Earlier quoted context omitted.
Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…
Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another? The moment the option of taking control of a production line of som…
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
711–720 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#712Earlier quoted context omitted.
That is also in the article... "17 people confirmed the manipulation of Supermicro’s hardware and other elements of the attacks. The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."
So not a single source. Might as well be going to war over invisible weapons of mass destruction. Also, Apple and Amazon both has said they do not agree with these claims. So far this is nothing more than propaganda.
That’s an interesting choice.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#713Earlier quoted context omitted.
How do you know that the DoD/CIA isn't behind this?
Because it came from Chinese manufacturers. Did you read the article?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#714Earlier quoted context omitted.
Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)
Certification [...] I can tell you - it's no joke :) I'm not so sure. "And then initial supplier inserted hardware that thwarted all those pressing considerations" sounds a punchline to me. :(.
The safeties are mainly to guard against the rest of the world. For example it prevents tampering in transit, or even in our own company - disgruntled employee can't do anything.
Or think for a second about the fact that we leave the device for, hopefully, entirety if its life at the client site. We had clients that were shady businesses like strip clubs that no other companies would touch with a stick.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#715Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#716Earlier quoted context omitted.
To be clear, this is only for the ability to update the BIOS over the BMC interface, not for BIOS updates in general. (unlike some other vendors, where you need a support contract to be even able to download the updates) At least on some boards you can boot the USB drive image containing the BIOS updater through the BMC and do a remote update that way.
Supermicro doesn't publish changelogs for their BIOSes. Their disclaimer on their BIOS download page says, "don't update the BIOS unless you have to". It's a ridiculous stance for a server company. You buy Supermicro over Dell for the price. That's pretty much it.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#717Earlier quoted context omitted.
Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)
> I can tell you - it's no joke :) But still as a user I have no idea if I'm talking to a certified machine or not.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#718Earlier quoted context omitted.
> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…
You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#719Amazon are going all out on the denial https://aws.amazon.com/blogs/security/setting-the-record-str...
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#720Earlier quoted context omitted.
Procedures change, as attacks get more sophisticated the next step could be disposable devices. But an attack like the one described in this article won't be mitigated by having a disposable device. On the other hand having your laptop "hijacked" while on a business trip will most likely involve some extra PCB or components that are a little more obvious that something that's "built in". Then again many companies or…
Does the security team have any motivation to reduce waste? Unless you're finding hacks in your devices already I see no reason to think they aren't just making you jump through hoops because it's funny.