Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

511–520 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#511
The logical extension of this is to embed a sleeper chip between board layers that can be activated by a radio signal, then try to disperse it widely within the DND.

Any serious conflict with China would then look like the first day of the second Cylon war...

Of course, they would probably have to get a Chinese boat really close to a US warship a few times beforehand to test the system. All they would need to do is to receive some sort of a ping back to confirm receipt of the signal. Could be simple as an innocuous visit to a particular page of a website.

It would probably look like brinksmanship or posturing, or a navigation error of some sort.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#513

Earlier quoted context omitted.

That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…

You can totally fake your way through PCI audits. I know of a company that did it for years using a fake network and servers. Not sophisticated at all. Most auditors do not find all of the compliance violations. They have one person do it. It's all about money.

You can fake a lot of things so what? That’s not the point, also PCI DSS is pretty crappy but the hardware vendor, payment provider and P2PEE certifications are a completely different story good luck faking it.

Sure you can send fake devices to be certified and sell something completely different but the same can be said for any certification and if you get caught boy or boy...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#514
post #296

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

>Each time, we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them. An uncharitable reading, but this statement does not exclude the possibility of investigations by 3rd parties hired by Apple.

Neither does it exclude the possibility of internal investigations of which Apple's press office is unaware. If Tim Cook simply said this never happened I'd believe him. This elaborate denial suggests otherwise.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#515
post #496

Earlier quoted context omitted.

Maybe time to buy your financial hardware from somewhere not china?

I know it's nice to blame China for everything... but it's not really the root of the problem here, supply chain management and control is.

China is 100% to blame here.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#516

Doesn't the printed circuit board also need to be redesigned, to allow for the spy chip to be inserted? So, this means that China forced multiple companies to modify their processes, in order to pull this off. 1. The PCB designer 2. The PCB printer, if it's a separate company 3. The company assembling the final product And if they forced the PCB to be redesigned, then wouldn't this be a immediate red flag? But this m…

They wouldn't need the PCB designer. They would need to suborn (employees of) the PCB manufacturer and the assembly house. These will be supplied with the PCB layout (in Gerber or ODB format, for making the PCB) and the bill of materials and pick and place file (for assembling it). With these files you can reverse engineer the schematic and carry out the modifications described. The PCB manufacturer might well be a sub-contractor to the assembly house.

Most electronic engineers don't have the software tools for or experience of sophisticated reverse engineering but there aren't any major conceptual barriers. They would have to go from the geometry of the tracks and pads to a connectivity graph (very automateable), then collect the pads into footprints for components (probably partly automated), then identify those components and the functions of their pins (easy with a complete BOM) and then workout the circuit function (should be straightforward for standard parts and circuits).

There might not be automated tools for making the desired changes, in which case they will have to manually draw the new track geometry on the Gerbers, add the parts to the BOM and pick and place files and change or nobble the test criteria / files. Hard work but quite straightforward.

These skills will be developed by people doing legitimate industrial reverse engineering as well as espionage / intelligence. I would think there are also unfortunate cases where firms have to reverse engineer their own products after losing the original files.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#518

Earlier quoted context omitted.

There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…

All employee actions are company actions. You partnered with a company that can’t control what it’s employees do? No internal audits to make sure their reputation wasn’t being tarnished by a few employees?! Your loss.

I understand the indignation etc etc. And the suggestion to not use these kind of companies anymore.

And that sounds really reasonable, until you realize that pretty much all contract manufacturers in the Far East will source cheaper or off-spec components than those on the BOM if they can get away with it.

One of my friends supplied small widgets for a well known consumer electronics maker. He routinely gets widgets returned to him as defect for inspection, which then inevitably turn out to be clones of his widgets.

The only way to make sure that your product rolls of the product line as expected, is to have people on-site with continuous inspection (and pray that they're not the cousin of somebody who's on the other side.)

If you want the benefit of dirt cheap manufacturing, you need to have a system in place to deal with these practices.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#519
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

For the folks commenting below that we should bring the manufacturing back to the US, why wouldn't the bad guys just start bribing American workers to insert the attack hardware into devices made here? It's not like Americans are somehow above being bribed.

Ignoring the abject amorality and greed that underpins Chinese culture will leave one confused like this.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#520

Earlier quoted context omitted.

This is also such a good anonymous story that I'd give decent odds it's made up.

Using the technically incorrect term "angular momentum" rather than the more correct term "moment of inertia" made me think the same thing. I would think a person tasked with building such a device would know their physics well enough to use the right term, but I may be wrong.

Maybe he is afraid of giving too much info away. By mentioning it, now the opposing side will be measuring angular momentum.

So now he needs to make a new test. Ow that that is out of the bag

Post reply on HN