Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

501–510 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#501

Earlier quoted context omitted.

Might make a difference if those pennies can't be tracked back to the government.

Yup. This would be the modern equivalent of Air America and other schemes by the CIA to raise money to operate by involving themselves in illegal activity like the drug trade.

One would consider those activities to have taken place in "modern" times as well...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#502
post #482
post #472

Earlier quoted context omitted.

The event was probably classified as a national security incident which would compel the affected parties to not disclose the event.

How does that actually work? How far down the chain of related facts to the national security incident are parties allowed/required to lie? If facts can be used to triangulate the secret, that can't be disclosed, right? Are incidents like this like a little fact-bomb which can be used to legally hide other institutional facts under its cover?

There most likely are classified legal constructs that compel speech. You see that with the PRISM denials by Apple and Google.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#503

Earlier quoted context omitted.

I think the point is that actual honesty from these megacorps would be so surprising that even raising the possibility of it happening is so absurd it feels like parody writing.

Last week Facebook was reasonably transparent about a hack affecting tens of millions of users.

This may be the first time in the history of the internet a statement from Facebook has ever been held up as an example of honesty and transparency from a corporation in America.

The GDPR has already called out Facebook for lack of info in its response to the breach: https://www.cnbc.com/2018/10/02/facebooks-muddy-account-brea...

Not sure why you'd pick that example.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#504
post #203

Earlier quoted context omitted.

There is no way that the intelligence community would allow that fraud case to go ahead.

That assumes that 1) the intelligence community has the power to stop it and 2) that Apple believes this to be the case and 3) that Apple is confident that the intel community would use that power to protect them. That seems like a reach to me.

I think it's extremely foolish to think that the SEC would have the ability to overrule the CIA/NSA/other TLA when it comes to disclosure of this.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#506
post #256

Earlier quoted context omitted.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

Second this, after having to go through a service level 1 DSS review for a few years. Lower level reviews (3,etc) just require self validation.

SAQs don’t involve QSAs. They are also intended for merchants which are a rounding error also there is no SAQ for PA, PED, PTS etc. certifications only for merchant PCI-DSS.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#507
post #495

Earlier quoted context omitted.

Apple is very strongly denying it as well https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

Never believe anything until it has been officially denied.

These are such detailed denials that it's hard to believe the companies are lying.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#508

Earlier quoted context omitted.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

Wrong. PIN codes are entered into a damn mobile app and passed through an API. Billions of times per day. You guys are clearly missing the card serciving aspect of the industry.

Please show me the device that transmits the pin of a chip and pin card to an API while not being compatible with PED and P2PEE requirements.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#509
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…

Probably the cost per unit is too attractive

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#510

Earlier quoted context omitted.

I love a good Trump bashing moment as much as the next guy, but this is inaccurate. The DoD has stringent requirements and quality control procedures in place for their chip procurement. Not to say they couldn't be improved, but the DoD has been aware of this threat for a while, and seems to be mitigating the risk fairly well.

Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes. http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied... The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.

Even if true, how does that make it a national security risk?
Post reply on HN