Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

201–210 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#201

Earlier quoted context omitted.

> guess the contents of a box Use X-ray? or whatever can penetrate the exterior shell

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

> They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.).

Given how sophisticated these attacks can be, I'd think they'd issue disposable equipment to be destroyed on return, like a cheap netbook or something. I don't see how you could trust an individual viewing a simple X-ray scan to detect some extra microchip the size of a signal conditioning coupler.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#202

They attacked the Base Management Controller. There's an article by Bruce Schneier from 2013 warning about exactly this attack. Quoting: "Basically, it's a perfect spying platform. You can't control it. You can't patch it. It can completely control your computer's hardware and software. And its purpose is remote monitoring. At the very least, we need to be able to look into these devices and see what's running on the…

> They attacked the Base Management Controller.

Do you know this, or are you speculating?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#203

Earlier quoted context omitted.

Except, you know, to avoid committing securities fraud by making a material misrepresentation.

There is no way that the intelligence community would allow that fraud case to go ahead.

That assumes that 1) the intelligence community has the power to stop it and 2) that Apple believes this to be the case and 3) that Apple is confident that the intel community would use that power to protect them. That seems like a reach to me.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#204
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker.

You only need to measure three angular momentums, all other can be calculated. See https://en.wikipedia.org/wiki/Moment_of_inertia#Motion_in_sp...

"This shows that the inertia matrix can be used to calculate the moment of inertia of a body around any specified rotation axis in the body."

On the attacker side, they only need to make sure three angular momentums match.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#205

> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?

I'm pretty certain they do. AMD's PSP and Intel's ME are really shady and are still enabled in every CPU sold today (and full of disclosed and undisclosed flaws for that matter).

Not to mention that these back doors can be easily disabled, e.g intels high assurance mode, but normal "owners" are specifically not allowed to disable them.

The whole thing is a fucking mess.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#206
post #83

This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…

Anti-China propaganda? These chips were designed by the Chinese military and inserted by PLA agents. Do you have to start calling things propaganda to make it seem like this is baseless criticism of China to those who have not read the article?

These chips were REPORTED TO BE designed by the Chinese military and inserted by PLA agents.

Big difference, which is parent's point.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#207
post #73

Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…

The article says: But they were capable of doing two very important things: telling the device to communicate with one of several anonymous computers elsewhere on the internet that were loaded with more complex code; and preparing the device’s operating system to accept this new code. The illicit chips could do all this because they were connected to the baseboard management controller, a kind of superchip that admin…

If this is indeed the case, I'm surprised someone didn't catch something earlier when the device was calling "home" over their network. I'm wondering if China stole BlackRidge First Packet Authentication tech [1] to keep things dark. BlackRidge is... "involved" in IC and defense projects.

[1]https://patents.google.com/patent/US8346951B2/en

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#209
This is just the hack that was discovered because there was macroscopic evidence of it. All it would take to pull off a similar hack that was undetectable is one well placed mole in the company that designed a key piece of silicon or software.
Post reply on HN