Who else found the design of the page made the article difficult to read? I know darkness, spies and hacking go hand-in-hand but it's a bit too much imho.
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
11–20 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#12Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands? That said, it's…
This stuff ends up being extremely difficult to disable. The naive approach would be to not connect to the dedicated NIC that's indicated on the back and in the instruction manual, but if you do this it masquerades onto the main NIC invisibly to the OS and DHCPs on its own to open up an administration port, web interface, and some assorted call homes. You have to explicitly tell it to use the non-connected port, change credentials, and modify it so that it is not accessible within operating system as well. Hopefully while the machine is offline to prevented any automated scanning finding it within your network.
The number of times I'd end up nmaping our local networks and being able to remotely access production hardware with an interface that allowed me to reach this interface was maddening. The system is basically designed to be as insecure as possible by default, and allow for the maximum possible persistent threats with BIOS flashing, IPMI flashing, and other completely nu-authenticated avenues exposed. The course of action was always just to write off the hardware and bin it, because god knows what impact you could actually have using that interface.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#13Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#14Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#15The denials by Amazon, Apple, Supermicro and the Chinese Ministry of Foreign Affairs [1] are relatively pro forma , both directed by respective nation states involved in this matter. One of the reporters interviewed on Bloomberg noted Amazon and Apple could be directed by US national security interests to deny to protect the ongoing US investigation. Supermicro could similarly be directed by Chinese national security…
Supermicro is an American corporation, headquartered in San Jose. They're not directed by Chinese national security interests, they'll do anything the US Government tells them to do when it comes to US national security.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#16Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#17Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#18Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#19Why aren't these attacks constrained by normal corporate firewalls? How does a random server on a navy ship start contacting baddie.china.com without raising red flags?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#20This sounds like something out of a movie. I would like some technical details how this is supposed to work with only a 6 lead chip.