Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

481–490 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#481

Earlier quoted context omitted.

Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…

There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…

All employee actions are company actions. You partnered with a company that can’t control what it’s employees do? No internal audits to make sure their reputation wasn’t being tarnished by a few employees?! Your loss.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#482
post #472

Earlier quoted context omitted.

What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

The event was probably classified as a national security incident which would compel the affected parties to not disclose the event.

How does that actually work? How far down the chain of related facts to the national security incident are parties allowed/required to lie? If facts can be used to triangulate the secret, that can't be disclosed, right? Are incidents like this like a little fact-bomb which can be used to legally hide other institutional facts under its cover?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#483
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

So you had hard evidence that your manufacturer was vandalising your property? Couldn't you drop them?

The main lesson I learned from my Dad’s employer (twice) was always have two vendors. You can play them off of each other. When I did contract work I saw how powerful getting out or putting for away the checkbook can be. Large vendors ignore you if the checkbook isn’t moving.

I say “twice” because they were also the biggest employer in town. I got out of there. Slim pickins for career opportunities that didn’t revolve around BigCo.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#484
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

You're conflating a few things there. Whilst companies like to make noises occasionally about saving the planet, doing the right thing, making (your country goes here) great etc, it's just horseshit. They exist to make money. That's it.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#486

Earlier quoted context omitted.

There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…

This still sounds nuts to me. Two thoughts: > they typically will not be thinking they are doing anything wrong. They are just testing if you notice and if you do not they will say it makes no difference for you but saves them costs. This is how children behave. Still feels like you’re rewarding bad behavior. You’re enabling them. I think it’s more that you’ve valued the low per unit price over having a healthy contr…

You're starting to realize that not all cultures are that great.

>I think it’s more that you’ve valued the low per unit price over having a healthy contract.

Well, when the choice is to either play ball or go out of business, it's not a tough decision.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#487

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

They have to deny it. If the allegation is true, it means the Chinese CCP Gov knows which computer parts are produced specially for US gov or certain big companies and target precisely. There has to be some deep link for information flow to allow that. Anyway, worth further digging.

That seems plausible, given what we know about Amazon employees with ties to China disclosing private sales info or changing reviews in exchange for cash bribes. https://abcnews.go.com/Business/amazon-probes-report-workers...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#488

Earlier quoted context omitted.

What about Japan? I know they've lost most of their semiconductor business as well, but they still have some capacity no?

I’m under the impression that China does not make chips, but they do final assembly cheaper and faster than everyone else. I don’t know if any companies do PCB manufacturing and assembly outside of China in large numbers.

That is true I think because of what happened to ZTE earlier this year.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#489
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

For the folks commenting below that we should bring the manufacturing back to the US, why wouldn't the bad guys just start bribing American workers to insert the attack hardware into devices made here? It's not like Americans are somehow above being bribed.

It's possible, but it's much, much, much easier for an American company to hold another American company accountable when something like this happens. Instead of having to go through all those hoops, you sue the pants off the manufacturer.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#490

Earlier quoted context omitted.

OpenBMC (Facebook, Google, Microsoft, Intel, IBM and others) is working on open-source baseboard management software, https://www.linuxfoundation.org/blog/2018/03/openbmc-project... > The organizations behind the new project each have already made substantial contributions to creating open source baseboard management controller (BMC) firmware. Now, working together, they will define the vision for a standard stack th…

Wouldn't help. The BMC hardware has direct serial access to CPUs and other hardware in the machine. Communication is unencrypted. A hardware modification attack wouldn't touch the firmware at all and could still compromise IPMI functionality.

[deleted]
Post reply on HN