Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

271–280 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#271

Earlier quoted context omitted.

All of which are overcome by nation state actors if they want too.

Depends on the hardware and the anti-tamper measures. I've seen POS terminals where the pcb was completely encased in security plastic, where any attempted breach would wipe the internal security keys, which meant the hardware just became a useless. They're so sensitive that these things enter "tampered state" from time to time without any tampering. I developed software on these things - and bricked multiple devices…

I have caused production outage during one of our reviews of the rack with the HSM. The procedure required opening the rack, inspecting and accounting for all devices and cables and then checking the status of the HSM itself. At the end of the procedure the rack had to be closed.

Visa/Mastercard required that there are two people present and that there are two people required to open the rack.

We had it modified so that it has second lock.

The additional lock did not fit perfectly. During the procedure when I tried to close the door the door snagged on the lock and then slammed shut. It wasn't a lot of force but it caused the HSM to loose its keys and required a lengthy procedure to get three security officers to initialize the HSM with components stored on their smart cards during which the whole system was unavailable.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#272

It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…

The more I understand software the less I trust it (given the current state of engineering practices). Meanwhile all my friends/family are scrambling to install all the latest new "smart home" gadgets and I just look like a paranoid kook trying to talk them out of it.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#274

Earlier quoted context omitted.

Clover CEO here. Won't comment on a competing device but this may not work the way you think. In Clover's approach the touch controller input isn't reaching the Application Processor running Android when in PIN entry mode. You can do patent search if you're interested.

That would be in line with the requirements. You go through stringent certification with the software and hardware that has access to the actual PIN and then show that the application and application hardware never really has any access to it so that you can customize/update your software. This is the easy part. The hard part I remember was establishing secure communication between all components in the system (initi…

Agree the people and process side is very difficult to do well. Familiar with all those and more -- we have extremely good, dedicated employees who care deeply about doing those things right.

We have some fun stories on this topic, like when we were using our PCI PIN approved secure room in our development office for the first time. We papered over the cage to prevent a security camera from being able to see employees entering PINs on the HSM. An eager employee papered over this cage a little too well cutting off the natural flow of air. And then there was a bug in our offline CA code and we spent 30 minutes in that air deprived cage while debugging occured :) finally the bug was fixed, we issued the cert on our first production device, and stepped out to get a breath of fresh air. Obviously this isn't our daily driver secure CA room :)

(If anyone reading is looking for a job in security engineering, we're hiring! https://www.clover.com/careers/engineering)

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#275

Earlier quoted context omitted.

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.

That's not correct.

HSMs are required so that the company does not need to have PIN codes exposed anywhere. Not having PINs or full credit card data makes your life easier as there is nothing to steal from you in the first place.

If your company stored PIN codes it means you were in breach of the contract and it had to lie to the auditors to pass the certification.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#276
Just as a sidenote: X-raying PCBs and then diffing them against clean PCBs is a worthwhile thing to do if you're concerned about hardware backdoors, or 'interdiction' of hardware in a supply chain. I do this sometimes when ordering super-critical equipment like Thinkpads from the U.S as you never know what lurks on the motherboard (keyloggers, etc).

I have a clean Thinkpad that I use to compare against potential backdoored devices. So far I haven't spotted any differences in the PCBs. I guess the intelligence agencies have not marked me as important enough to target. That being said, I imagine there are people working in the cryptocurrency space who have a lot to hide (if you own their boxes, you could be looking at thefts worth millions of dollars, or whatever the equivalent is in the cryptocurrency they are developing).

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#277
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Very interesting methods you used to detect the changes! Out of curiosity: was there a reason that taking an xray of the devices was not an option? Industrial/veterinary xray machines can often be had quite cheaply...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#278
post #175

Earlier quoted context omitted.

Are you saying companies should or that you know of companies that do?

As far as I know, big EU companys do that, when they visit US, or they don't have sensitive information with them in the first place.

Especially when border cops can seize your phone / ask for your passwords

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#279

Earlier quoted context omitted.

> I hope this corrects the mistaken believe that China can't home grow sophisticated tech. There's nothing particularly sophisticated about what they did, especially given what China has access to as one of the central hubs of tech manufacturing. There are two dozen nations (or more) that could do this from a strictly technical standpoint (few have the kind of required supply chain access to pull it off at scale in a…

You're right. One question though. Would a politically correct, by-the-book US president have had the balls to sanction China? Considering such sanctions could affect the US economy.

> Would a politically correct, by-the-book US president have had the balls to sanction China?

Does Trump even have a goal in mind with his tariffs? It seems like he just wants to score political points, rather than achieve any actual outcomes.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#280
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker.

You mean moment of inertia, not angular momentum.

You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the center of mass, 3 for the axes, three for the moments, and for the the total mass.

For a nicer way to count and to do the math, you have the inertia tensor at the CM (a 3-dimensional rank-2 symmetric tensor, 6 DoF) plus the location of the CM and the mass.

In any event, this is a cute tampering-detection trick, but I would have started with an X-ray or CT scan.

Post reply on HN