quantifications would say it's 100 000 times harder.
Whether the platforms are hackable / hacked, that's harder to say thanks Intel ME and such but the CPUs aren't.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#76So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…
Terrifying and neat; thanks for the explanation!
How easy is it for us (or rather the companies making the hardware) to detect and mitigate this?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#77I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#78Earlier quoted context omitted.
Firewalls in high security environments aren't just port/protocol based. You lock everything down - source ip/port and destination ip/port. You should know where it is coming from and where it is going to. Navy ships don't upload via Dropbox.
In the parent I described a system which would be able to communicate through those restrictions to another compromised host (remember we're assuming everything is compromised for the sake of this article, which actually seems like a good assumption now).
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#79The only interesting thing about this is left out. Who planted it is clear (someone told to do so) but not a single time is it questioned who they planted it for. Smells like false flag to me. We think China does X Y and Z but we know the US does X Y Z and the rest of the alphabet. So unless something specific is leaked that shows who actually ordered this, logic would point at the US.
> ...but not a single time is it questioned who they planted it for... The article and some accompanying reporting on Bloomberg audio/video segments says the attack seems targeted relatively specifically towards nearly 30 organizations (only US-based organizations were mentioned as targets, unknown if the list included organizations based in other nations). One known vector was through four subcontractors in China th…
The US has something to loose too: Being perceived as dependent on Chinese manufacturing and potentially compromised down to military hardware. (The first everybody knows, the second would be devastating for trust.)
All in all it would be a weird angle for a false-flag attack.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#80I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?
If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed.
Trying to guess the contents of a box that you cannot open sounds a bit like madness.