I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
321–330 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#322Earlier quoted context omitted.
NSL letter, under active investigation
NSLs require secrecy not lying.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#323white text on 0,0,0 black background... ugh my eyes do not thank thee
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#324Earlier quoted context omitted.
What about Japan? I know they've lost most of their semiconductor business as well, but they still have some capacity no?
I’m under the impression that China does not make chips, but they do final assembly cheaper and faster than everyone else. I don’t know if any companies do PCB manufacturing and assembly outside of China in large numbers.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#325Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…
Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?
The perception is that Apple is perfect and worth paying 3x the cost?
EDIT: Curious if all of these Apple comments are going to disappear. I believe they have a strong marketing team to hide dissent.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#326Earlier quoted context omitted.
Effectively nothing can be constrained by a whitelisting firewall if you have a sufficiently bored actor. You can smuggle data through a variety of benign looking protocols, things that wouldn't matter in the least generally. Your average server contacts hundreds of different public NTP servers, binary repositories, domain name servers every day. If the keys to the kingdom are a 32 byte ECDSA private key, you've lost…
Firewalls in high security environments aren't just port/protocol based. You lock everything down - source ip/port and destination ip/port. You should know where it is coming from and where it is going to. Navy ships don't upload via Dropbox.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#327I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Could this be solved by a clause in the contract that specified if any randomly sampled devices came tampered with, the manufacturer did not get paid?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#328Earlier quoted context omitted.
SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…
OpenBMC (Facebook, Google, Microsoft, Intel, IBM and others) is working on open-source baseboard management software, https://www.linuxfoundation.org/blog/2018/03/openbmc-project... > The organizations behind the new project each have already made substantial contributions to creating open source baseboard management controller (BMC) firmware. Now, working together, they will define the vision for a standard stack th…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#329Earlier quoted context omitted.
Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...
This only accept contact-less payment who doesn't require pincode.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#330I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…