Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

401–410 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#401

This reminds me of that old story about the Xerox copy machines that the Soviet Union bought. Where each unit was planted with a image recorder. And for years, the American spy agencies had a great laugh, that they were able to intercept all the documents that the Russians made a copy of. Back then, this was an off-network infiltration. Where the copied images, were retrieved during regular servicing intervals by a X…

Huh crazy, I hadn't heard about this before! Just found a couple posts on it [0][1], for anyone who's interested.

0: https://electricalstrategies.com/about/in-the-news/spies-in-...

1: https://discover.cobbtechnologies.com/blog/the-soviet-union-...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#402
post #99

Earlier quoted context omitted.

Sorry, but this doesn't sound as true or there is huge mistakes done in choosing supply chain for such sensitive matter. How come company keep ordering devices from some unverified sources from China, and after hitting a wall keep doing same? How do you accept shipment of such devices without randomly opening and inspecting sample(yes losing all data, but electronic inspection can be done). How you didn't investigate…

While it may sound sensational this was more of an operational issue, really. We were told by Visa and Mastercard that it is not even a question if we are going to be targeted. If you work in payment card industry you are constantly being attacked and the only way is to make it part of the process to deal with those things. Our network was hacked but what was important was tight, almost mathematical processes around…

[deleted]

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#404
post #351

Earlier quoted context omitted.

they have literally every reason to deny and literally no reason to say it's true

Not at all. It would be quite damaging to their reputation if it came out later that they were affected by this, knew it, and lied about it. Especially since the privacy of customer data is a key part of their marketing message these days.

Damaging how? People will stop buying iPhones? Be realistic.

Assuming the story is true, you lie lie lie until something bigger in the news happens then you quietly relent.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#405
post #203

Earlier quoted context omitted.

There is no way that the intelligence community would allow that fraud case to go ahead.

That assumes that 1) the intelligence community has the power to stop it and 2) that Apple believes this to be the case and 3) that Apple is confident that the intel community would use that power to protect them. That seems like a reach to me.

I'm reminded of Matrix-Churchill: https://en.wikipedia.org/wiki/Arms-to-Iraq

Although that nearly went in the other direction. The people involved were nearly sent to jail for shipping arms to Iraq which they had been doing at the behest and with the complicity of the UK security services.

The power of government agencies to turn up to people's offices and tell them "you need to stop doing what you're doing, and it's illegal to mention this meeting" should not be underestimated.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#406
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection?

No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products will be returned at the suppliers expense." And then add a clause that says ">3 non-compliance events in under # months will result in the entire PO (10 or 20 units) being returned and all contracts cancelled."

I cannot believe you are getting screwed by a company you choose to do business with and yet you eat cost to ensure they aren't screwing you. Just get a new supplier! Do on-site inspections at their facility. This is nuts.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#407

Earlier quoted context omitted.

It would be foolish to show your hand for few pennies.

Might make a difference if those pennies can't be tracked back to the government.

Yup. This would be the modern equivalent of Air America and other schemes by the CIA to raise money to operate by involving themselves in illegal activity like the drug trade.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#408
post #385

Earlier quoted context omitted.

An update on that theory: AST2400 has option for two SPI memories, one main, one "recovery." https://download.csdn.net/download/duanzhang512/10385038 The recovery overrides the primary if detected by default. The place they put their "filter cap" is right on top the empty TSOP8 pad for the recovery flash. And they probably ordered the factory to sneak the traces just a little bit more, or put hidden vias under it, or…

eh, does this mean that the motherboard is not tampered with ?

Well, it means that provision for the second flash was already there, and PLA simply exploited that fact that Aspeed chips are virtually omnipresent in higher end servers.

It also means that the extend of intervention into board design was minimal, and that a trivial automatic xray would not have picked it up. And as implied in the article, later they buried the bug to beat the AOI, if it was done higher upstream.

So, they would've been screwed even if they were doing board testing outside of China.

That's a clever trick.

But the sole fact that the chip has "to phone home" makes detection trivial, and puts the usefulness of the method to nil - anybody sees the router blink when it shouldn't and your bug's cover is blown.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#409
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

For the folks commenting below that we should bring the manufacturing back to the US, why wouldn't the bad guys just start bribing American workers to insert the attack hardware into devices made here? It's not like Americans are somehow above being bribed.

The bad actors could be brought to trial in a United States court, which is a level of deterrent not included in offshore manufacturing. If a US manufacturer was found selling tampered chips then the company itself could be held liable. This would create a general pressure to increase onsight security.

There are other benefits to us based manufacturing, but you only brought up the crime aspect so I will leave the other benefits unsaid.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#410

We need open source hardware designs that can be built locally (where ever your local might be). This black box hardware crap has to stop. Smart people who know how all this works need to dump all their knowledge in to a design and a process. Trade secrets are keeping us not only limited in choices but exposed to bad actors who can control a link in the supply chain.

[deleted]
Post reply on HN