Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

411–420 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#411

I don't know which is more disturbing here. That the Chinese military is technically competent enough to pull off such a thing. Or that they are incompetent enough, to not secure their own back doors and networks, and allowed the FBI, NSA, and other American government organizations, the ability to counter-hack them, and monitor all their internal communications. The truth is somewhere in between. So, this article is…

Not surprising, when you consider that every intelligence agency spends at least 10x more money on offense than defense. I first became aware of this when I worked at a company where we had the NSA "defense" as a customer. We tried and tried to get contacts on the offense, because it was a much bigger market opportunity, but the company went under before we succeeded. So it's our Ferrari offense against their Fiat defense, and vice versa. (Not at all a comment on skills or motivation BTW. There might be an element of having one's pick of a larger talent pool, but mostly it's about resources.) It's practically inevitable that we'll both score lots of points off each other.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#412
post #209

This is just the hack that was discovered because there was macroscopic evidence of it. All it would take to pull off a similar hack that was undetectable is one well placed mole in the company that designed a key piece of silicon or software.

no way, an intentional design-level plant would have to pass through many eyeballs. a single mole wouldn't be enough.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#413

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

The trick seems to be having sufficiently uninformed people in all positions that might get to write that kind of response. No need to feign ignorance when you can have the real thing.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#414
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

This reminds me of a story about, IIRC, Soviet intelligence personnel determining that a photocopy machine at their consulate in the USA was bugged by the CIA by measuring it's weight and comparing that value to the standard value published by Xerox.

Modern times, but same old methods of "debugging"

The angular momentum stuff is innovative though.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#415
post #178

Earlier quoted context omitted.

You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

But in the US we just use signatures for card transactions instead of chip PIN :/

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#416
post #33
post #23

The Chinese government didn’t directly address questions about manipulation of Supermicro servers, issuing a statement that read, in part, “Supply chain safety in cyberspace is an issue of common concern, and China is also a victim.” Essentially China ils saying "it was not me". Plausible

I Read that as "The US is also attacking our hardware supply chains". That is, the statement concerned supply chain attacks in general, not this specific one.

China is sourcing virtually nothing from US. If US is attacking the supply chain of China, it's doing it on Chinese soil. Which brings us back to my interpretation

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#417

Earlier quoted context omitted.

> I hope this corrects the mistaken believe that China can't home grow sophisticated tech. There's nothing particularly sophisticated about what they did, especially given what China has access to as one of the central hubs of tech manufacturing. There are two dozen nations (or more) that could do this from a strictly technical standpoint (few have the kind of required supply chain access to pull it off at scale in a…

You're right. One question though. Would a politically correct, by-the-book US president have had the balls to sanction China? Considering such sanctions could affect the US economy.

Please take this political posturing elsewhere.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#418

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

Regarding both cases:

https://en.wikipedia.org/wiki/Gag_order

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#419
post #367

Earlier quoted context omitted.

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

Canadian steel is considered by this administration to be a national security risk. But Chinese made boards and chips installed in weapons systems and crucial data centers? No problem. Let that sink in for a moment. https://www.wsj.com/articles/dont-trust-the-chinese-to-make-...

I love a good Trump bashing moment as much as the next guy, but this is inaccurate. The DoD has stringent requirements and quality control procedures in place for their chip procurement. Not to say they couldn't be improved, but the DoD has been aware of this threat for a while, and seems to be mitigating the risk fairly well.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#420

Earlier quoted context omitted.

> Has the West completely lost the ability ... at first I had the same thought. but i have to question how securely the same manufacturing could be done in a US plant. the US employee base has its fair share of desperate, ethically challenged individuals. and plenty of incentives to make a quick buck could be offered here too. idk.

The consequences if US citizens or residents get caught engaging in espionage for a foreign government are go-to-jail-for-years serious.

Death penalty.
Post reply on HN