Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

231–240 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#232

Earlier quoted context omitted.

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed.

Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms.

You are not getting a device on the market or usable with any merchanet network without complying with this: https://www.pcisecuritystandards.org/documents/pos_ped_secur... and a few other standards.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#233

Earlier quoted context omitted.

> guess the contents of a box Use X-ray? or whatever can penetrate the exterior shell

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

And none of those measures would have protected against the compromise detailed in the article.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#234

So what is the alternative to SuperMicro if you aren't large enough design your own board?

Other motherboard vendors (e.g. Tyan, Asrock, Gigabyte make server boards), or buying entire servers from Dell, HP, ... And hoping they don't have issues like this, despite probably all manufacturing partly in China.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#236
post #57

"Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not."

That line in the article made me LOL. Douglas Adams would be proud.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#237
post #178

Earlier quoted context omitted.

You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

> To achieve this, the keyboard and the display is galvanically separated for the duration of the PIN entry

Perhaps this sounds too dull to ask, but what stops the terminal from just ... not separating the keyboard and display?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#238
post #219

Earlier quoted context omitted.

This only accept contact-less payment who doesn't require pincode.

PED/PTS devices have even stricter guidelines than contactless payments.

But this device doesn't need a way for the user to enter the pincode. So, all the sensitive part of the terminal is probably completely isolated from the android part.

I don't know this device internal and the PED/PTS exact requirement but it seems plausible for me.

You have something like a physical compartment who include the NFC and everything needed to process it like in a classical terminal. This compartment is highly secured as requested by the specification with just a very simple interface for the android part to send the amount to bill.

I've seen a lot of each-machine running on windows. Doesn't they work like this with the windows machine just managing the display buttons to select the amount and sending this information to the secure part who handle card interaction, pincode and delivery of the money ?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#239
post #129
post #75

Earlier quoted context omitted.

No, it is totally inconceivable AMD and Intel CPUs are backdoored this way. Inserting a microcontroller somewhere on the Ethernet traces and then using IPMI is not as sophisticated as this article wants to describe. Sophistication is necessary from the payload to be stealthy but not the hardware. There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts…

I don't think the parent was talking about this specific type of attacks but other types of hardware backdoors. I think the answer to that is very obviously yes, and given what we know about intelligence agencies I'm even willing to go as far as saying that it is likely (or at least, if you have reasons to be worried about Uncle Sam getting to your stuff you should consider it a very real possibility). Modern ASICs a…

> Modern ASICs are so complex that I'm sure that sneaking a tiny backdoor into the behemoth that's a modern CPU or embedded SoC would be almost trivial.

I suspect putting in a backdoor would be difficult because they are complex. Wouldn’t it be far too easy for the backdoor to inadvertently cause reliability or performance issues? And the bug would have to be useful enough to warrant potentially destroying the semiconductor business of a nation, not just some difficult to trigger side channel.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#240
post #234

So what is the alternative to SuperMicro if you aren't large enough design your own board?

Other motherboard vendors (e.g. Tyan, Asrock, Gigabyte make server boards), or buying entire servers from Dell, HP, ... And hoping they don't have issues like this, despite probably all manufacturing partly in China.

None of those guys offer the same variety of form factors and features that Super Micro does. If you are an OEM that needs an Intel Xeon-D board in mini-itx form factor for example.
Post reply on HN