Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

361–370 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#361
post #280

Earlier quoted context omitted.

> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker. You mean moment of inertia, not angular momentum. You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the cente…

Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…

> What was this company doing in hiring an untrustworthy manufacturer to handle secure devices? That's playing a game you've lost from the start

You're assuming that there were feasible alternatives; from their comment below:

"wasn't our device. There was a big, reputable company behind the device. We were ordering a number of those and they would be shipped to us directly from China. ... Also, we were basically locked in due to the magnitude of investment in the software we have developed for the device. ... Fortunately this only lasted for few months until it was dealt with"

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#362
post #358

Earlier quoted context omitted.

Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…

Another problem is anti-tampering measure is applied before the initial tampering check have been applied. Anyway, that wouldn't solve everything considering that if the chip itself is tampered with, that's undetectable short of an electron microscope analysis and even that wouldn't solve the problem of backdoor in the original chip design. As you say, that's un-winnable. The only way to really build trust is the cap…

> the real oblivion (destruction of shareholder value) with criminal charge for the company officers

This very rarely happens even if people have got killed. Also, good luck suing a Chinese company in China.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#363

Amazon are going all out on the denial https://aws.amazon.com/blogs/security/setting-the-record-str...

Apple is very strongly denying it as well

https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#364
This reminds me of that old story about the Xerox copy machines that the Soviet Union bought.

Where each unit was planted with a image recorder. And for years, the American spy agencies had a great laugh, that they were able to intercept all the documents that the Russians made a copy of.

Back then, this was an off-network infiltration. Where the copied images, were retrieved during regular servicing intervals by a Xerox technician.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#365
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

For the folks commenting below that we should bring the manufacturing back to the US, why wouldn't the bad guys just start bribing American workers to insert the attack hardware into devices made here?

It's not like Americans are somehow above being bribed.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#366

Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

> The naive approach would be to not connect to the dedicated NIC that's indicated on the back and in the instruction manual, but if you do this it masquerades onto the main NIC

cool, thanks for that info.

> just to write off the hardware

maybe you could just standup the mgmt network but blackhole route it at each switch port. The mgmt NIC thinks it's working properly but it can't talk to anyone nor can anyone talk to it.

at the expense of a dedicated switch.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#367
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

Canadian steel is considered by this administration to be a national security risk. But Chinese made boards and chips installed in weapons systems and crucial data centers? No problem.

Let that sink in for a moment.

https://www.wsj.com/articles/dont-trust-the-chinese-to-make-...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#368

Earlier quoted context omitted.

See, the article showed that even largest companies are not completely immune to the problem. This was decade ago and payment card industry, not exactly national security matters.

The PLA can lean on factory managers very effectively but they're not going to be interested in small time stuff like credit card numbers. The sort of sophisticated criminal gang doing something like this will have fewer coercive tools at its disposal and I'd imagine would target lower level employees with bribes.

I'm not sure; the DPRK are certainly known to make their espionage units self-funding through credit card fraud.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#369
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

This wasn't our device. There was a big, reputable company behind the device. We were ordering a number of those and they would be shipped to us directly from China. Also, we were basically locked in due to the magnitude of investment in the software we have developed for the device. Fortunately this only lasted for few months until it was dealt with. It was quite new back then (a decade ago) and it was a surprise fo…

How was it finally "dealt with?"

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#370
post #265

Earlier quoted context omitted.

It's in the article: "The illicit chips could do all this because they were connected to the baseboard management controller..."

Can you quote a single source from that article, or is it all anonymous?

That is also in the article...

"17 people confirmed the manipulation of Supermicro’s hardware and other elements of the attacks. The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."

Post reply on HN