Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

121–130 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#122
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag

You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick to dismiss state sponsored attacks by something as simple as an anti-tamper seal. You can learn how to do it yourself at most medium to large hacker conferences too (DEFCON, BlackHat, HOPE, and CCC to name a few, but there’s more with it).

[0] https://www.techradar.com/news/networking/routers-storage/ph...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#123
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Maybe a setup to measure inertia tensor and center of mass (in that setup's axes) will be easier and I think it's what your call "measuring all angular momentums".

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#124

>Amazon’s security team conducted its own investigation into AWS’s Beijing facilities and found altered motherboards there as well, including more sophisticated designs than they’d previously encountered. >...the malicious chips were thin enough that they’d been embedded between the layers of fiberglass onto which the other components were attached >...that generation of chips was smaller than a sharpened pencil tip,…

Dang is a cunt.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#125
post #83

This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…

Anti-China propaganda? These chips were designed by the Chinese military and inserted by PLA agents. Do you have to start calling things propaganda to make it seem like this is baseless criticism of China to those who have not read the article?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#126
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Gosh, I would love to read everything about this. I know there are some videos about anti-tampering card readers on youtube, but not on the feedback race between hackers and security.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#127
post #80

Earlier quoted context omitted.

I think what is described is an issue with process. If the device is sealed with an anti-tampering system then the contents must be checked by a trusted entity before being sealed. Trying to guess the contents of a box that you cannot open sounds a bit like madness.

Transparent plastic?

They may find a way to hide things out of view. My thinking would be to x-ray it. Airports are pretty good at that.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#128
post #83

This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…

> Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet?

I cannot think of any sovereign power that wouldn't.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#129
post #75

> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?

No, it is totally inconceivable AMD and Intel CPUs are backdoored this way. Inserting a microcontroller somewhere on the Ethernet traces and then using IPMI is not as sophisticated as this article wants to describe. Sophistication is necessary from the payload to be stealthy but not the hardware. There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts…

I don't think the parent was talking about this specific type of attacks but other types of hardware backdoors. I think the answer to that is very obviously yes, and given what we know about intelligence agencies I'm even willing to go as far as saying that it is likely (or at least, if you have reasons to be worried about Uncle Sam getting to your stuff you should consider it a very real possibility).

Modern ASICs are so complex that I'm sure that sneaking a tiny backdoor into the behemoth that's a modern CPU or embedded SoC would be almost trivial. They'd also have great plausible deniability in case they're found, if something like SPECTRE was an intentional backdoor how would you ever prove it for instance?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#130
post #75

> One country in particular has an advantage executing this kind of attack: China, which by some estimates makes 75 percent of the world’s mobile phones and 90 percent of its PCs. Intel and AMD are both USA based companies. Is it conceivable their processors contain backdoors in a similar vein?

No, it is totally inconceivable AMD and Intel CPUs are backdoored this way. Inserting a microcontroller somewhere on the Ethernet traces and then using IPMI is not as sophisticated as this article wants to describe. Sophistication is necessary from the payload to be stealthy but not the hardware. There are at least two problems with China messing with CPUs: a) they are not made there. TSMC is Taiwan, the Asian parts…

> No, it is totally inconceivable AMD and Intel CPUs are backdoored this way.

That’s a fairly strong statement.

It could be argued it is conceivable as evidenced by the fact we are here talking about it.

Also, I’ve read that it’s impossible for any one person to fully comprehend the circuit diagram of a modern CPU. In light of that it seems conceviable any number of wayward circuits could be hidden.

Post reply on HN