Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

291–300 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#291
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

> Has the West completely lost the ability ...

at first I had the same thought. but i have to question how securely the same manufacturing could be done in a US plant.

the US employee base has its fair share of desperate, ethically challenged individuals. and plenty of incentives to make a quick buck could be offered here too. idk.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#292

Earlier quoted context omitted.

America has fabs, both old and leading edge, but ask industry giants like Gemalto to even bother to manufacture chips anywhere outside of Taiwan, assemble the final product outside of China. They will never do that, because they look for the cheapest solution. The bigger the company, the less it cares about things other than cost. This is why Mediatek and Broadcom can usurp the market of network SoCs, while making pr…

What about Japan? I know they've lost most of their semiconductor business as well, but they still have some capacity no?

I’m under the impression that China does not make chips, but they do final assembly cheaper and faster than everyone else.

I don’t know if any companies do PCB manufacturing and assembly outside of China in large numbers.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#293

Earlier quoted context omitted.

That would be in line with the requirements. You go through stringent certification with the software and hardware that has access to the actual PIN and then show that the application and application hardware never really has any access to it so that you can customize/update your software. This is the easy part. The hard part I remember was establishing secure communication between all components in the system (initi…

Agree the people and process side is very difficult to do well. Familiar with all those and more -- we have extremely good, dedicated employees who care deeply about doing those things right. We have some fun stories on this topic, like when we were using our PCI PIN approved secure room in our development office for the first time. We papered over the cage to prevent a security camera from being able to see employee…

I have few more stories like the time when I closed the HSM rack door a bit too energetically and caused outage to entire company as we had to bring in third security officer to re-initialize it.

We also had special screens created for all cameras in the datacenter to block view on the HSM racks.

The biggest issue was, just before end-to-end test we figured out we forgot one of critical procedures (it was establishing authenticity of the HSM used) and we had to scramble to get new HSM and to re-establish all cryptographic material (so new storage keys, etc.)

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#294

Just as a sidenote: X-raying PCBs and then diffing them against clean PCBs is a worthwhile thing to do if you're concerned about hardware backdoors, or 'interdiction' of hardware in a supply chain. I do this sometimes when ordering super-critical equipment like Thinkpads from the U.S as you never know what lurks on the motherboard (keyloggers, etc). I have a clean Thinkpad that I use to compare against potential back…

Sometimes the difference is inside of a chip.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#295
post #234

So what is the alternative to SuperMicro if you aren't large enough design your own board?

Other motherboard vendors (e.g. Tyan, Asrock, Gigabyte make server boards), or buying entire servers from Dell, HP, ... And hoping they don't have issues like this, despite probably all manufacturing partly in China.

Define partly ? Almost all components are coming from China

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#296

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

>Each time, we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them.

An uncharitable reading, but this statement does not exclude the possibility of investigations by 3rd parties hired by Apple.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#297

Is this as big as it sounds?

Probably much bigger. It's naive to assume Supermicro was the only vendor compromised in this way. Similar implants probably exist in equipment from every major vendor of information-processing equipment. Routers, mobile network equipment, you name it.

This is the leverage you give another nation-state when you let them control your supply chain.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#298

So, what was the SMT part supposed to be, and what was put in there instead? I would love identifying markings, or you know, a datasheet. Nothing so far I've read includes part numbers. Sure would like to go through my supply to see if I have any of the offending parts.

something like this http://www.littelfuse.com/products/tvs-diode-arrays/ultra-lo... not only looks the part, but actually belongs on the data lines

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#299
post #280
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker. You mean moment of inertia, not angular momentum. You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the cente…

Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like a reasonable number of parameters to fix by adding and removing small amounts of material.

What was this company doing in hiring an untrustworthy manufacturer to handle secure devices? That's playing a game you've lost from the start. Not every problem is technical!

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#300
post #56

When will this stuff finally have consequences for China? Their behavior, not their communication, has been overtly hostile for a while. Yet, very few politicians openly adress the issue.

> When will this stuff finally have consequences for China?

Hahaha funny thing to say after disclosers from NSA/CIA/FBI/GCQH/BND...

Post reply on HN