Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

91–100 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#91

Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…

5. When a server was installed and switched on, the microchip altered the operating system’s core so it could accept modifications. The chip could also contact computers controlled by the attackers in search of further instructions and code. So, in typical vulnerability/payload/exploit fashion, the board's bus is vulnerable by default, because the chip pierces all the usual lines of defense protecting against network…

Hm, but DMA messages get distributed over a parallel bus and this chip seems to employ a serial interface, so I would assume that it's not directly connected to anything that requires high throughput (i.e. memory, disk and peripheral access).

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#92
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Get an x-ray machine? They are surprisingly cheap pieces of hardware if you are willing to deal with a small area, low penetration image. Low penetration means no lead, which makes for something that's about as cumbersome as a large bar fridge.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#93
post #59

Earlier quoted context omitted.

5. When a server was installed and switched on, the microchip altered the operating system’s core so it could accept modifications. The chip could also contact computers controlled by the attackers in search of further instructions and code. So, in typical vulnerability/payload/exploit fashion, the board's bus is vulnerable by default, because the chip pierces all the usual lines of defense protecting against network…

They didn't do anything to the CPU, what they did is the modchipped the line from EEPROM and the board management controller. They probably found it out when they were repeatedly tried to reflash the BMC flash, and saw that checksums did not match.

That would make a lot of sense and would give the attacker a way to interface with all of the other hardware (network, disk etc.). Do you have a source for this information?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#94
post #56

When will this stuff finally have consequences for China? Their behavior, not their communication, has been overtly hostile for a while. Yet, very few politicians openly adress the issue.

Do you really think that another world power would behave differently if they were the factory of the world?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#95
post #80
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.

Yes, irrespective of country where its manufactured, if there are compliance requirements around an un-openable box, then some process becomes required.

But I think the GP's question is: "Whether it would be cheaper" - in the sense whether such an expensive QA process could have been averted by having a more trustworthy partner. One whom you're not on a race hack after hack.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#96
post #77
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#97
post #59

Earlier quoted context omitted.

They didn't do anything to the CPU, what they did is the modchipped the line from EEPROM and the board management controller. They probably found it out when they were repeatedly tried to reflash the BMC flash, and saw that checksums did not match.

That would make a lot of sense and would give the attacker a way to interface with all of the other hardware (network, disk etc.). Do you have a source for this information?

I looked up supermicro blade motherboards, and saw that the chip was right near the IPMI chip's line to spi flash.

And prior to that, there were already persistent rumors in the Chinese interney of certain Chinese mobos sending "weird garbage on ICMP," and "BMCs that somehow boot and work with their flash memory soldered off"

Remembering that, I might even suggest that this is not a modchip that does something with signal on the go, but just a very tiny flash chip that has the modded firmware.

Going further from that, to pack, say, 16 mB on a sandgrain sized chip, the densities need to be like that of best flash chips out there, which also means that they have access to last gen flash fab.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#98
post #80

Earlier quoted context omitted.

I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.

Yes, irrespective of country where its manufactured, if there are compliance requirements around an un-openable box, then some process becomes required. But I think the GP's question is: "Whether it would be cheaper" - in the sense whether such an expensive QA process could have been averted by having a more trustworthy partner. One whom you're not on a race hack after hack.

The point is that if the devices are sensitive with compliance requirements then you must be able to verify them irrespective of who you hired to manufacture them.

You cannot just trust the word of a contractor on this because it's your ass on the line.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#99
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Sorry, but this doesn't sound as true or there is huge mistakes done in choosing supply chain for such sensitive matter.

How come company keep ordering devices from some unverified sources from China, and after hitting a wall keep doing same?

How do you accept shipment of such devices without randomly opening and inspecting sample(yes losing all data, but electronic inspection can be done).

How you didn't investigate that with Visa/Mastercard? Whoever does that, he will lose his payment terminal certification after such incident, because they will track them down by IC serials very quickly.

What if vendor changed power supply board or even components type on it, and your momentum or weight test will make false positive?

Unless... your employer or you buy single devices, on demand, from some shady aliexpress seller. But then, it is plain suicide.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#100
post #33
post #23

The Chinese government didn’t directly address questions about manipulation of Supermicro servers, issuing a statement that read, in part, “Supply chain safety in cyberspace is an issue of common concern, and China is also a victim.” Essentially China ils saying "it was not me". Plausible

I Read that as "The US is also attacking our hardware supply chains". That is, the statement concerned supply chain attacks in general, not this specific one.

Yeah it seemed to imply a ‘tit for tat’ attitude to me
Post reply on HN