Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

261–270 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#261
So, what was the SMT part supposed to be, and what was put in there instead? I would love identifying markings, or you know, a datasheet.

Nothing so far I've read includes part numbers. Sure would like to go through my supply to see if I have any of the offending parts.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#262

Earlier quoted context omitted.

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

And none of those measures would have protected against the compromise detailed in the article.

Sure, we were discussing someone saying their devices came with extra PCBs inside (it's a bit hard to follow but scroll up to the original comment, currently first on the page).

> We would be getting products from China with added boards to beam credit card information.

>> Trying to guess the contents of a box that you cannot open sounds a bit like madness.

>>> Use X-ray? or whatever can penetrate the exterior shell

2 different types of attacks, 2 different types of responses.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#264
post #200

Earlier quoted context omitted.

Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...

Clover CEO here. Won't comment on a competing device but this may not work the way you think. In Clover's approach the touch controller input isn't reaching the Application Processor running Android when in PIN entry mode. You can do patent search if you're interested.

That would be in line with the requirements. You go through stringent certification with the software and hardware that has access to the actual PIN and then show that the application and application hardware never really has any access to it so that you can customize/update your software.

This is the easy part.

The hard part I remember was establishing secure communication between all components in the system (initializing HSMs, injecting keys). I remember helping designing the process and writing hundreds of documents describing various security-related procedures like how the HSM racks are inspected, how the keys to the racks are fetched from the safes, how there are multiple safes for multiple security officers, how the officers are prevented from ever having access to other safes, how fetching anything from safes requires logging and using tamper-evident containers, how the logs are inspected, and so on.

I have designed a special cryptographic protocol so that we could generate and inject keys to the devices in KIF (Key Injection Facility) and separately to our database (to establish communication with the terminal). Fun.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#265

They attacked the Base Management Controller. There's an article by Bruce Schneier from 2013 warning about exactly this attack. Quoting: "Basically, it's a perfect spying platform. You can't control it. You can't patch it. It can completely control your computer's hardware and software. And its purpose is remote monitoring. At the very least, we need to be able to look into these devices and see what's running on the…

> They attacked the Base Management Controller. Do you know this, or are you speculating?

It's in the article:

"The illicit chips could do all this because they were connected to the baseboard management controller..."

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#266

Earlier quoted context omitted.

You are underestimating the FUN of playing anti-anti-^N-hacks. I have had the privilege to be paid to so anti-anti-^N-hacking on a firewall thingy in the past and it was a challenge and a joy!

The day I figured out to measure the angular momentums and calculated the feasibility I was walking around the office proud like a peacock.

I'd very much love to hear more stories if you have any!

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#267

Earlier quoted context omitted.

You are underestimating the FUN of playing anti-anti-^N-hacks. I have had the privilege to be paid to so anti-anti-^N-hacking on a firewall thingy in the past and it was a challenge and a joy!

The day I figured out to measure the angular momentums and calculated the feasibility I was walking around the office proud like a peacock.

i love this ~

quote captures the human element playing strong in face of bad system

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#268

Earlier quoted context omitted.

You are underestimating the FUN of playing anti-anti-^N-hacks. I have had the privilege to be paid to so anti-anti-^N-hacking on a firewall thingy in the past and it was a challenge and a joy!

The day I figured out to measure the angular momentums and calculated the feasibility I was walking around the office proud like a peacock.

^ This gave me a much needed smile today, thanks for sharing.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#270
post #77
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

When I worked in telecom (a while ago) the manufacturing was shifted from China to Thailand/Other SE Asia due to this. The Thai companies weren't as efficient, but were much more open and honest when problems would arise., plus they didn't blatantly steal tech
Post reply on HN