Earlier quoted context omitted.
Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…
This is also such a good anonymous story that I'd give decent odds it's made up.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
461–470 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#462Earlier quoted context omitted.
Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…
There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…
I fail to see how that has anything to do with it. The company is responsible for the product, full stop. If they can't stop their employees from tampering with the product, that's entirely their fault.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#463Earlier quoted context omitted.
Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…
There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…
Again, I don't see why that matters. I understand the latter part, but if this is one employee without the knowledge of the company, then pushing it on them forces them to add checks, not you.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#464Earlier quoted context omitted.
Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…
There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…
Two thoughts:
> they typically will not be thinking they are doing anything wrong. They are just testing if you notice and if you do not they will say it makes no difference for you but saves them costs.
This is how children behave. Still feels like you’re rewarding bad behavior. You’re enabling them.
I think it’s more that you’ve valued the low per unit price over having a healthy contract. Your vendor is incentivized to make all of their money off of externalities and your company think it’s cheaper to outwit them than to demand QC on their end. Whose brand will be sullied if you miss some of these units and a customer finds the spyware? Not theirs.
And second thought, shouldn’t serial numbers be coming off the line in ascending order? The kind of work they are doing would require taking parts off the line and putting them back later so odd lots of SNs are the ones you need to verify.
You could also be mandating how many boards are allowed or that the SNs go on early in the build process.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#465I am sincerly impressed by the amount of supply chain analysis and operative supply chain management that went into that hack. And once the Chinese identified a distribution node in that particular supply chain, supermicro, they opted for a brute force attack by seeding these backdoor chips into supermicros servers and wating where they ended up. That was one hell of a hack. It also gives you pause. Did that happen o…
Im impressed as well. But I'm sure its not as impressive as what the NSA is capable of. If you're reading an article about this - its because the US government wants you to know about it. The US has been doing this kind of stuff well before the Chinese or anyone else... And yes, totally agree that this is probably fairly common place. Some comments have shown that this happens with run-of-the-mill hardware like credi…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#466Earlier quoted context omitted.
you would be extremely hard pressed to fit that amount of logic (and code) into that small of a package. and to operate intelligently, as you suggest, it needs a CPU clock, not available to it from where it would sit. And it would need to do signal analysis in real time, with no power and no clock. it's not possible.
Clockless CPUs exist.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#467I am sincerly impressed by the amount of supply chain analysis and operative supply chain management that went into that hack. And once the Chinese identified a distribution node in that particular supply chain, supermicro, they opted for a brute force attack by seeding these backdoor chips into supermicros servers and wating where they ended up. That was one hell of a hack. It also gives you pause. Did that happen o…
if they really are widely seeded (and it’s general knowledge/easily assumed that the pla leans on other manufacturers), this gives me a few ideas about what could happen in the event of conflict between china and the US. turnkey shutdown of the entire economy.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#468Earlier quoted context omitted.
An update on that theory: AST2400 has option for two SPI memories, one main, one "recovery." https://download.csdn.net/download/duanzhang512/10385038 The recovery overrides the primary if detected by default. The place they put their "filter cap" is right on top the empty TSOP8 pad for the recovery flash. And they probably ordered the factory to sneak the traces just a little bit more, or put hidden vias under it, or…
This is the most plausible theory I've read in this thread. Assuming the image in the article is a stock image (there isn't yet a clear image of a definitely compromised board), then the added part could simply be another TSOP8 Flash part. This implies the firmware to the AST2400 is unsigned (which it appears to be, as there's coreboot options for it). That makes the whole thing gloriously simple. A part "stuck on" a…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#469Earlier quoted context omitted.
Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…
This is also such a good anonymous story that I'd give decent odds it's made up.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#470Earlier quoted context omitted.
You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…
Do you honestly think any of that is not something a nation state actor could pull off though?