Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

351–360 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#351

Earlier quoted context omitted.

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

they have literally every reason to deny and literally no reason to say it's true

Not at all. It would be quite damaging to their reputation if it came out later that they were affected by this, knew it, and lied about it. Especially since the privacy of customer data is a key part of their marketing message these days.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#352
Where is the _actual_ explanation of how the chip works? I assume it's been dissected to bits, and that's way more interesting than just "it's been found on lots of boards". What does it actually contain that apparently lets it do things that apparently no one else has managed to achieve at that scale?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#353
post #266

Earlier quoted context omitted.

I'd very much love to hear more stories if you have any!

We had MasterCard end-to-end test auditor on site. This is the first time ever you get to do a transaction with real transaction system with real credit card. Due to requirements we opted to have the only large meeting room to have outside our secure zone. This created an issue as we had no network access from there and in the end we decided to use slow GPRS terminal for the test. The end-to-end test starts with offl…

Seriously, pitch this story to an editor at one of the major tech blogs. It would be an incredible read.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#354
post #265

Earlier quoted context omitted.

> They attacked the Base Management Controller. Do you know this, or are you speculating?

It's in the article: "The illicit chips could do all this because they were connected to the baseboard management controller..."

Can you quote a single source from that article, or is it all anonymous?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#355
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

It's hard to compete domestically against low prices caused by China's completely different standards for wages and human rights for laborers. Plus, here we don't like the idea of manufacturing industries being subsidized by the government (except in the case of "defense" of course...), while China obviously has no qualms with doing so.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#356

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

What liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

I mean what are they gonna say? "Yes, we have been aware that an unknown but possibly huge number of our servers have been compromised, but decided to keep our customers in the dark"?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#357

I don't know which is more disturbing here. That the Chinese military is technically competent enough to pull off such a thing. Or that they are incompetent enough, to not secure their own back doors and networks, and allowed the FBI, NSA, and other American government organizations, the ability to counter-hack them, and monitor all their internal communications. The truth is somewhere in between. So, this article is…

> we also hacked all of their internal communications too

my take on the article was that US counterintelligence sort of cobbled together some hacked phone communications with some info from human agents working in or around or near Chinese factories. to say that "we own them" maybe goes too far?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#358
post #280

Earlier quoted context omitted.

> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker. You mean moment of inertia, not angular momentum. You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the cente…

Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…

Another problem is anti-tampering measure is applied before the initial tampering check have been applied. Anyway, that wouldn't solve everything considering that if the chip itself is tampered with, that's undetectable short of an electron microscope analysis and even that wouldn't solve the problem of backdoor in the original chip design.

As you say, that's un-winnable. The only way to really build trust is the capacity to sue your manufacturer to oblivion - I mean the real oblivion (destruction of shareholder value) with criminal charge for the company officers, not the lame single digit percent of a single year of profit with a discount if you settle.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#359

Earlier quoted context omitted.

Another implication of the parallel axis theorem is that the attacker could perfectly mimic every moment of inertia by shaving plastic. They wouldn't have to know which two axes were being tested because there are only three real numbers worth of information in the system to begin with (once center of mass and total mass have been dealt with.) In the whole MOI tensor there are only six free numbers which sounds like…

I honestly did not know about that. I thought that if you move any mass (remove non zero mass and place it somewhere else) there must be at least one axis which you can use to detect the change in moment of inertia.

whatshisface is correct.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#360
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another?

The moment the option of taking control of a production line of something _this important_ becomes available, your local specialized organized crime outfits will start to figure out ways to insert themselves into those production lines, learning the ins and outs, and figuring out a way to get something, anything, in there that won't be noticed but will give them a hook into millions of systems.

The law does not prevent crime. It just puts a price on it. While that price is typically too high for individuals, for organizations that have no business registration to revoke, and no CEO to drag to court, it is an entirely trivial cost.

Post reply on HN