Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

431–440 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#431
post #413

Earlier quoted context omitted.

What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

The trick seems to be having sufficiently uninformed people in all positions that might get to write that kind of response. No need to feign ignorance when you can have the real thing.

At least in the case of Amazon, the denial is published under the name of the CISO, Steve Schmidt, who previously worked for the FBI for a decade.

https://aws.amazon.com/blogs/security/setting-the-record-str...

Not saying he's not lying but it definitely raises the stakes.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#432
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

>Seriously, why are we still outsourcing chip manufacturing to other countries?

I actually agree it might be better for the Americans to manufacture things in America - especially things used in critical government systems.

But this seems like a human problem - if all the factories were moved to America, couldn't those factory managers etc also be bribed?

American manufacturing in the 60s was rife with unions w/ ties to organized crime.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#433
post #97

Earlier quoted context omitted.

I looked up supermicro blade motherboards, and saw that the chip was right near the IPMI chip's line to spi flash. And prior to that, there were already persistent rumors in the Chinese interney of certain Chinese mobos sending "weird garbage on ICMP," and "BMCs that somehow boot and work with their flash memory soldered off" Remembering that, I might even suggest that this is not a modchip that does something with s…

An update on that theory: AST2400 has option for two SPI memories, one main, one "recovery." https://download.csdn.net/download/duanzhang512/10385038 The recovery overrides the primary if detected by default. The place they put their "filter cap" is right on top the empty TSOP8 pad for the recovery flash. And they probably ordered the factory to sneak the traces just a little bit more, or put hidden vias under it, or…

This is the most plausible theory I've read in this thread. Assuming the image in the article is a stock image (there isn't yet a clear image of a definitely compromised board), then the added part could simply be another TSOP8 Flash part. This implies the firmware to the AST2400 is unsigned (which it appears to be, as there's coreboot options for it).

That makes the whole thing gloriously simple. A part "stuck on" afterwards is obvious. A part fitted into a no-fit footprint after optical inspection is not, it looks exactly as if it was meant to be there.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#434
Like data breaches, this will be big news that some devices were compromised at some time. Then followed by a slow dribble here and there, that, oh yeah, well more than we initially thought. Then a few months later it will be, "Yeah, it's really a lot more than we thought." Maybe a year from now it will basically turn out to be everything. But numbers get so big so fast people don't really know how to effectively parse the difference between 20 million devices and 20 billion devices. So it won't matter to most people.

And really, it shouldn't matter to most people. There's nothing the vast majority of people can do about this. It's not like we can just go buy stuff made in the U.S.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#435
post #351

Earlier quoted context omitted.

they have literally every reason to deny and literally no reason to say it's true

Not at all. It would be quite damaging to their reputation if it came out later that they were affected by this, knew it, and lied about it. Especially since the privacy of customer data is a key part of their marketing message these days.

What percentage of stories like this do you think never come out publicly? 50%? 90%?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#436

Earlier quoted context omitted.

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another? The moment the option of taking control of a production line of som…

>Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another?

It's certainly easier to enforce laws and observe manufacturing processes at domestic factories than it is at factories thousands of miles away in a country that actively encourages IP theft and other wrongdoings, don't you think?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#437

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

The article says they shipped the boards to a company in Ontario, lawyerly:

>…At no time, past or present, have we ever found any issues relating to modified hardware or malicious chips in SuperMicro motherboards in any Elemental or Amazon systems. Nor have we engaged in an investigation with the government.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#438
> In order to get further down the trail, U.S. spy agencies drew on the prodigious tools at their disposal. They sifted through communications intercepts, tapped informants in Taiwan and China, even tracked key individuals through their phones, according to the person briefed on evidence gathered during the probe.

So this is still possible ? And this is slipped so lightly in the article.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#439

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

They have to deny it. If the allegation is true, it means the Chinese CCP Gov knows which computer parts are produced specially for US gov or certain big companies and target precisely. There has to be some deep link for information flow to allow that. Anyway, worth further digging.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#440

Earlier quoted context omitted.

you would be extremely hard pressed to fit that amount of logic (and code) into that small of a package. and to operate intelligently, as you suggest, it needs a CPU clock, not available to it from where it would sit. And it would need to do signal analysis in real time, with no power and no clock. it's not possible.

Clockless CPUs exist.

grain-sized? and they still need power.
Post reply on HN