Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

141–150 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#141
post #87

So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…

I don't know enough about this, but isn't the article saying that the appearance is deceptive: The chips on Elemental servers were designed to be as inconspicuous as possible, according to one person who saw a detailed report prepared for Amazon by its third-party security contractor, as well as a second person who saw digital photos and X-ray images of the chips incorporated into a later report prepared by Amazon’s…

If the photo in the article is real you wouldnt be able to identify this component as compromised "just" by visual (even xray augmented) inspection. TVS Diode Array looks the same from the outside, whats more its build in same way with silicon die embedded in tis structure. Other than signal analysis it would take decapping every single component of a motherboard to find this implant.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#142

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

NSL letter, under active investigation

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#143
post #109

Earlier quoted context omitted.

It's mentioned in the article that X-Ray didn't help much: 'Gray or off-white in color, they looked more like signal conditioning couplers, another common motherboard component, than microchips, and so they were unlikely to be detectable without specialized equipment'

This comment is specific to the parent talking about their experiences producing credit card terminals that ended up with PCBs implanted in them. Here it is appropriate.

And as soon as they know you are using X-Ray to test ( I would be surprised if there were no insider information leaking on the OP's end ), they would develop a way so that somehow the X-Ray images looks identical. May be a heat spreader like metal as cover up.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#144

It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…

[deleted]

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#145

Earlier quoted context omitted.

> guess the contents of a box Use X-ray? or whatever can penetrate the exterior shell

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

I would imagine you would treat any kit that has been to those countries as disposable on return and crush them

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#146
post #83

This story could easily be interpreted as anti-China propaganda. Could you think of any other sovereign power who would want a backdoor into servers used by billions of people across the internet? Hardware comes from China. This doesn't mean that the Chinese government orchestrated the attack. The United States government is having a trade war with China. This article's publication isn't just coincidence. Further, th…

This comment could easily be interpreted as pro-China propaganda.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#148
post #84

Earlier quoted context omitted.

>When will this stuff finally have consequences for China? Never, unless hardware manufacturing will take off somewhere else.

Somewhere poor, where labor is cheap and people are still susceptible to bribes?

Rather not, China's economic rise started in Jiang's era was both due to it being cheap, AND due to Jiang's era officials being more competent and business friendly than those of an average bantustan (really sorry having to use the term)

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#149

Earlier quoted context omitted.

> guess the contents of a box Use X-ray? or whatever can penetrate the exterior shell

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

Add the USA to that list.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#150
They attacked the Base Management Controller. There's an article by Bruce Schneier from 2013 warning about exactly this attack. Quoting:

"Basically, it's a perfect spying platform. You can't control it. You can't patch it. It can completely control your computer's hardware and software. And its purpose is remote monitoring. At the very least, we need to be able to look into these devices and see what's running on them."

https://www.schneier.com/blog/archives/2013/01/the_eavesdrop...

Post reply on HN