Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

161–170 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#161
Interesting about how some of the trojan chips were hidden in PCB substrate layers to avoid optical detection. For a much stealthier approach again, it was shown in 2013 that slighting changing the dopant mask for a few gates on Intel Ivy Bridge chips could render RNGs insecure[1][2]. Mask inspection systems[3] are used to detect mask manufacturing defects, but the question then is, do those inspection systems use Super Micro motherboards?

[1] Paper: http://www.emsec.rub.de/media/crypto/veroeffentlichungen/201...

[2] Presentation: https://www.iacr.org/workshops/ches/ches2013/presentations/C...

[3] Example system: https://www.lasertec.co.jp/en/products/semiconductor/mask_se...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#162
post #98

Earlier quoted context omitted.

Yes, irrespective of country where its manufactured, if there are compliance requirements around an un-openable box, then some process becomes required. But I think the GP's question is: "Whether it would be cheaper" - in the sense whether such an expensive QA process could have been averted by having a more trustworthy partner. One whom you're not on a race hack after hack.

The point is that if the devices are sensitive with compliance requirements then you must be able to verify them irrespective of who you hired to manufacture them. You cannot just trust the word of a contractor on this because it's your ass on the line.

The point is that the process was to assure the device wasn't tampered AFTER shipped from manufacturer. Nobody thought it could already have been modified so early in the process. This is the eternal cat and mouse game. When I started in IT in 90s it was assumed that company network was quite safe and you didn't always need passwords, maybe for critical resources only.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#164

It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…

> It's been a few years I've given up on the idea of privacy with technology.

The problem with tech is that it's modularity and dependency on other people/tools/hardware/etc ultimately requires trust.

> in place for more than 20 years.

Far longer than 20 years. The idea of trust, privacy and security has been discussed for a long time. The complexity of security on just on one specific technology ( compilers ) was discussed in the early 1980s by Ken Thompson.

"Reflections on Trusting Trust"

https://news.ycombinator.com/item?id=13569275

Compilers are just one part of a complex ecosystem. Now imagine having to check ABI or the physical chips/hardware themselves. Where you require sophisticated hardware.

The motto of technology is "In Trust We Trust".

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#165

Who else found the design of the page made the article difficult to read? I know darkness, spies and hacking go hand-in-hand but it's a bit too much imho.

This is because, contrary to what a lot of people say about dark themes (even though it's mostly a meme at this point), dark letters on white background are better to read than white letters on black background.

"People with astigmatism (approximately 50% of the population) find it harder to read white text on black than black text on white. Part of this has to do with light levels: with a bright display (white background) the iris closes a bit more, decreasing the effect of the "deformed" lens; with a dark display (black background) the iris opens to receive more light and the deformation of the lens creates a much fuzzier focus at the eye." - Jason Harrison – Post Doctoral Fellow, Imager Lab Manager – Sensory Perception and Interaction Research Group, University of British Columbia

This quote describes the situation well I think, why the opinions differ and why neither dominates UIs really.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#166
post #25

Earlier quoted context omitted.

Who's saying the firewall isn't compromised too? ;)

Right so all the stars need to align for it to go unnoticed - compromised server, firewall and other alerting/monitoring tools. I would have thought one single unexpected packet in these high security environments would raise significant alarm bells and any anomaly would be found very quickly.

Only if you’re lucky. Priority is checking boxes and meeting audit requirements.

If you’re running an IDS on a big 100 Gb datacenter network, you’re literally processing millions of events. Very few places would notice such a thing unless they were investigating something related, and the ones with the capability are going to be for static workloads as getting anything done will be slow and painful.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#167
post #37

Earlier quoted context omitted.

I've worked on systems deployed in the financial sector in high risk environments. This sort of monitoring doesn't happen in the real world.

Intrusion Detection Systems are basic network security 101 type stuff. I'd be surprised if anything that was really "high risk" didn't use an IDS.

Intrusion detection involves connections coming from the outside. These attacks originate inside the network, from the compromised equipment.

Except on extremely controlled networks, this would be very hard to detect. It gets even worse when you consider that the Chinese had/have a distributed network of compromised machines. Imagine using a Google edge server as a dead drop...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#168
post #57

"Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not."

Why does this keep getting quoted in the comments. Yes we read the article too.

Because it's so awesome. This must be one of this journalist's career highlights, to be able to put something like this in a mainstream serious reporting piece.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#169

The only interesting thing about this is left out. Who planted it is clear (someone told to do so) but not a single time is it questioned who they planted it for. Smells like false flag to me. We think China does X Y and Z but we know the US does X Y Z and the rest of the alphabet. So unless something specific is leaked that shows who actually ordered this, logic would point at the US.

looks like no one noticed the word "Troll" in OP's username

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#170
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

The chinese government is probably not interested enough in credit card numbers to warrant involvement.
Post reply on HN