Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

331–340 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#331

I don't know which is more disturbing here. That the Chinese military is technically competent enough to pull off such a thing. Or that they are incompetent enough, to not secure their own back doors and networks, and allowed the FBI, NSA, and other American government organizations, the ability to counter-hack them, and monitor all their internal communications. The truth is somewhere in between. So, this article is…

> America is finally admitting, that they too, actively spy on other countries.

The Snowden revelations made that very clear to all years ago, no?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#332

Earlier quoted context omitted.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

About that, I can only say that Chinese android POSes do everything in software, for sure, without any hsm present. The question is, how Chinese banks coax Visa into allowing them using them.

Probably it just goes through as a card not present (CNP) transaction?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#333
post #59

Earlier quoted context omitted.

5. When a server was installed and switched on, the microchip altered the operating system’s core so it could accept modifications. The chip could also contact computers controlled by the attackers in search of further instructions and code. So, in typical vulnerability/payload/exploit fashion, the board's bus is vulnerable by default, because the chip pierces all the usual lines of defense protecting against network…

They didn't do anything to the CPU, what they did is the modchipped the line from EEPROM and the board management controller. They probably found it out when they were repeatedly tried to reflash the BMC flash, and saw that checksums did not match.

[deleted]

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#334

This seems either incredibly suspicious to me or indicates that Apple is way more protective of security and distrustful of the USGov than I would have thought: “Because Apple didn’t, according to a U.S. official, provide government investigators with access to its facilities or the tampered hardware, the extent of the attack there remained outside their view.” Why wouldn’t the FBI be able to compel Apple to turn ove…

Apple seems cagey about its reputation with the Chinese government. Their balls are directly in the Chinese government's hands, they don't want to do anything that might make the government upset. Beyond having their manufacturing there, it's also the biggest untapped market in the world.

"Untapped" I see what you did there.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#335
post #135

Earlier quoted context omitted.

"Designed to be insecure" is probably unfair to the designers of IPMI. Security was just not as big a concern as it is today.

This is only really valid for protocols or products designed before the Morris worm of 1988. Anything designed beyond 2000 has no excuse for not thinking about internet security.

Well, IPMI isn't supposed to be exposed to the internet. Best practices have you running your BMC's on a completely separate, highly locked down administrative network.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#336

We need open source hardware designs that can be built locally (where ever your local might be). This black box hardware crap has to stop. Smart people who know how all this works need to dump all their knowledge in to a design and a process. Trade secrets are keeping us not only limited in choices but exposed to bad actors who can control a link in the supply chain.

This sounds beyond complex to manufacture. Especially at Fortune 500 levels.

DIY? Well its going to be larger, hotter, more failures, and probably more expensive.

There is a reason companies specialize.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#338
post #97

Earlier quoted context omitted.

That would make a lot of sense and would give the attacker a way to interface with all of the other hardware (network, disk etc.). Do you have a source for this information?

I looked up supermicro blade motherboards, and saw that the chip was right near the IPMI chip's line to spi flash. And prior to that, there were already persistent rumors in the Chinese interney of certain Chinese mobos sending "weird garbage on ICMP," and "BMCs that somehow boot and work with their flash memory soldered off" Remembering that, I might even suggest that this is not a modchip that does something with s…

An update on that theory: AST2400 has option for two SPI memories, one main, one "recovery."

https://download.csdn.net/download/duanzhang512/10385038

The recovery overrides the primary if detected by default.

The place they put their "filter cap" is right on top the empty TSOP8 pad for the recovery flash. And they probably ordered the factory to sneak the traces just a little bit more, or put hidden vias under it, or simply had somebody very dexterous to solder it to pads with hair thin wires.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#340

Earlier quoted context omitted.

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct. HSMs are required so that the company does not need to have PIN codes exposed anywhere. Not having PINs or full credit card data makes your life easier as there is nothing to steal from you in the first place. If your company stored PIN codes it means you were in breach of the contract and it had to lie to the auditors to pass the certification.

"If someone was going to break the law, they would have to lie about it first."

Legit companies don't want the info and anyone that wants the info isn't doing anything legal with it.

Post reply on HN