Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

731–740 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#731

Earlier quoted context omitted.

OpenBMC (Facebook, Google, Microsoft, Intel, IBM and others) is working on open-source baseboard management software, https://www.linuxfoundation.org/blog/2018/03/openbmc-project... > The organizations behind the new project each have already made substantial contributions to creating open source baseboard management controller (BMC) firmware. Now, working together, they will define the vision for a standard stack th…

Wouldn't help. The BMC hardware has direct serial access to CPUs and other hardware in the machine. Communication is unencrypted. A hardware modification attack wouldn't touch the firmware at all and could still compromise IPMI functionality.

Even now, supply chain hardware modification attacks remind people of fiction. However, the number of people known to be affected by buggy BMC firmware is orders of magnitude larger, as described two comments upthread:

> The system is basically designed to be as insecure as possible by default, and allow for the maximum possible persistent threats with BIOS flashing, IPMI flashing, and other completely un-authenticated avenues exposed.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#732

Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…

Not the chip itself but there's an investigation which I've already submitted:

https://news.ycombinator.com/item?id=18144519

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#733
post #723

Earlier quoted context omitted.

Exciting, but not so ethical. We owe society to put our knowledge towards making it better for all people, not just "our team".

It's important though to make sure that your team keeps tactical advantage so that it can continue existing. Maybe someday mankind will find world peace but in our current world there are a lot of nations that hate each other still and wouldn't hesitate to take advantage of weaknesses of other nations for personal gain.

If our team is resorting to unethical and immoral ways to gain that advantage, then we can't take the moral high ground and also can't complain when the other team also does "whatever it takes" to gain an advantage.

Also, security through obscurity is, as we know, an illusion. Information always finds a way out.

I understand your point, but there should be limits.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#734
post #422

Earlier quoted context omitted.

It does. I've deployed systems that would not only notify staff when novel packets were observed but immediately isolate anomalous hardware through a combination of powerdown and network fabric reconfiguration.

The amount of false positives a system like that would generate would rapidly render such a system entirely unusable.

Not in a secure environment... where you are supposed to control the hardware, the software, and the network absolutely.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#735

We need to get the fuck out of China. It is becoming less credible to throw our hands up and say "China has all the silicon manufacturing, guess we have to put up with it!" - this is national security, both directly via hardware in the DoD and through our economic stability. Saying "Well the Chinese companies are different" or "It's just rogue employees" or "We just have to accept it" is not good enough. We need a li…

> It is becoming less credible to throw our hands up and say "China has all the silicon manufacturing, guess we have to put up with it!"

The thing is, China doesn't. Most expensive chips are fabricated outside of China in nearby countries and shipped there for final assembly.

What goes on in China is usually human assembly. And that's what seems to have happened here -- in the process of putting chips on motherboards, someone added some bonus chips. It seems like it would be hard to do that without dedicated traces / solder points.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#736

Earlier quoted context omitted.

That is also in the article... "17 people confirmed the manipulation of Supermicro’s hardware and other elements of the attacks. The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."

So not a single source. Might as well be going to war over invisible weapons of mass destruction. Also, Apple and Amazon both has said they do not agree with these claims. So far this is nothing more than propaganda.

Are you saying Bloomberg made the sources up, or that they exist but are all lying, because they won't go on the record?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#737

They attacked the Base Management Controller. There's an article by Bruce Schneier from 2013 warning about exactly this attack. Quoting: "Basically, it's a perfect spying platform. You can't control it. You can't patch it. It can completely control your computer's hardware and software. And its purpose is remote monitoring. At the very least, we need to be able to look into these devices and see what's running on the…

> You can't patch it. Sure you can. OEMs regularly release patches for platform BMCs.

Not sure about you, but I'm not an "OEM".

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#738
post #723

Earlier quoted context omitted.

It's important though to make sure that your team keeps tactical advantage so that it can continue existing. Maybe someday mankind will find world peace but in our current world there are a lot of nations that hate each other still and wouldn't hesitate to take advantage of weaknesses of other nations for personal gain.

If our team is resorting to unethical and immoral ways to gain that advantage, then we can't take the moral high ground and also can't complain when the other team also does "whatever it takes" to gain an advantage. Also, security through obscurity is, as we know, an illusion. Information always finds a way out. I understand your point, but there should be limits.

As I tell my small human, The good guy must do only good, or he is also the bad guy.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#739

We need to get the fuck out of China. It is becoming less credible to throw our hands up and say "China has all the silicon manufacturing, guess we have to put up with it!" - this is national security, both directly via hardware in the DoD and through our economic stability. Saying "Well the Chinese companies are different" or "It's just rogue employees" or "We just have to accept it" is not good enough. We need a li…

Relevant: https://www.wired.com/2011/11/counterfeit-missile-defense/am...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#740

Earlier quoted context omitted.

I had never heard of this...but now I can only imagine how exciting this must have been as one of the engineers-- working on a top secret project for the CIA in an abandoned bowling alley: https://electricalstrategies.com/about/in-the-news/spies-in-... edit: whoops, looks like amatecha beat me to posting more info

Exciting, but not so ethical. We owe society to put our knowledge towards making it better for all people, not just "our team".

[deleted]
Post reply on HN