Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

451–460 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#451

Earlier quoted context omitted.

I’m under the impression that China does not make chips, but they do final assembly cheaper and faster than everyone else. I don’t know if any companies do PCB manufacturing and assembly outside of China in large numbers.

Not exactly, PCB assembly is super cheap everywhere thanks to propagation of chipshooters, what makes the cost go up is logistics - what do you do after you populate the board for your part? Ship it across the world, or to another factory behind the corner?

That largely depends on the size of your board and the total number you want to ship. As soon as you reach full truck loads or full container loads that additional shipping cost is marginal on a board level.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#452
post #272

It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…

The more I understand software the less I trust it (given the current state of engineering practices). Meanwhile all my friends/family are scrambling to install all the latest new "smart home" gadgets and I just look like a paranoid kook trying to talk them out of it.

This. I've even had an in-law say, "My brother works for the Defense Intelligence Agency, and he uses smart devices in his home, so they must be safe!", with no consideration that tech may not be his specialty, or he doesn't follow the daily IoT fiascos, or maybe he just thinks he won't get hacked. Dunno. Meanwhile, my year-old thermostat still wants me to connect it to wi-fi, and that will never happen.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#453

Earlier quoted context omitted.

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

Wrong. PIN codes are entered into a damn mobile app and passed through an API. Billions of times per day. You guys are clearly missing the card serciving aspect of the industry.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#454
post #319

Anyone remember the hack of Apple via Supermicro firmware.... https://arstechnica.com/information-technology/2017/02/apple...

This is what Bloomberg's article refers to as "unrelated reasons" for Apple cutting ties with Supermicro in 2016.

> Three senior insiders at Apple say that in the summer of 2015, it, too, found malicious chips on Supermicro motherboards. Apple severed ties with Supermicro the following year, for what it described as unrelated reasons.

And then as an "unrelated and relatively minor security incident" later on.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#455

Earlier quoted context omitted.

Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…

There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…

>There were other considerations like the fact we were actually buying it from large reputable company and what happened was that some employees were doing it with no involvement of the company.

It's their responsibility to police for that. From the perspective of their business arrangement with you, it doesn't matter whether their left hand or right hand is evil; it's not your problem either way.

Is it really hard to find alternatives? Are they really cheaper than non-Chinese sources when you account for these inspection costs?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#456
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

What good is angular momentum when the producer can have fluctuations in its supply chain? Yes you can see when devices are not the same, but what if that happens all the time, legitimately?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#457

Earlier quoted context omitted.

Supermicro 6128 aka x10 series microblade. Those were very popular among Chinese DC operators during Broadwel era. https://www.itcreations.com/dist/landing/i/MBI-6128R-T2/MBI-... Left of the sata connector. An empty space with 8 pads for an smt eeprom or flash. It is occupied by the thingy on bugged boards. Right below is the Aspeed chip - the BMC

Is there a list of known compromised Supermicro SKUs?

No

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#458
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

> Sure it's cheaper

That's enough, full stop, say no more. The other costs are real yet they're either not marginal, are borne by others, or both.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#459

Earlier quoted context omitted.

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

You can totally fake your way through PCI audits. I know of a company that did it for years using a fake network and servers. Not sophisticated at all. Most auditors do not find all of the compliance violations. They have one person do it. It's all about money.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#460
post #175

Earlier quoted context omitted.

Add the USA to that list.

Are you saying companies should or that you know of companies that do?

One of the companies named in thr Bloomberg article does. They just deatroy your laptop if it was in the hands of customs without your supervision for any length. US customs explicitly included, which is kind of wierd if you ask me.
Post reply on HN