Earlier quoted context omitted.
Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?
they have literally every reason to deny and literally no reason to say it's true
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
351–360 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#352Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#353Earlier quoted context omitted.
I'd very much love to hear more stories if you have any!
We had MasterCard end-to-end test auditor on site. This is the first time ever you get to do a transaction with real transaction system with real credit card. Due to requirements we opted to have the only large meeting room to have outside our secure zone. This created an issue as we had no network access from there and in the end we decided to use slow GPRS terminal for the test. The end-to-end test starts with offl…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#354Earlier quoted context omitted.
> They attacked the Base Management Controller. Do you know this, or are you speculating?
It's in the article: "The illicit chips could do all this because they were connected to the baseboard management controller..."
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#355I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#356Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…
What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants...
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#357I don't know which is more disturbing here. That the Chinese military is technically competent enough to pull off such a thing. Or that they are incompetent enough, to not secure their own back doors and networks, and allowed the FBI, NSA, and other American government organizations, the ability to counter-hack them, and monitor all their internal communications. The truth is somewhere in between. So, this article is…
my take on the article was that US counterintelligence sort of cobbled together some hacked phone communications with some info from human agents working in or around or near Chinese factories. to say that "we own them" maybe goes too far?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#358Earlier quoted context omitted.
> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker. You mean moment of inertia, not angular momentum. You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the cente…
Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…
As you say, that's un-winnable. The only way to really build trust is the capacity to sue your manufacturer to oblivion - I mean the real oblivion (destruction of shareholder value) with criminal charge for the company officers, not the lame single digit percent of a single year of profit with a discount if you settle.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#359Earlier quoted context omitted.
Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…
I honestly did not know about that. I thought that if you move any mass (remove non zero mass and place it somewhere else) there must be at least one axis which you can use to detect the change in moment of inertia.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#360I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…
The moment the option of taking control of a production line of something _this important_ becomes available, your local specialized organized crime outfits will start to figure out ways to insert themselves into those production lines, learning the ins and outs, and figuring out a way to get something, anything, in there that won't be noticed but will give them a hook into millions of systems.
The law does not prevent crime. It just puts a price on it. While that price is typically too high for individuals, for organizations that have no business registration to revoke, and no CEO to drag to court, it is an entirely trivial cost.