Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

111–120 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#111
post #109

Earlier quoted context omitted.

Get an x-ray machine? They are surprisingly cheap pieces of hardware if you are willing to deal with a small area, low penetration image. Low penetration means no lead, which makes for something that's about as cumbersome as a large bar fridge.

It's mentioned in the article that X-Ray didn't help much: 'Gray or off-white in color, they looked more like signal conditioning couplers, another common motherboard component, than microchips, and so they were unlikely to be detectable without specialized equipment'

This comment is specific to the parent talking about their experiences producing credit card terminals that ended up with PCBs implanted in them. Here it is appropriate.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#112
post #81

> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?

can you be sure that fabs haven't been infiltrated and masks changed between design and production in any factory, be it tsmc, samsung, glofo or intel?

Presumably the organisations responsible for hard coding backdoors in chip designs know how to test to confirm their presence.

Presumably some adversarial nation-states have moles inside these organisations > know how to remove them prior to fab.

Presumably these adversaries export genuine chips to their adversaries, thereby tricking them in to thinking the backdoors made it through the fab process, and only use chips that have the backdoors removed in their own critical infrastructure.

Presumably.

I’ve always had this fantasy of being a hextuple agent involved in this type of deep espionage.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#113
Statements from Amazon, Apple, Supermicro and Chinese government.

https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

From Apple:

"Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them. We have repeatedly and consistently offered factual responses, on the record, refuting virtually every aspect of Bloomberg’s story relating to Apple."

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#114
post #29

Earlier quoted context omitted.

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

It sometimes feels like certain hardware protocols were designed to be insecure. I remember reading about IPMI issues back in 2013: https://www.itworld.com/article/2708437/security/ipmi--the-m...

"Designed to be insecure" is probably unfair to the designers of IPMI. Security was just not as big a concern as it is today.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#115
post #25

Earlier quoted context omitted.

Right so all the stars need to align for it to go unnoticed - compromised server, firewall and other alerting/monitoring tools. I would have thought one single unexpected packet in these high security environments would raise significant alarm bells and any anomaly would be found very quickly.

I've worked on systems deployed in the financial sector in high risk environments. This sort of monitoring doesn't happen in the real world.

We had something similar where anything outside "normal" generated a ticket. It was disabled after 1 week because the support teams where getting more then 5000+ tickets each day. And this was after filtering etc....

Now this does not make it impossible, just very complex. In a more "controlled" environment such as a naval ship, i could see this actually working better, especially if the system is supposed to talk to very few external systems.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#116

So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…

The chip shown in the article most likely just something journalists found in photo stock by keywords.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#117

It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…

I think the root of the problem is backwards compatibility and the fact that initially all these components were not designed with security in mind. So we're adding more insecure components in spirit of "move fast, break things" than fixing the debt incurred.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#118
post #47

How common is it for a seemingly standard security audit to inspect motherboards with such level of detail or at all? They likely needed to have the exact official schematic of the motherboard to compare every single detail of the hardware with.

While you may find a particular attack if you're looking for, in general, it's impossible for even the most thorough audits to check for the whole class of such attacks. You're not going to look into the chips. Well, you can, but that's prohibitively expensive and destructive - even if you could check that this chip was okay, then you still have to throw it out after analysis and plug in a different one. The only fea…

Zilog Z80, 1976

> Faggin: Yes, we were concerned about others copying the Z80. So I was trying to figure what we could do that that would be effective, and that’s when I came across an idea that if we use the depletion load the mask that doesn’t leave any trace, then I could create depletion load devices that look like enhancement mode devices. And by doing that we could trick the customer into believing that a certain logic was implemented, when it was not. Then I told Shima, “Shima, this is the idea how to implement traps. Put traps, you know, figure out how to do the worst possible traps that you can imagine,” and then Shima with his mind, that was steel mind, was able to actually figure out a bunch of traps that he could talk about.

> Slater: You want to tell us a little about that Shima?

> Shima: I didn’t count [on] talking about that mostly. I placed six traps for stopping the copy of the layout by the copy maker. And one transistor was added to existing enhancement transistors. And I added a transistor looks like an enhancement transistor. But if transistors are set to be always on state by the ion implantations, it has a drastic effect on very much. I heard from NEC later the copy maker delayed the announcement of Z80 compatible product for about six months.

http://archive.computerhistory.org/resources/text/Oral_Histo...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#119
post #80

Earlier quoted context omitted.

I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.

> guess the contents of a box Use X-ray? or whatever can penetrate the exterior shell

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.).

The more critical the field, the more you have to treat those devices as untrusted before attaching them to your trusted zone.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#120
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

This is fairly analogous to my comment here: https://news.ycombinator.com/item?id=18138847

Presumably the organisations responsible for hard coding backdoors in chip designs know how to test to confirm their presence.

Presumably some adversarial nation-states have moles inside these organisations > know how to remove them prior to fab. Presumably these adversaries export genuine chips to their adversaries, thereby tricking them in to thinking the backdoors made it through the fab process, and only use chips that have the backdoors removed in their own critical infrastructure.

Presumably.

I’ve always had this fantasy of being a hextuple agent involved in this type of deep espionage.

Post reply on HN