Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

241–250 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#241
post #110

Earlier quoted context omitted.

Why don't you guys consider to expose this by suing the bad manufacturer? I believe this could help other truely honest manufacturers both in and outside China to beat the wrong doers.

The Chinese operation would simply shut down and reopen under a different name. And the credit card companies are always very worried about their brand image, so they are not interested in any negative publicity.

But I don't think it's that good to keep playing the rat-cat game.

> the credit card companies are always very worried about their brand image, so they are not interested in any negative publicity.

Letting the bad guys keep doing what they do while putting it's own customers under shadow, to me, it sounds like the credit card companies are helping the bad guys.

As a Chinese myself and a credit card user, I'm more worried than you guys do, because we are more likely to receive that kind of treatment (compromised credit card and computer chips etc). I really hope somebody can teach those bad doers a unforgettable lesson.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#242
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

I believe you are talking about "Rotational Moment of Inertia" about various axis, instead of "Angular Momentum".

Angular Momentum of a body at rest is zero.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#243
post #203

Earlier quoted context omitted.

There is no way that the intelligence community would allow that fraud case to go ahead.

That assumes that 1) the intelligence community has the power to stop it and 2) that Apple believes this to be the case and 3) that Apple is confident that the intel community would use that power to protect them. That seems like a reach to me.

#3 isn't the intel community protecting Apple, it would be protecting themselves, which is a lot more plausible. They don't want detailed information about the techniques coming out. Odds are good that the Bloomberg story is still incomplete in some critical way, and decent that even if the story as a whole is broadly-speaking "true" there's still an outright lie contained in it. My guess would be the way in which it was discovered.

I work for a company that sells network appliances, and I've been questioned by customers as to why I'm doing an SRV DNS lookup instead of a standard A DNS record lookup in some software I wrote, and had every detail of how I use TLS picked over by some customers. (More power to them. Not a complaint.) Some people run really tight networks. I wouldn't be surprised the real discovery mechanism was someone noticing the packets heading out that had implausible source-dest pairs ("why is my internal network that barely knows the internet exists trying to send packets to $RANDOM_LOCATION?"). If the people discovering this were actually the intel agencies themselves, for instance, they'd find another story to tell rather than reveal that. I am absolutely, positively not claiming this is true; I have no more evidence of it than anyone else. I'm just giving an example of the sort of thing I mean. It's also possible the intel agencies slipped a hint to someone about what to look for; again, I have no info to that effect, just an example of why they might not want something to go to court.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#244
It makes me wonder how compromised the prosumer/enthusiast motherboards are. All of my important home systems are homebuilds using off-the-shelf motherboards purchased in person, and lack any IPMI access. Sure there's AMD's PSP (grumble, grumble) in my Ryzen box, but I can't help wonder what might be lurking on the motherboards, or for that matter in my network switch, router, access point, etc.

I've sometimes thought about picking up some type of used rackmount server, but hacks like this give me cold feet - aside from the usual issue of 1U/2U boxes sounding like jets taking off.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#245
post #178

Earlier quoted context omitted.

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…

Do you honestly think any of that is not something a nation state actor could pull off though?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#246

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite.

https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#247
post #224

Earlier quoted context omitted.

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

Payment systems are typically better defended than by just a sticker. It’s not surprising to see a ton of tamper switches, vibration/shock sensors, even light sensors. And they’re all powered by an internal batter and separate MCU that will brick the device upon open.

All of which are overcome by nation state actors if they want too.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#248
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

What's the motive? If we assume a motive of theft, seems more reasonable that there's organized crime involved than a state actor.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#249

Earlier quoted context omitted.

America has fabs, both old and leading edge, but ask industry giants like Gemalto to even bother to manufacture chips anywhere outside of Taiwan, assemble the final product outside of China. They will never do that, because they look for the cheapest solution. The bigger the company, the less it cares about things other than cost. This is why Mediatek and Broadcom can usurp the market of network SoCs, while making pr…

What about Japan? I know they've lost most of their semiconductor business as well, but they still have some capacity no?

I don't know that.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#250
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Did you look into Terahertz scanning?
Post reply on HN