Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

251–260 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#251

Earlier quoted context omitted.

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

About that, I can only say that Chinese android POSes do everything in software, for sure, without any hsm present.

The question is, how Chinese banks coax Visa into allowing them using them.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#252

Earlier quoted context omitted.

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

> To achieve this, the keyboard and the display is galvanically separated for the duration of the PIN entry Perhaps this sounds too dull to ask, but what stops the terminal from just ... not separating the keyboard and display?

Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#253

Earlier quoted context omitted.

"People with astigmatism (approximately 50% of the population) find it harder to read white text on black than black text on white. Part of this has to do with light levels: with a bright display (white background) the iris closes a bit more, decreasing the effect of the "deformed" lens; with a dark display (black background) the iris opens to receive more light and the deformation of the lens creates a much fuzzier…

I actually have astigmatism so that might be why I think it's even harder to read on black/dark themes. So yeah, definitely true in my case.

It's interesting to finally have some explanation as to why I have always found dark themes worse, also having astigmatism.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#254
post #200

Earlier quoted context omitted.

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...

Clover CEO here. Won't comment on a competing device but this may not work the way you think. In Clover's approach the touch controller input isn't reaching the Application Processor running Android when in PIN entry mode. You can do patent search if you're interested.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#256

Earlier quoted context omitted.

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

Second this, after having to go through a service level 1 DSS review for a few years. Lower level reviews (3,etc) just require self validation.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#257

Earlier quoted context omitted.

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

> They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). Given how sophisticated these attacks can be, I'd think they'd issue disposable equipment to be destroyed on return, like a cheap netbook or something. I don't see how you could trust an individual viewing a simple X-ray scan to detect some extra microchip the size of a signal conditioning coupler.

Procedures change, as attacks get more sophisticated the next step could be disposable devices. But an attack like the one described in this article won't be mitigated by having a disposable device. On the other hand having your laptop "hijacked" while on a business trip will most likely involve some extra PCB or components that are a little more obvious that something that's "built in".

Then again many companies or public institutions would find it hard to justify shredding each week maybe tens of laptops and phones that still have to be good enough to work on. Basically they still have to be a "standard issue" device with your company's software stack, config, etc.

I'm sure someone can find a good compromise between security and wastefulness.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#259
post #175

Earlier quoted context omitted.

Are you saying companies should or that you know of companies that do?

As far as I know, big EU companys do that, when they visit US, or they don't have sensitive information with them in the first place.

The problem is not the data on the machine, it's that you connect that machine to your trusted network when you're back.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#260
post #224

Earlier quoted context omitted.

Payment systems are typically better defended than by just a sticker. It’s not surprising to see a ton of tamper switches, vibration/shock sensors, even light sensors. And they’re all powered by an internal batter and separate MCU that will brick the device upon open.

All of which are overcome by nation state actors if they want too.

Depends on the hardware and the anti-tamper measures. I've seen POS terminals where the pcb was completely encased in security plastic, where any attempted breach would wipe the internal security keys, which meant the hardware just became a useless. They're so sensitive that these things enter "tampered state" from time to time without any tampering. I developed software on these things - and bricked multiple devices by accident, even though this was 'development' hardware.
Post reply on HN