Earlier quoted context omitted.
You can be as sarcastic as you want, but these stories are absolutely indicative of a much larger problem. It might be beyond the capacity of one company to fix, but in the aggregate they represent a serious political and economic threat and need to be dealt with one way or another. Preferably by literally anyone other than Donald Trump.
Speaking as someone who is _not_ a citizen of the USA and is well aware of his issues, he seems to be first US President who actually appears to have the guts to do something about it. I doubt an establishment politician would ever have imposed tariffs on 200 billion dollars of China imports.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
781–790 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#782Earlier quoted context omitted.
Might make a difference if those pennies can't be tracked back to the government.
Yup. This would be the modern equivalent of Air America and other schemes by the CIA to raise money to operate by involving themselves in illegal activity like the drug trade.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#783Earlier quoted context omitted.
he's saying that his company knowingly allows a percentage of fraud, identity, and financial theft to occur against his customers' customers because there are enough layers of indirection where they (he and his bosses) probably can't be held personally responsible. Enough efforts (fancy tables with big receipts, etc) have been provided for coverage in case of a court case or media blitz but actually using a reputable…
I guess it's news to you that the financial sector and especially banks in fact do exactly that: https://www.creditcards.com/credit-card-news/credit-card-sec... But it doesn't stop with the cards. ATMs, Tax Fraud, ... almost all businesses within banks have to deal with fraud and there is some threshold that they just allow to happen.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#784Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#785Earlier quoted context omitted.
SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…
> The naive approach would be to not connect to the dedicated NIC that's indicated on the back and in the instruction manual, but if you do this it masquerades onto the main NIC cool, thanks for that info. > just to write off the hardware maybe you could just standup the mgmt network but blackhole route it at each switch port. The mgmt NIC thinks it's working properly but it can't talk to anyone nor can anyone talk t…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#786Earlier quoted context omitted.
> Modern ASICs are so complex that I'm sure that sneaking a tiny backdoor into the behemoth that's a modern CPU or embedded SoC would be almost trivial. I suspect putting in a backdoor would be difficult because they are complex. Wouldn’t it be far too easy for the backdoor to inadvertently cause reliability or performance issues? And the bug would have to be useful enough to warrant potentially destroying the semico…
Nobody cares about your wild, uneducated speculation.
It wasn’t wild nor uneducated; I have some experience with FPGAs and the challenges of complex circuit design - regardless, I was posing a question rather than stating fact.
Do you disagree with what I suggested? Educate me, correct my speculation.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#787It even looks like this attack has been already described here: https://blog.eclypsium.com/2018/09/06/insecure-firmware-upda...
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#788Earlier quoted context omitted.
> I wonder what reason Apple has to hide. The perception is that Apple is perfect and worth paying 3x the cost? EDIT: Curious if all of these Apple comments are going to disappear. I believe they have a strong marketing team to hide dissent.
This breaks the site guideline that asks you not to insinuate astroturfing or shillage without evidence. Please don't do that—it's a toxic trope that leads to dumber threads. https://news.ycombinator.com/newsguidelines.html Edit: looks like we've already warned you about this more than once. If you keep doing it we're going to have to ban you, so please don't post like this again. Ditto for unsubstantive comments in…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#789[1]: https://news.ycombinator.com/item?id=18146438 [2]: https://news.ycombinator.com/item?id=18138328 [3]: https://news.ycombinator.com/item?id=18145645 [4]: https://news.ycombinator.com/item?id=18138990 [5]: https://news.ycombinator.com/item?id=18141328
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#790Earlier quoted context omitted.
Supermicro 6128 aka x10 series microblade. Those were very popular among Chinese DC operators during Broadwel era. https://www.itcreations.com/dist/landing/i/MBI-6128R-T2/MBI-... Left of the sata connector. An empty space with 8 pads for an smt eeprom or flash. It is occupied by the thingy on bugged boards. Right below is the Aspeed chip - the BMC
Is there a list of known compromised Supermicro SKUs?