Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

101–110 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#101

Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

But without the IPMI kernel modules loaded, IPMI is harmless, right ?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#102
post #56

When will this stuff finally have consequences for China? Their behavior, not their communication, has been overtly hostile for a while. Yet, very few politicians openly adress the issue.

Ha. This looks more like good old capitalism rather than any state sponsored spying.

"Nobody's making you buy from China"

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#103
post #80
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.

Transparent plastic?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#104
post #83

This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…

It could be interpreted that way, but this sort of activity isnt novel or unknown.

The Feds run key hardware through third parties to detect counterfeit hardware. The “new” thing is the targeting of devices headed for commercial customers.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#105
In retrospect it seems that the decision to move all manufacturing to China was ill-advised.

Western companies ultimately will have no choice than to move it all back. (And Trump will want to take credit for that.)

I can understand all the big guys denying this. It's very hard to fix and very bad for business.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#107

Earlier quoted context omitted.

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

But without the IPMI kernel modules loaded, IPMI is harmless, right ?

No, since it can configure the BMC, which works without the OS.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#108
post #99
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Sorry, but this doesn't sound as true or there is huge mistakes done in choosing supply chain for such sensitive matter. How come company keep ordering devices from some unverified sources from China, and after hitting a wall keep doing same? How do you accept shipment of such devices without randomly opening and inspecting sample(yes losing all data, but electronic inspection can be done). How you didn't investigate…

It sounds like they are just ordering stock products from Amazon.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#109
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Get an x-ray machine? They are surprisingly cheap pieces of hardware if you are willing to deal with a small area, low penetration image. Low penetration means no lead, which makes for something that's about as cumbersome as a large bar fridge.

It's mentioned in the article that X-Ray didn't help much: 'Gray or off-white in color, they looked more like signal conditioning couplers, another common motherboard component, than microchips, and so they were unlikely to be detectable without specialized equipment'

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#110
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Why don't you guys consider to expose this by suing the bad manufacturer? I believe this could help other truely honest manufacturers both in and outside China to beat the wrong doers.
Post reply on HN