Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

321–330 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#321
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

That's kinda amazing

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#322
post #199
post #142

Earlier quoted context omitted.

NSL letter, under active investigation

NSLs require secrecy not lying.

The snowden leaks among others show that most companies aware of PRISM ended up flat out lying about it. Either it's a type of NSL we haven't seen before or employees receive death threats, etc.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#324

Earlier quoted context omitted.

What about Japan? I know they've lost most of their semiconductor business as well, but they still have some capacity no?

I’m under the impression that China does not make chips, but they do final assembly cheaper and faster than everyone else. I don’t know if any companies do PCB manufacturing and assembly outside of China in large numbers.

Not exactly, PCB assembly is super cheap everywhere thanks to propagation of chipshooters, what makes the cost go up is logistics - what do you do after you populate the board for your part? Ship it across the world, or to another factory behind the corner?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#325

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

> I wonder what reason Apple has to hide.

The perception is that Apple is perfect and worth paying 3x the cost?

EDIT: Curious if all of these Apple comments are going to disappear. I believe they have a strong marketing team to hide dissent.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#326
post #28

Earlier quoted context omitted.

Effectively nothing can be constrained by a whitelisting firewall if you have a sufficiently bored actor. You can smuggle data through a variety of benign looking protocols, things that wouldn't matter in the least generally. Your average server contacts hundreds of different public NTP servers, binary repositories, domain name servers every day. If the keys to the kingdom are a 32 byte ECDSA private key, you've lost…

Firewalls in high security environments aren't just port/protocol based. You lock everything down - source ip/port and destination ip/port. You should know where it is coming from and where it is going to. Navy ships don't upload via Dropbox.

Certainly true, since Dropbox doesn't work on Windows XP anymore.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#327
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Could this be solved by a clause in the contract that specified if any randomly sampled devices came tampered with, the manufacturer did not get paid?

Ah, yes, and then we would voluntarily go out of business. And the supplier will just have another customer that would not be so principled.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#328

Earlier quoted context omitted.

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

OpenBMC (Facebook, Google, Microsoft, Intel, IBM and others) is working on open-source baseboard management software, https://www.linuxfoundation.org/blog/2018/03/openbmc-project... > The organizations behind the new project each have already made substantial contributions to creating open source baseboard management controller (BMC) firmware. Now, working together, they will define the vision for a standard stack th…

Wouldn't help. The BMC hardware has direct serial access to CPUs and other hardware in the machine. Communication is unencrypted. A hardware modification attack wouldn't touch the firmware at all and could still compromise IPMI functionality.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#329
post #219
post #200

Earlier quoted context omitted.

Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...

This only accept contact-less payment who doesn't require pincode.

It accepts contactless payments over the threshold where a PIN is required, and does in fact prompt for a PIN using an on-screen keypad.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#330
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

So you had hard evidence that your manufacturer was vandalising your property? Couldn't you drop them?
Post reply on HN