Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

691–700 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#691
post #650
post #572

Earlier quoted context omitted.

the indignation was not that. you are still missing the point. after the 1st device found, you should have contacted the manufacturer and said that you will start a department that has the capability of opening the device, inspecting and re-sealing in a way that it won't impact any guarantee the factory provides. If they denied this very sensible request, you had proof that it wasn't a isolated employee doing the hac…

Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's.

> Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's.

I think that's the case. The EEV Blog guy did a teardown of and old one once and pointed out the numerous tamper-detection features that would clear the device if opened.

However, if I were the customer here, I'd tell the supplier that from that point forward they need to supply me free extra product with my orders, so I can do my own random destructive testing to look for implants. I order 100, they send me 105 for the price of 100.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#693

Earlier quoted context omitted.

Frankly, I trust Bloomberg more than Amazon and Apple's PR departments combined.

You trust anonymous sources, over a company that is willing to back their claims?

However Apple or Amazon didn't back up their claims. If Bloomberg published an article of this magnitude which could be demonstrably disproved, it'd kill Newsweek's reputation.

More importantly, think of what would be Bloomberg's reasons to publish a false story versus Amazon and Apple's reason to deny a true story.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#694

This reminds me of that old story about the Xerox copy machines that the Soviet Union bought. Where each unit was planted with a image recorder. And for years, the American spy agencies had a great laugh, that they were able to intercept all the documents that the Russians made a copy of. Back then, this was an off-network infiltration. Where the copied images, were retrieved during regular servicing intervals by a X…

I was born raised, and went to CS undergrad program in China before come to US. Yes. I can testify that the "Xerox Copy Machine" is the first thing they teach you about information security :p

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#695
post #566

Earlier quoted context omitted.

How much do you think you would have to pay them to make it worth their while to not use cheap components (so as not to risk losing you as a customer)? It’s amazing how people never consider using economics. Edit: But let’s not get away from the matter at hand. The issue wasn’t cheap components, it was full-on credit skimmers installed in yor hardware (IIRC). Should be easier to incentivize the conpany into halting t…

As somebody else noted: it doesn't have to be the company that does it, but a lower level employee who cuts a deal. So paying the company more wouldn't solve the issue completely. All of these things are extremely cost sensitive. Your suggestion that people don't consider using economics is simply wrong. If you can manufacture a million pieces for a few cent less per piece, and the only negative is having to paying a…

> All of these things are extremely cost sensitive.

Say their profit margin is 1%. If you offer to pay them a 1% higher price, you're offering to nearly double their profits on whatever they sell to you.

Admittedly, that only works if you are a sufficiently large portion of their business. If you're a tiny percentage, then it may take a lot more to motivate them if their other customers aren't willing to pay more.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#696

Earlier quoted context omitted.

Maybe you and me are missing something here. It seems crazy that somebody would go to these lengths without switching suppliers, there must be an underlying reason that is assumed to be understood by the informed reader. (But isn't understood by me and you it seems.)

A good read is 'Poorly Made in China'. The product is different, but the problems are the same. * They drop changes and problems at the last minute, so you're over a barrel with your customers. * Relationships take months, maybe years to build. Switching suppliers is a long and costly exercise. * Often suppliers themselves are in communication, so your attempt to build a new relationship is scuppered by your current…

> * Are you going to admit to your customers and bosses that your products were faulty and you knew?

If you can't answer that with a yes, maybe you don't have the backbone to work in anything critical.

When you discover a fault in something, particularly a fault that might hurt someone, you have a moral obligation to speak up. To do otherwise is cowardice.

Failure to speak up when we see shit is how stuff like the VW emissions gate happen, and also why security professionals can make a career out of ferreting out your mistakes and engaging in responsible disclosure.

All this tells me is that Made in the USA is more valuable than I once believed.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#697

Earlier quoted context omitted.

Probably it just goes through as a card not present (CNP) transaction?

So you mean it first authenticates the pin, and initiates CNP after? Never thought of that as possible.

It's not CNP doesn't use the pin it uses the CVV2, you also can't use the chip and pin or track 2 swipe data for a CNP transaction.

I think the GP is confused on how a POS works, POS isn't a POI most of them don't touch the credit card they just talk to the reader, most readers today are P2PE closed loop solutions so the only thing the POS does is sends to the reader charge the next card $X the reader will then reply if the transaction went through or not and that's it.

The reader itself will talk to the acquiring bank or the payment provider in a point to point encrypted closed loop and the merchant would never see any credit card details.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#698
post #518

Earlier quoted context omitted.

I understand the indignation etc etc. And the suggestion to not use these kind of companies anymore. And that sounds really reasonable, until you realize that pretty much all contract manufacturers in the Far East will source cheaper or off-spec components than those on the BOM if they can get away with it. One of my friends supplied small widgets for a well known consumer electronics maker. He routinely gets widgets…

How much do you think you would have to pay them to make it worth their while to not use cheap components (so as not to risk losing you as a customer)? It’s amazing how people never consider using economics. Edit: But let’s not get away from the matter at hand. The issue wasn’t cheap components, it was full-on credit skimmers installed in yor hardware (IIRC). Should be easier to incentivize the conpany into halting t…

You have to pay them as much as it would cost to manufacture in the Western country doing the out-sourcing...so unless the cost of these extra quality checks outweighs the cost of on-shoring you might as well measure angular momentum.

Madness if you ask me but there we are.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#699
post #649

Earlier quoted context omitted.

It’s describing events from 2015. Presumably this issue has been resolved.

There are tons of old SuperMicro computers on eBay for very reasonable prices. They could have bought lots of them of the appropriate vintage (2015 and prior).

> There are tons of old SuperMicro computers on eBay for very reasonable prices. They could have bought lots of them of the appropriate vintage (2015 and prior).

I think buying a bunch of old servers and looking in them for implants is so far outside Bloomberg News' core competencies that it's unsurprising they didn't do it.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#700
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

This feels cargo cultish. Products drop from the sky. One day they become poisonous. You have no idea how to reproduce them locally. So you come up with hacks to make then less dangerous. We really need to get back into manufacturing if this is our brave new world.

The better question is how did we stop manufacturing.
Post reply on HN