Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

181–190 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#181
post #136
post #97

Earlier quoted context omitted.

I looked up supermicro blade motherboards, and saw that the chip was right near the IPMI chip's line to spi flash. And prior to that, there were already persistent rumors in the Chinese interney of certain Chinese mobos sending "weird garbage on ICMP," and "BMCs that somehow boot and work with their flash memory soldered off" Remembering that, I might even suggest that this is not a modchip that does something with s…

A photo of such a motherboard with a big arrow pointed at the additional chip would be a useful addition to this discussion.

Supermicro 6128 aka x10 series microblade. Those were very popular among Chinese DC operators during Broadwel era.

https://www.itcreations.com/dist/landing/i/MBI-6128R-T2/MBI-...

Left of the sata connector. An empty space with 8 pads for an smt eeprom or flash. It is occupied by the thingy on bugged boards.

Right below is the Aspeed chip - the BMC

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#182

Earlier quoted context omitted.

It's not particularly magical, there's consumer chips around which are not a whole lot bigger (though obviously in a more standard package). You don't get a lot of resources, but you don't really need it if all the other frameworks are in place in other software. If this sort of thing is something you can buy on Mouser for a few cents, the espionage grade material is probably an order or magnitude more higher quality…

For another example, I have a couple of these which are a bit bigger but have an ARM SoC and onboard Bluetooth (with antenna): https://www.digikey.com/en/product-highlight/t/taiyo-yuden/e...

That's a crazy module, I had no idea anything of that scale existed for Bluetooth radios.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#183

Earlier quoted context omitted.

See, the article showed that even largest companies are not completely immune to the problem. This was decade ago and payment card industry, not exactly national security matters.

The PLA can lean on factory managers very effectively but they're not going to be interested in small time stuff like credit card numbers. The sort of sophisticated criminal gang doing something like this will have fewer coercive tools at its disposal and I'd imagine would target lower level employees with bribes.

[deleted]

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#184
post #47

How common is it for a seemingly standard security audit to inspect motherboards with such level of detail or at all? They likely needed to have the exact official schematic of the motherboard to compare every single detail of the hardware with.

There are vendors in this space. See: https://www.harris.com/sites/default/files/supplier_counterf...

Good starting point.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#186
post #72

Earlier quoted context omitted.

SuperMicro hardware in particular always struck me as such. Asking users to pay a license fee to be able to update the BIOS on their devices (after paying tens of thousands for the hardware itself) is a kick in the teeth. https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S... http://www.supermicro.com/products/nfo/SMS_SUM.cfm

To be clear, this is only for the ability to update the BIOS over the BMC interface, not for BIOS updates in general. (unlike some other vendors, where you need a support contract to be even able to download the updates) At least on some boards you can boot the USB drive image containing the BIOS updater through the BMC and do a remote update that way.

For the models I was looking at a number of years ago, the options were through IPMI or via a USB Floppy Drive. Perhaps my memory is failing me here, but I seem to remember being quite enraged at the prospect and would have done a lot not to have to pay the license fee on principle.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#187
post #99
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Sorry, but this doesn't sound as true or there is huge mistakes done in choosing supply chain for such sensitive matter. How come company keep ordering devices from some unverified sources from China, and after hitting a wall keep doing same? How do you accept shipment of such devices without randomly opening and inspecting sample(yes losing all data, but electronic inspection can be done). How you didn't investigate…

Look, there are enough supply chain problems with counterfeits already, you don’t want to start thinking of malicious implants

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#188

So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…

The article specifically says that the attack goes after the Baseboard Management Controller (BMC). In Supermicro equipment this takes the form of a separate SOC made by ASPEED that runs it's own operating system entirely separate from the main CPU but with access into the main system through various mechanisms. Facebook uses the same ASPEED chips in their open hardware projects.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#189
post #99
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Sorry, but this doesn't sound as true or there is huge mistakes done in choosing supply chain for such sensitive matter. How come company keep ordering devices from some unverified sources from China, and after hitting a wall keep doing same? How do you accept shipment of such devices without randomly opening and inspecting sample(yes losing all data, but electronic inspection can be done). How you didn't investigate…

Look, there are enough supply chain problems with counterfeits already, you don’t want to start thinking about malicious implants. Just google for it, it’s massive

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#190
post #175

Earlier quoted context omitted.

Add the USA to that list.

Are you saying companies should or that you know of companies that do?

As far as I know, big EU companys do that, when they visit US, or they don't have sensitive information with them in the first place.
Post reply on HN