The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
121–130 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#122I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick to dismiss state sponsored attacks by something as simple as an anti-tamper seal. You can learn how to do it yourself at most medium to large hacker conferences too (DEFCON, BlackHat, HOPE, and CCC to name a few, but there’s more with it).
[0] https://www.techradar.com/news/networking/routers-storage/ph...
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#123I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#124>Amazon’s security team conducted its own investigation into AWS’s Beijing facilities and found altered motherboards there as well, including more sophisticated designs than they’d previously encountered. >...the malicious chips were thin enough that they’d been embedded between the layers of fiberglass onto which the other components were attached >...that generation of chips was smaller than a sharpened pencil tip,…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#125This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#126I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#127Earlier quoted context omitted.
I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.
Transparent plastic?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#128This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…
I cannot think of any sovereign power that wouldn't.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#129> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?
No, it is totally inconceivable AMD and Intel CPUs are backdoored this way. Inserting a microcontroller somewhere on the Ethernet traces and then using IPMI is not as sophisticated as this article wants to describe. Sophistication is necessary from the payload to be stealthy but not the hardware. There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts…
Modern ASICs are so complex that I'm sure that sneaking a tiny backdoor into the behemoth that's a modern CPU or embedded SoC would be almost trivial. They'd also have great plausible deniability in case they're found, if something like SPECTRE was an intentional backdoor how would you ever prove it for instance?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#130> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?
No, it is totally inconceivable AMD and Intel CPUs are backdoored this way. Inserting a microcontroller somewhere on the Ethernet traces and then using IPMI is not as sophisticated as this article wants to describe. Sophistication is necessary from the payload to be stealthy but not the hardware. There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts…
That’s a fairly strong statement.
It could be argued it is conceivable as evidenced by the fact we are here talking about it.
Also, I’ve read that it’s impossible for any one person to fully comprehend the circuit diagram of a modern CPU. In light of that it seems conceviable any number of wayward circuits could be hidden.