Earlier quoted context omitted.
An update on that theory: AST2400 has option for two SPI memories, one main, one "recovery." https://download.csdn.net/download/duanzhang512/10385038 The recovery overrides the primary if detected by default. The place they put their "filter cap" is right on top the empty TSOP8 pad for the recovery flash. And they probably ordered the factory to sneak the traces just a little bit more, or put hidden vias under it, or…
This is the most plausible theory I've read in this thread. Assuming the image in the article is a stock image (there isn't yet a clear image of a definitely compromised board), then the added part could simply be another TSOP8 Flash part. This implies the firmware to the AST2400 is unsigned (which it appears to be, as there's coreboot options for it). That makes the whole thing gloriously simple. A part "stuck on" a…
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
771–780 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#772I didn't realize Pied Piper was based on a real company...
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#773Earlier quoted context omitted.
I looked up supermicro blade motherboards, and saw that the chip was right near the IPMI chip's line to spi flash. And prior to that, there were already persistent rumors in the Chinese interney of certain Chinese mobos sending "weird garbage on ICMP," and "BMCs that somehow boot and work with their flash memory soldered off" Remembering that, I might even suggest that this is not a modchip that does something with s…
An update on that theory: AST2400 has option for two SPI memories, one main, one "recovery." https://download.csdn.net/download/duanzhang512/10385038 The recovery overrides the primary if detected by default. The place they put their "filter cap" is right on top the empty TSOP8 pad for the recovery flash. And they probably ordered the factory to sneak the traces just a little bit more, or put hidden vias under it, or…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#774Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…
https://freebeacon.com/national-security/military-warns-chin...
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#775Earlier quoted context omitted.
OMG, that is so so so so brilliant! I'm going to go tell my boss right now that the suppliers better suite up, otherwise we are going right to their more expensive, less experienced vendor and will delay our product launch for a year....and likely still suffer the same problem. Those Chinese vendors better shape up or we're going to really teach them a lesson by driving ourself out of business right quick!
You can be as sarcastic as you want, but these stories are absolutely indicative of a much larger problem. It might be beyond the capacity of one company to fix, but in the aggregate they represent a serious political and economic threat and need to be dealt with one way or another. Preferably by literally anyone other than Donald Trump.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#776Earlier quoted context omitted.
Not all societies are equally corrupt.
But no societies are free from organized crime. And last time I checked, no western country was free from card skimmers either.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#777Earlier quoted context omitted.
There's definitely something afoot. Bloomberg probably wouldn't have gone forward with just an in-depth piece referencing so many major tech companies unless it had substance. But generally even when legally compelled, companies tend to prefer silence or curt denials over lengthy detailed contrary pieces. Is there a federal investigation going on into some sort of sabotage by the Chinese government? Possibly, and if…
I think it is a win-win for Apple and Amazon to spin it this way. They get to deny that they were compromised, and if that gets disproved they can easily say they were cooperating with national security operations and get away without any damage.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#778Earlier quoted context omitted.
Not all societies are equally corrupt.
But no societies are free from organized crime. And last time I checked, no western country was free from card skimmers either.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#779Earlier quoted context omitted.
The more I understand software the less I trust it (given the current state of engineering practices). Meanwhile all my friends/family are scrambling to install all the latest new "smart home" gadgets and I just look like a paranoid kook trying to talk them out of it.
This. I've even had an in-law say, "My brother works for the Defense Intelligence Agency, and he uses smart devices in his home, so they must be safe!", with no consideration that tech may not be his specialty, or he doesn't follow the daily IoT fiascos, or maybe he just thinks he won't get hacked. Dunno. Meanwhile, my year-old thermostat still wants me to connect it to wi-fi, and that will never happen.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#780Earlier quoted context omitted.
Wouldn't help. The BMC hardware has direct serial access to CPUs and other hardware in the machine. Communication is unencrypted. A hardware modification attack wouldn't touch the firmware at all and could still compromise IPMI functionality.
Reducing the attack surface does help -- you're making perfection the enemy of the "somewhat better".