Earlier quoted context omitted.
I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.
See, the article showed that even largest companies are not completely immune to the problem. This was decade ago and payment card industry, not exactly national security matters.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
171–180 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#172When will this stuff finally have consequences for China? Their behavior, not their communication, has been overtly hostile for a while. Yet, very few politicians openly adress the issue.
There’s a certain Casablanca-esque “what? There’s gambling happening here?” element here too — Huawei was shipping fake Cisco gear 20 years ago.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#173Earlier quoted context omitted.
The point is that if the devices are sensitive with compliance requirements then you must be able to verify them irrespective of who you hired to manufacture them. You cannot just trust the word of a contractor on this because it's your ass on the line.
The point is that the process was to assure the device wasn't tampered AFTER shipped from manufacturer. Nobody thought it could already have been modified so early in the process. This is the eternal cat and mouse game. When I started in IT in 90s it was assumed that company network was quite safe and you didn't always need passwords, maybe for critical resources only.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#174Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…
SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#175Earlier quoted context omitted.
All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…
Add the USA to that list.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#176I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#177I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Sorry, but this doesn't sound as true or there is huge mistakes done in choosing supply chain for such sensitive matter. How come company keep ordering devices from some unverified sources from China, and after hitting a wall keep doing same? How do you accept shipment of such devices without randomly opening and inspecting sample(yes losing all data, but electronic inspection can be done). How you didn't investigate…
For example, PINs are only ever being in unencrypted form inside of Hardware Security Modules and only for the purpose of being encrypted with Visa/Mastercard exchange keys. The process was designed so that nobody has enough access to ever get enough cryptographic material to be able to decrypt anything, at least two or three people would have to collude to do anything.
It also happens that we put all our resources in investment in software for the platform locking ourselves in. It would be rash decision to change the platform and it would probably kill our company. Also we (correctly) gambled that it would be dealt with quickly.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#178I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…
Use an AES256 key from the factory to hash the chip's burned-in serial number and the time from the RTC. Lock out JTAG interfaces so once the chips are burned, they are inside their own fortress. There are a ton of ways to really lock down the hardware other than a shiny sticker and weird screws. Those keep people from breaking their own hardware, anti-tamper tech in chips keep out bad guys.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#179Earlier quoted context omitted.
Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?
they have literally every reason to deny and literally no reason to say it's true
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#180Earlier quoted context omitted.
I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.
See, the article showed that even largest companies are not completely immune to the problem. This was decade ago and payment card industry, not exactly national security matters.
As I hinted in another comment I suspect that they had a suspicion and checked those motherboards very, very carefully.