The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
231–240 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#232Earlier quoted context omitted.
The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…
Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.
Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms.
You are not getting a device on the market or usable with any merchanet network without complying with this: https://www.pcisecuritystandards.org/documents/pos_ped_secur... and a few other standards.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#233Earlier quoted context omitted.
> guess the contents of a box Use X-ray? or whatever can penetrate the exterior shell
All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#234So what is the alternative to SuperMicro if you aren't large enough design your own board?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#235Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#236"Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not."
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#237Earlier quoted context omitted.
You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…
The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…
Perhaps this sounds too dull to ask, but what stops the terminal from just ... not separating the keyboard and display?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#238Earlier quoted context omitted.
This only accept contact-less payment who doesn't require pincode.
PED/PTS devices have even stricter guidelines than contactless payments.
I don't know this device internal and the PED/PTS exact requirement but it seems plausible for me.
You have something like a physical compartment who include the NFC and everything needed to process it like in a classical terminal. This compartment is highly secured as requested by the specification with just a very simple interface for the android part to send the amount to bill.
I've seen a lot of each-machine running on windows. Doesn't they work like this with the windows machine just managing the display buttons to select the amount and sending this information to the secure part who handle card interaction, pincode and delivery of the money ?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#239Earlier quoted context omitted.
No, it is totally inconceivable AMD and Intel CPUs are backdoored this way. Inserting a microcontroller somewhere on the Ethernet traces and then using IPMI is not as sophisticated as this article wants to describe. Sophistication is necessary from the payload to be stealthy but not the hardware. There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts…
I don't think the parent was talking about this specific type of attacks but other types of hardware backdoors. I think the answer to that is very obviously yes, and given what we know about intelligence agencies I'm even willing to go as far as saying that it is likely (or at least, if you have reasons to be worried about Uncle Sam getting to your stuff you should consider it a very real possibility). Modern ASICs a…
I suspect putting in a backdoor would be difficult because they are complex. Wouldn’t it be far too easy for the backdoor to inadvertently cause reliability or performance issues? And the bug would have to be useful enough to warrant potentially destroying the semiconductor business of a nation, not just some difficult to trigger side channel.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#240So what is the alternative to SuperMicro if you aren't large enough design your own board?
Other motherboard vendors (e.g. Tyan, Asrock, Gigabyte make server boards), or buying entire servers from Dell, HP, ... And hoping they don't have issues like this, despite probably all manufacturing partly in China.