Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

701–710 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#701
post #238

Earlier quoted context omitted.

PED/PTS devices have even stricter guidelines than contactless payments.

But this device doesn't need a way for the user to enter the pincode. So, all the sensitive part of the terminal is probably completely isolated from the android part. I don't know this device internal and the PED/PTS exact requirement but it seems plausible for me. You have something like a physical compartment who include the NFC and everything needed to process it like in a classical terminal. This compartment is…

Yes this is a common design in fact most current solution segregated the POS and POI completely anything that handles the actual credit card whether it's C&P, Track2 or NFC is a closed black box with the required PED/PTS/POI and P2PE certifications the merchant never sees what's going on they only can talk to the thing in bill the next card X and get a confirmation of the transaction that's it they don't see any of the card data they don't even see any card holder data unless they collect it in a side channel e.g. a loyalty program.

Now none of these certifications or standards is bullet proof but people have a very skewed vision of the PCI certification process likely due to bias of only having interacting with the PCI-DSS requirements for merchants and low levels to boot meaning they didn't had to do anything but to fill the SAQ themselves and be on their way.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#702

We need to get the fuck out of China. It is becoming less credible to throw our hands up and say "China has all the silicon manufacturing, guess we have to put up with it!" - this is national security, both directly via hardware in the DoD and through our economic stability. Saying "Well the Chinese companies are different" or "It's just rogue employees" or "We just have to accept it" is not good enough. We need a li…

How do you know that the DoD/CIA isn't behind this?

What evidence do you have to suggest that?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#703

Earlier quoted context omitted.

Frankly, I trust Bloomberg more than Amazon and Apple's PR departments combined.

You trust anonymous sources, over a company that is willing to back their claims?

Of course. Apple/Amazon can be coerced into denying this (via government requests or otherwise). Bloomberg can't, nor is there any advantage for them to publish false information.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#704
As something I heard: In China, business a fight for survival that is brutal to the extreme. You will be cut down, cheated, extorted, and broken with zero hesitation.

Doing business in the West is comparatively like a walk in the park.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#705
post #367

Earlier quoted context omitted.

Canadian steel is considered by this administration to be a national security risk. But Chinese made boards and chips installed in weapons systems and crucial data centers? No problem. Let that sink in for a moment. https://www.wsj.com/articles/dont-trust-the-chinese-to-make-...

The thing being called a national security risk is a lack of domestic production capability. No one is saying Canadian steel is sabotaged or something.

But they are saying that Canada would cut us off from their steel production in a time of need, which is a pretty absurd assessment of the situation.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#706
Do we know how this attack actually worked? From TFA it seems to involve the BMC (which afaik everyone already assumed was untrustable), and also involved the capability to "phone home" (also notable since in security-conscious deployments the BMC NIC would never be allowed public Internet connectivity).

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#707

Earlier quoted context omitted.

> You're starting to realize that not all cultures are that great. That's sounding pretty racist

Conflating culture with race is ... racist. Not all cultures are great. If you are claiming “all cultures are great”, then perhaps “great” has lost any useful meaning. Discrimination, as the ability to discriminate features to identify useful pattens, is not *-ist; it’s a critical skill that is being sullied by some neo-intellectual BS that passes for “equality” or something. The ability to identify patterns of behav…

Give one example of a non-ethnic Chinese person who is considered to be culturally Chinese.

It's the norm in the west to not conflate culture with race. But to think that this is the norm in the rest of the world is to project your value system on others.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#708
post #135

Earlier quoted context omitted.

This is only really valid for protocols or products designed before the Morris worm of 1988. Anything designed beyond 2000 has no excuse for not thinking about internet security.

Well, IPMI isn't supposed to be exposed to the internet. Best practices have you running your BMC's on a completely separate, highly locked down administrative network.

I did a security audit on a company that had a setup similar to this.

After popping an internet facing web server, I was able to compromise the IPMI system and use the management network to bounce around to any server in the enterprise completely bypassing all the firewalls and segmentation on the production network.

Management networks need rack level isolation.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#709

Earlier quoted context omitted.

A good read is 'Poorly Made in China'. The product is different, but the problems are the same. * They drop changes and problems at the last minute, so you're over a barrel with your customers. * Relationships take months, maybe years to build. Switching suppliers is a long and costly exercise. * Often suppliers themselves are in communication, so your attempt to build a new relationship is scuppered by your current…

> * Are you going to admit to your customers and bosses that your products were faulty and you knew? If you can't answer that with a yes, maybe you don't have the backbone to work in anything critical. When you discover a fault in something, particularly a fault that might hurt someone, you have a moral obligation to speak up. To do otherwise is cowardice. Failure to speak up when we see shit is how stuff like the VW…

Not having the backbone to reveal it when you discover a fault is not what that comment was getting at
Post reply on HN