Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

441–450 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#441
post #209

This is just the hack that was discovered because there was macroscopic evidence of it. All it would take to pull off a similar hack that was undetectable is one well placed mole in the company that designed a key piece of silicon or software.

no way, an intentional design-level plant would have to pass through many eyeballs. a single mole wouldn't be enough.

I have worked in both chip design and security so I feel well qualified to make this assessment: a single mole in the right place who knew what they were doing would definitely be enough. Security holes get past design review all the time by accident. A skilled hacker could easily insert an intentionally obfuscated one that would escape detection.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#442
post #266

Earlier quoted context omitted.

I'd very much love to hear more stories if you have any!

We had MasterCard end-to-end test auditor on site. This is the first time ever you get to do a transaction with real transaction system with real credit card. Due to requirements we opted to have the only large meeting room to have outside our secure zone. This created an issue as we had no network access from there and in the end we decided to use slow GPRS terminal for the test. The end-to-end test starts with offl…

FWIW, the described technique (or something roughly equivalent) is now standardized as 0-rtt early data in TLS 1.3. (you still need 1-rtt for TCP, unless you can combine this with tcp fast open, or run TLs over UDP)

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#444

Earlier quoted context omitted.

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct. HSMs are required so that the company does not need to have PIN codes exposed anywhere. Not having PINs or full credit card data makes your life easier as there is nothing to steal from you in the first place. If your company stored PIN codes it means you were in breach of the contract and it had to lie to the auditors to pass the certification.

It is correct. Incompetence abounds. You are correct about the HSM but it does not enforce anything except for the exchange between whoever and MC. You do realize that pin codes are entered into a UI and phone system as plain text right? There are PCI audits but they are a joke.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#445
post #367

Earlier quoted context omitted.

Canadian steel is considered by this administration to be a national security risk. But Chinese made boards and chips installed in weapons systems and crucial data centers? No problem. Let that sink in for a moment. https://www.wsj.com/articles/dont-trust-the-chinese-to-make-...

I love a good Trump bashing moment as much as the next guy, but this is inaccurate. The DoD has stringent requirements and quality control procedures in place for their chip procurement. Not to say they couldn't be improved, but the DoD has been aware of this threat for a while, and seems to be mitigating the risk fairly well.

Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes.

http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied...

The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#447
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

This feels cargo cultish. Products drop from the sky. One day they become poisonous. You have no idea how to reproduce them locally. So you come up with hacks to make then less dangerous.

We really need to get back into manufacturing if this is our brave new world.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#448

Earlier quoted context omitted.

Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…

I honestly did not know about that. I thought that if you move any mass (remove non zero mass and place it somewhere else) there must be at least one axis which you can use to detect the change in moment of inertia.

If the mass had to all move to one other place this would be correct (the center of mass would have to change), but the attackers are able to move the mass to multiple other places.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#449

Earlier quoted context omitted.

This wasn't our device. There was a big, reputable company behind the device. We were ordering a number of those and they would be shipped to us directly from China. Also, we were basically locked in due to the magnitude of investment in the software we have developed for the device. Fortunately this only lasted for few months until it was dealt with. It was quite new back then (a decade ago) and it was a surprise fo…

How was it finally "dealt with?"

I wouldn't know. We were just buying the stuff.
Post reply on HN