Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

721–730 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#721
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

> something as simple as an anti-tamper seal

To echo, it's actually quite trivial to bypass anti-tamper stickers with acetone and a needle.

https://www.youtube.com/watch?v=SqkMIek8sqI

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#722
post #175

Earlier quoted context omitted.

Are you saying companies should or that you know of companies that do?

One of the companies named in thr Bloomberg article does. They just deatroy your laptop if it was in the hands of customs without your supervision for any length. US customs explicitly included, which is kind of wierd if you ask me.

That’s perfectly expected. It’s not a stretch of the imagination to think border checks are abused for industrial espionage. If it gives your country a major advantge nothing is off limits these days.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#723

Earlier quoted context omitted.

I had never heard of this...but now I can only imagine how exciting this must have been as one of the engineers-- working on a top secret project for the CIA in an abandoned bowling alley: https://electricalstrategies.com/about/in-the-news/spies-in-... edit: whoops, looks like amatecha beat me to posting more info

Exciting, but not so ethical. We owe society to put our knowledge towards making it better for all people, not just "our team".

It's important though to make sure that your team keeps tactical advantage so that it can continue existing. Maybe someday mankind will find world peace but in our current world there are a lot of nations that hate each other still and wouldn't hesitate to take advantage of weaknesses of other nations for personal gain.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#724

Earlier quoted context omitted.

Last week Facebook was reasonably transparent about a hack affecting tens of millions of users.

This may be the first time in the history of the internet a statement from Facebook has ever been held up as an example of honesty and transparency from a corporation in America. The GDPR has already called out Facebook for lack of info in its response to the breach: https://www.cnbc.com/2018/10/02/facebooks-muddy-account-brea... Not sure why you'd pick that example.

Mostly because I believe that, while it's important to maintain healthy skepticism around privacy and security issues, I also believe that we don't benefit from cynical hyperbole.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#725
post #482
post #472

Earlier quoted context omitted.

The event was probably classified as a national security incident which would compel the affected parties to not disclose the event.

How does that actually work? How far down the chain of related facts to the national security incident are parties allowed/required to lie? If facts can be used to triangulate the secret, that can't be disclosed, right? Are incidents like this like a little fact-bomb which can be used to legally hide other institutional facts under its cover?

I assume it’s like national security letter. Only people in the company that has knowledge would be the ceo, general counsel, and people working directly to mitigate the issue. PR and corporate communication wouldn’t have any knowledge on the incident. I wonder how you collect insurance for these types of incidents if you can’t disclose them.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#727

Earlier quoted context omitted.

You trust anonymous sources, over a company that is willing to back their claims?

Of course. Apple/Amazon can be coerced into denying this (via government requests or otherwise). Bloomberg can't, nor is there any advantage for them to publish false information.

> nor is there any advantage for them to publish false information.

of course there is. It's called ad revenue and page views, both of which they're raking in today with these allegations. This story is all over the place. I don't trust Bloomberg with anything Apple at all and haven't for years now.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#728
post #496

Earlier quoted context omitted.

I know it's nice to blame China for everything... but it's not really the root of the problem here, supply chain management and control is.

China is 100% to blame here.

Absolutely.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#729

They attacked the Base Management Controller. There's an article by Bruce Schneier from 2013 warning about exactly this attack. Quoting: "Basically, it's a perfect spying platform. You can't control it. You can't patch it. It can completely control your computer's hardware and software. And its purpose is remote monitoring. At the very least, we need to be able to look into these devices and see what's running on the…

> You can't patch it.

Sure you can. OEMs regularly release patches for platform BMCs.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#730
post #213

Earlier quoted context omitted.

your comment looks like an pro-china propaganda. In china the state has heavy control on all the companies. The hardware is manufactured in china. I don't think something like this is happen without the state's knowledge.

It seems like many people take communist-like propaganda at face value. The Chinese government would like to have almost-complete control. The Chinese government publicly says it has high levels of control. But when they can't effectively regulate their medical (mass HIV infection from blood plasma needle reuse), food (tainted milk), or chemical (unlicensed mass CFC production) industries... reality seems to differ.

So, suppose you're Supermicro. When some CPC official comes around to tell you to make your technology a little easier for the intelligence department to access, you're going to do it.

Companies in China (especially those in the tech sector) have to keep close ties to the government, and most of their leaders are members are of the party. You don't GET to be a multi-billion dollar tech company* in China without toeing the party line [1] [2] [3]

The issues around regulating food safety and vaccines that you mentioned are irrelevant.

* Foreign companies must operate Chinese subsidiaries to run their operations in China.

[1] https://www.wsj.com/articles/beijing-pushes-for-a-direct-han...

[2] https://qz.com/1102948/chinas-communist-party-is-all-in-on-t...

[3] http://chinamediaproject.org/2018/05/02/tech-firms-tilt-towa...

Post reply on HN