Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

131–140 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#131
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

It's not the chips that are the problem. Most of Intel's fabs are in the US, and their assembly sites are in a number of countries.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#132
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

This is not microchips, this is basic PCB assembly

But I'd guess momentum is hard to change.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#133
post #84
post #56

When will this stuff finally have consequences for China? Their behavior, not their communication, has been overtly hostile for a while. Yet, very few politicians openly adress the issue.

>When will this stuff finally have consequences for China? Never, unless hardware manufacturing will take off somewhere else.

Somewhere poor, where labor is cheap and people are still susceptible to bribes?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#134

So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…

Yes, TVS Diode Array (image google to see they look just like in the article) for ESD protection is the obvious candidate, inserted on serial communication lines - perfect spot for signal interception/injection.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#135
post #29

Earlier quoted context omitted.

It sometimes feels like certain hardware protocols were designed to be insecure. I remember reading about IPMI issues back in 2013: https://www.itworld.com/article/2708437/security/ipmi--the-m...

"Designed to be insecure" is probably unfair to the designers of IPMI. Security was just not as big a concern as it is today.

This is only really valid for protocols or products designed before the Morris worm of 1988. Anything designed beyond 2000 has no excuse for not thinking about internet security.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#136
post #97

Earlier quoted context omitted.

That would make a lot of sense and would give the attacker a way to interface with all of the other hardware (network, disk etc.). Do you have a source for this information?

I looked up supermicro blade motherboards, and saw that the chip was right near the IPMI chip's line to spi flash. And prior to that, there were already persistent rumors in the Chinese interney of certain Chinese mobos sending "weird garbage on ICMP," and "BMCs that somehow boot and work with their flash memory soldered off" Remembering that, I might even suggest that this is not a modchip that does something with s…

A photo of such a motherboard with a big arrow pointed at the additional chip would be a useful addition to this discussion.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#137

So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…

"But this clever hack is probably not limited to RF and is likely to also be embedded in transformers used for isolating Ethernet lines."

I was thinking along the same lines: a balun could harvest energy and use it for other purposes, but it should either store it for later use using maybe a tiny supercapacitor inside, or inject it into the data stream on the fly not unlike RFID dongles do. Or maybe just have enough power and memory to store a few hundred bytes and alter a few fields here and there, so that for example a network frame coming from a compromised machine can have its source field rewritten as it came from a trusted source. In theory small pull up resistors also could be swapped with lookalike malicious parts capable of tampering with i2c traffic between boards peripherals so that devices can be activated/deactivated no matter what the CPU tells them.

We're going straight to the point when there won't be a single device in the world, from toasters to supercomputers through top brand network gear, that can claim and guarantee to be secure; inserting malicious hardware and firmware is getting just too easy for those with the necessary knowledge and resources. A technically interesting and scary scenario.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#138

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#139
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

America has fabs, both old and leading edge, but ask industry giants like Gemalto to even bother to manufacture chips anywhere outside of Taiwan, assemble the final product outside of China.

They will never do that, because they look for the cheapest solution.

The bigger the company, the less it cares about things other than cost. This is why Mediatek and Broadcom can usurp the market of network SoCs, while making products with atrociously bad support. I personally dealt with both, and say that they wholely match their popular culture image.

I don't know how it is with USA, but for Russia, the military doesn't care that their chips had frequency measured in kilohertz, and had sizes measured in square sentimetres, for as long as they get them made inside the country.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#140
post #77
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

You are underestimating the FUN of playing anti-anti-^N-hacks. I have had the privilege to be paid to so anti-anti-^N-hacking on a firewall thingy in the past and it was a challenge and a joy!
Post reply on HN