Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

341–350 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#341
post #109

Earlier quoted context omitted.

Get an x-ray machine? They are surprisingly cheap pieces of hardware if you are willing to deal with a small area, low penetration image. Low penetration means no lead, which makes for something that's about as cumbersome as a large bar fridge.

It's mentioned in the article that X-Ray didn't help much: 'Gray or off-white in color, they looked more like signal conditioning couplers, another common motherboard component, than microchips, and so they were unlikely to be detectable without specialized equipment'

Can't the image be diffed with one of a trusted system?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#342
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to start working on our own. As a country, we need to close this gap, more automation and capability and there will be no need to outsource circuit board printing and manufacturing. We will be much better off.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#343
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

x-ray would have been easier, as others have said.

but you're talking about the addition of an entire board! probably on the order of 10% of the size of the main boards.

in this article, perhaps dumbed down or altered, they are talking about the addition of a single, tiny chip, too small to even be an MCU let alone have wireless capability (which BTW requires an antenna).

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#345

Earlier quoted context omitted.

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

> Has the West completely lost the ability ... at first I had the same thought. but i have to question how securely the same manufacturing could be done in a US plant. the US employee base has its fair share of desperate, ethically challenged individuals. and plenty of incentives to make a quick buck could be offered here too. idk.

The consequences if US citizens or residents get caught engaging in espionage for a foreign government are go-to-jail-for-years serious.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#346
post #163

I wonder if SuperMicro being delisted from Stock market has anything to do with this? Where their "Accounting Errata" were merely cover up.

I'm not sure exactly what "delisting" entails, but if my billion dollar company was about to be in the news for having its supply chain compromised by a foreign state actor, I would be happy to not see the stock crash triggered by a public order book.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#347
Doesn't the printed circuit board also need to be redesigned, to allow for the spy chip to be inserted?

So, this means that China forced multiple companies to modify their processes, in order to pull this off.

1. The PCB designer

2. The PCB printer, if it's a separate company

3. The company assembling the final product

And if they forced the PCB to be redesigned, then wouldn't this be a immediate red flag? But this means that the customer, Supermicro, would have to audit the PCB results as well.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#348
post #28

Earlier quoted context omitted.

Firewalls in high security environments aren't just port/protocol based. You lock everything down - source ip/port and destination ip/port. You should know where it is coming from and where it is going to. Navy ships don't upload via Dropbox.

In the parent I described a system which would be able to communicate through those restrictions to another compromised host (remember we're assuming everything is compromised for the sake of this article, which actually seems like a good assumption now).

> remember we're assuming everything is compromised

I think Bloomberg (and all related) web servers displaying the article are compromised and they're leaving out critical facts the point the finger elsewhere.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#349
post #154

Earlier quoted context omitted.

Good point. Definitely seems designed for mobile (only).

I know this is going off the main topic. But it is very strange that I discover Black background, as in Dark mode in macOS, doesn't work at all despite what I have always thought it would be cool. But Black background on mobile devices work absolutely great!. And I have no idea why, I searched on Google and couldn't find any decent answer. All results were either OLED being battery friendly with switched off pixels o…

As a fan of dark color themes and displays, I've shared a bunch of thoughts related to this on my personal blog. But I'd like to share a few quick thoughts below. I am not an expect on these matters, so these are just my opinions:

1. Glare. When reading on a small device, the amount of glare reflected in the screen space occupied by black pixels may be fairly minimal depending on your reading environment and positioning. Also, although mobile devices use glossy display surfaces, they tend to have several anti-glare layers in the display stack. You said your computer is macOS, so I suspect you're unlucky enough to be reading on a glossy laptop display. With "dark mode" color schemes, your eyes can more easily see the reflected scene (maybe your office lights, an exterior window, or even your own face). And the focal length of that reflected scene is 2x your reading distance to the screen. That reflected scene at an extended focal length is more relaxing for your eyes to focus on. So in order to read, you need to fight your natural tendency to relax and look at the reflected scene.

If you are lucky enough to be reading on a matte desktop display (typically a professional or prosumer monitor, such as a Dell UltraSharp or LG 43MU79-B), the glare will be minimal and it should be much easier to read.

2. Pixel density. I contend that one reason dark themes have become more prevalent in recent history is thanks to wider adoption of high pixel density displays. At a legacy density of approximately 75 dots per inch, the stroke weight of bright text on a dark background appears too faint if the strokes render as just one pixel in width. Higher pixel density allows for the strokes of letters to be wider than a single pixel, allowing for greater clarity. If you ever designed a dark theme in the days of ~75 dpi displays, you might naturally favor bold text as the default because it was considerably easier to read. (Interesting sidebar: many console oriented bitmap fixed-width fonts historically used two pixels for stroke weight, especially in the horizontal dimension, presumably because they were designed to be used bright-on-dark.)

Now, you did again say you were reading on macOS, so your display's pixel density is probably higher than ~75 dpi. But a MacBook Pro is still only ~220 dpi. A Surface Book is ~260 dpi. A Dell XPS laptop with a 4K display will be a little higher still (maybe ~300 dpi). But many phones are using 450+ dpi displays. The stroke weight of a character on a mobile device is several pixels wide, so it's highly defined and clear.

3. Font selection (related to above). Bloomberg has selected a serif font, presumably because they are a media organization and serif fonts are typically used for article bodies. However, combined with pixel density, the serifs will lose a lot of their definition and (in my opinion) reduce readability versus a sans-serif font. As an experiment, pull up the dev tools and change article[data-brand="businessweek"] .body-copy p to use sans-serif and see what you think. It may be marginally easier to read.

4. Don't discount OLED. The contrast that Bloomberg selected is maximal (pure black background and pure white text) and that works well for OLED since the background vanishes entirely. However, since most desktop and laptop monitors are not OLED, you're still getting backlight bleed, so the contrast is imperfect. Especially combined with the glare factor above, my experience is that given LCD backlight bleed, it is better to use a dark gray background instead of stark black. This makes the backlight bleed less distracting, for lack of a better word. The background ends up looking more uniform.

As with above, try adding "background-color: rgb(40,40,40)" or similar to .body-copy and see what you think.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#350
what they describe isn't possible. which is perhaps why Apple et al. are easily able to refute it.

what actually occurred must be something a bit different, that they didn't understand and/or aren't conveying accurately or didn't receive accurate info due to it being classified. or you know, because the general press is still at movie technology ... the hacker is in the building!

A chip the size of a pencil point can't be inserted anywhere useful or do anything meaningful. Something that small amounts to a discrete component, not a "chip", if packaged. If bare die, it still can't be vastly complex and needs to be mounted in a way that is very obvious (epoxy blob).

So, it must be an additional discrete that inhibits the burning of a W/O fuse in the BMC or some other management function. Thus preventing the disabling of some debug function.

There is no way it has communication capability, etc, on its own.

EDIT: ah, @baybal2 perhaps figured it out. it's likely flash memory and the bmc already has provision to read it as the "recovery" flash.

Post reply on HN