Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

641–650 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#641

Earlier quoted context omitted.

>The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty Sounds like the solution is not doing business with them and pushing for a ban on others doing business with them (since this largely has a socialized cost when things go wrong, such as individual…

OMG, that is so so so so brilliant! I'm going to go tell my boss right now that the suppliers better suite up, otherwise we are going right to their more expensive, less experienced vendor and will delay our product launch for a year....and likely still suffer the same problem. Those Chinese vendors better shape up or we're going to really teach them a lesson by driving ourself out of business right quick!

Just imagine for a second if someone was advocating on HN for the use of a web framework that has knowingly allowed itself to be compromised to steal passwords because it was cheaper to use.

How about a compromise? If any of your customers are a victim of a crime because you continued to use a shady but cheap vendor after seeing them trying to slip past tampered hardware, your company is held fiscally and criminally responsible.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#642
If you scroll all the way to the bottom of the article you will find the disclaimer

Bloomberg LP has been a Supermicro customer. According to a Bloomberg LP spokesperson, the company has found no evidence to suggest that it has been affected by the hardware issues raised in the article.

Why did Bloomberg not buy a bunch of SuperMicros (new and used) and find the chip? That would be difficult but would turn this into a HUGE story. Even if they didn't have the technology to do so in-house, there are many companies they could hire to do a forensic investigation. The weakness of all bugging is that it has to communicate to the "outside world" at some point to be useful and that communications is discoverable. Even Stuxnet, which was much more narrowly targeted than this, was eventually discovered.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#643
post #135

Earlier quoted context omitted.

This is only really valid for protocols or products designed before the Morris worm of 1988. Anything designed beyond 2000 has no excuse for not thinking about internet security.

Well, IPMI isn't supposed to be exposed to the internet. Best practices have you running your BMC's on a completely separate, highly locked down administrative network.

Best practice would be for the BMC to not have access to the regular network ports when it has a dedicated network jack. All the ones I've looked at don't have any kind of physical interlock or switch, it's a software interlock.

Now even a hardware interlock could be subverted, but that's harder than sticking code in the bmc firmware, which does tend to get updated during the life of a server.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#644
post #441

Earlier quoted context omitted.

no way, an intentional design-level plant would have to pass through many eyeballs. a single mole wouldn't be enough.

I have worked in both chip design and security so I feel well qualified to make this assessment: a single mole in the right place who knew what they were doing would definitely be enough. Security holes get past design review all the time by accident . A skilled hacker could easily insert an intentionally obfuscated one that would escape detection.

Yup. And that single well placed mole could have 100 or 1,000 security experts working on their behalf. It is not as though the mole would have to design the hack, only pass necessary documents to a military grade hacking group then implement their modifications.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#645
post #642

If you scroll all the way to the bottom of the article you will find the disclaimer Bloomberg LP has been a Supermicro customer. According to a Bloomberg LP spokesperson, the company has found no evidence to suggest that it has been affected by the hardware issues raised in the article. Why did Bloomberg not buy a bunch of SuperMicros (new and used) and find the chip? That would be difficult but would turn this into…

It’s describing events from 2015. Presumably this issue has been resolved.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#647

We need open source hardware designs that can be built locally (where ever your local might be). This black box hardware crap has to stop. Smart people who know how all this works need to dump all their knowledge in to a design and a process. Trade secrets are keeping us not only limited in choices but exposed to bad actors who can control a link in the supply chain.

Won't that just get us NSA backdoors instead of PLA backdoors?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#648
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…

Honestly, to anyone bashing GP, look into your pockets, laptops, watches, cars, TVs, routers, CCs, singing toys, bitcoin mining ASICs. All with sealed black-box chips. Sure we can x-ray a couple of randomly stripped chips, but each one?

Now show me alternatives when most consumer grade electronic parts are fully or partially made in China.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#649
post #642

If you scroll all the way to the bottom of the article you will find the disclaimer Bloomberg LP has been a Supermicro customer. According to a Bloomberg LP spokesperson, the company has found no evidence to suggest that it has been affected by the hardware issues raised in the article. Why did Bloomberg not buy a bunch of SuperMicros (new and used) and find the chip? That would be difficult but would turn this into…

It’s describing events from 2015. Presumably this issue has been resolved.

There are tons of old SuperMicro computers on eBay for very reasonable prices. They could have bought lots of them of the appropriate vintage (2015 and prior).

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#650
post #572

Earlier quoted context omitted.

There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…

the indignation was not that. you are still missing the point. after the 1st device found, you should have contacted the manufacturer and said that you will start a department that has the capability of opening the device, inspecting and re-sealing in a way that it won't impact any guarantee the factory provides. If they denied this very sensible request, you had proof that it wasn't a isolated employee doing the hac…

Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's.
Post reply on HN