Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

631–640 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#631

Earlier quoted context omitted.

Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another? The moment the option of taking control of a production line of som…

Not all societies are equally corrupt.

But no societies are free from organized crime. And last time I checked, no western country was free from card skimmers either.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#632

Earlier quoted context omitted.

There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…

>The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty Sounds like the solution is not doing business with them and pushing for a ban on others doing business with them (since this largely has a socialized cost when things go wrong, such as individual…

I used to work on the server-side stuff for telecom devices. We designed hardware that went into customer homes, but only downloaded the (encrypted) firmware upon home activation as otherwise the Chinese manufacturers would have ripped us off and sold them to telecom companies without our cut.

So, realising they could copy our hardware, but didn't have our software, they responded by trying to hack my servers, multiple times, from the same IP they sent manufacturing data from. A quiet word with their management would stop it, and it'd start again a couple of days later.

These people have no shame, and if we are going to go for lowest cost at all times it is what manufacturers should expect to happen.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#633
post #518

Earlier quoted context omitted.

All employee actions are company actions. You partnered with a company that can’t control what it’s employees do? No internal audits to make sure their reputation wasn’t being tarnished by a few employees?! Your loss.

I understand the indignation etc etc. And the suggestion to not use these kind of companies anymore. And that sounds really reasonable, until you realize that pretty much all contract manufacturers in the Far East will source cheaper or off-spec components than those on the BOM if they can get away with it. One of my friends supplied small widgets for a well known consumer electronics maker. He routinely gets widgets…

> I understand the indignation

IMO this is not indignation, it's supplier sourcing 101.

> If you want the benefit of dirt cheap manufacturing, you need to have a system in place to deal with these practices.

I will definitely agree that holding suppliers to standards regarding consistent output, unadulterated products, and conducting audits all make production much more expensive.

But if you're a device manufacturer, these sourcing controls are key to shipping quality products.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#634
post #135

Earlier quoted context omitted.

This is only really valid for protocols or products designed before the Morris worm of 1988. Anything designed beyond 2000 has no excuse for not thinking about internet security.

Well, IPMI isn't supposed to be exposed to the internet. Best practices have you running your BMC's on a completely separate, highly locked down administrative network.

Well yes, typically you'd 1) configure IPMI to use the dedicated port, 2) put those ports into a VLAN with no outgoing internet access. But since this is BMC, what's stopping it from just using your management or production port to fire off its secret phone-homes and whatnot?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#635

Earlier quoted context omitted.

Yeah, I mean that's what I would say too if some government intelligence agency told me I cannot say a word about this and have to deny it vehemently! haha :)

There's definitely something afoot. Bloomberg probably wouldn't have gone forward with just an in-depth piece referencing so many major tech companies unless it had substance. But generally even when legally compelled, companies tend to prefer silence or curt denials over lengthy detailed contrary pieces. Is there a federal investigation going on into some sort of sabotage by the Chinese government? Possibly, and if…

I think it is a win-win for Apple and Amazon to spin it this way. They get to deny that they were compromised, and if that gets disproved they can easily say they were cooperating with national security operations and get away without any damage.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#637

Earlier quoted context omitted.

Altering components to something cheaper is common practice for every company that is willing to exploit the fuck out of their customers. Look at the food industry. In EU there is control, in US thare are sanctions. But it is up to the governments because companies are to opportunistic to change. As long you can (re)sell the junk you get, you're fine, if you can't you upgrade "QA".

Both the EU and US have internal controls on food quality and sanctions. Contrary to the impression your post gives, the EU has much more "sanctions" against food (esp. imports) than the US does, and is generally taxing much heavier and restricting many more things. Importing essentially any milk product into the EU is only possible on an exception basis. Trump has a LOT more work before extra sanctions in the US wil…

and no kinder surprise in the us.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#638
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Thanks for sharing this story, and I hope you aren't put off by the huge thread of people second-guessing your competence. We need more of your kind of story.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#639

Earlier quoted context omitted.

Altering components to something cheaper is common practice for every company that is willing to exploit the fuck out of their customers. Look at the food industry. In EU there is control, in US thare are sanctions. But it is up to the governments because companies are to opportunistic to change. As long you can (re)sell the junk you get, you're fine, if you can't you upgrade "QA".

Both the EU and US have internal controls on food quality and sanctions. Contrary to the impression your post gives, the EU has much more "sanctions" against food (esp. imports) than the US does, and is generally taxing much heavier and restricting many more things. Importing essentially any milk product into the EU is only possible on an exception basis. Trump has a LOT more work before extra sanctions in the US wil…

Champagne is literally the name of the area where the product comes from. It makes perfect sense that anything that doesn't come from the region Champagne, isn't champagne... Call it sparkling wine, it's fine, but not champagne. And it applies to most local products. Camembert? Comes from a specific town, which is called Camembert. Beaujolais? The name of the province. And the list goes on. It doesn't sound "absolutely ridiculous" to me.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#640

Earlier quoted context omitted.

OpenBMC (Facebook, Google, Microsoft, Intel, IBM and others) is working on open-source baseboard management software, https://www.linuxfoundation.org/blog/2018/03/openbmc-project... > The organizations behind the new project each have already made substantial contributions to creating open source baseboard management controller (BMC) firmware. Now, working together, they will define the vision for a standard stack th…

Wouldn't help. The BMC hardware has direct serial access to CPUs and other hardware in the machine. Communication is unencrypted. A hardware modification attack wouldn't touch the firmware at all and could still compromise IPMI functionality.

Reducing the attack surface does help -- you're making perfection the enemy of the "somewhat better".
Post reply on HN