Earlier quoted context omitted.
NSL letter, under active investigation
NSLs require secrecy not lying.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
221–230 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#222Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#223Earlier quoted context omitted.
Why does this keep getting quoted in the comments. Yes we read the article too.
Because it's so awesome. This must be one of this journalist's career highlights, to be able to put something like this in a mainstream serious reporting piece.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#224I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…
It’s not surprising to see a ton of tamper switches, vibration/shock sensors, even light sensors. And they’re all powered by an internal batter and separate MCU that will brick the device upon open.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#225Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#226Earlier quoted context omitted.
You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…
The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#227Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#228Earlier quoted context omitted.
The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…
Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...
https://www.pcisecuritystandards.org/documents/pos_ped_secur...
https://www.pcisecuritystandards.org/documents/PCI_PTS_POI_S...
The requirement for the tamper proofings is literally the first requirement in the PED standard:
A1 Vendors must comply with all components of A1.
A1.1
The PED uses tamper-detection and response mechanisms that cause the PED to become immediately inoperable and result in the automatic and immediate erasure of any secret information that may be stored in the PED, such that it becomes infeasible to recover the secret information. These mechanisms protect against physical penetration of the device by means of (but not limited to) drills, lasers, chemical solvents, opening covers, splitting the casing (seams), and using ventilation openings, and there is not any demonstrable way to disable or defeat the mechanism and insert a PIN-disclosing bug or gain access to secret information without requiring an attack potential of at least 25 per PED, exclusive of the IC card reader, for identification and initial exploitation as defined in Appendix B of the PCI POS PED DTRS
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#229Earlier quoted context omitted.
Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...
This only accept contact-less payment who doesn't require pincode.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#230Earlier quoted context omitted.
SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…
But without the IPMI kernel modules loaded, IPMI is harmless, right ?