Earlier quoted context omitted.
I’m under the impression that China does not make chips, but they do final assembly cheaper and faster than everyone else. I don’t know if any companies do PCB manufacturing and assembly outside of China in large numbers.
Not exactly, PCB assembly is super cheap everywhere thanks to propagation of chipshooters, what makes the cost go up is logistics - what do you do after you populate the board for your part? Ship it across the world, or to another factory behind the corner?
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
451–460 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#452It's been a few years I've given up on the idea of privacy with technology. The number of security flaws that get discovered daily is only the tip of the iceberg. I'm pretty sure some governments (or organizations) have had backdoors, be they hardware or software, in place for more than 20 years. We simply don't know about it yet (and probably never will). Would that actually be that far-fetched? I think not sadly. E…
The more I understand software the less I trust it (given the current state of engineering practices). Meanwhile all my friends/family are scrambling to install all the latest new "smart home" gadgets and I just look like a paranoid kook trying to talk them out of it.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#453Earlier quoted context omitted.
Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.
That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#454Anyone remember the hack of Apple via Supermicro firmware.... https://arstechnica.com/information-technology/2017/02/apple...
> Three senior insiders at Apple say that in the summer of 2015, it, too, found malicious chips on Supermicro motherboards. Apple severed ties with Supermicro the following year, for what it described as unrelated reasons.
And then as an "unrelated and relatively minor security incident" later on.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#455Earlier quoted context omitted.
Wait a minute... So your company has a Chinese equipment supplier, finds out that the supplier is tampering with your purchased equipment, and your solution is to add criteria to the incoming inspection? No wonder China keeps screwing with you guys. You aren't supposed to eat that cost! Write a PO with tons of fine print that says "We will disassembly units at random for compliance inspection. Non compliant products…
There were other considerations like the fact we were actually buing it from large reputable company and what happened was that some employees were doing it with no involvement of the company. The fact is, doing any kind of hardware production in China, you have to be aware Chineese have different value system and you would not be suited doing any business if you throw tantrum at any sign of apparent dishonesty (assu…
It's their responsibility to police for that. From the perspective of their business arrangement with you, it doesn't matter whether their left hand or right hand is evil; it's not your problem either way.
Is it really hard to find alternatives? Are they really cheaper than non-Chinese sources when you account for these inspection costs?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#456I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#457Earlier quoted context omitted.
Supermicro 6128 aka x10 series microblade. Those were very popular among Chinese DC operators during Broadwel era. https://www.itcreations.com/dist/landing/i/MBI-6128R-T2/MBI-... Left of the sata connector. An empty space with 8 pads for an smt eeprom or flash. It is occupied by the thingy on bugged boards. Right below is the Aspeed chip - the BMC
Is there a list of known compromised Supermicro SKUs?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#458I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…
That's enough, full stop, say no more. The other costs are real yet they're either not marginal, are borne by others, or both.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#459Earlier quoted context omitted.
Worked in the payment industry for years. Visa/Mastercard do absolutely nothing to verify that companies are not storing Pin codes. The HSM is required for communication with them only.
That's not correct the QSA will validate that the device does not store PIN codes or the that the merchant does not store anything they are not allowed. Devices that accept cards need to comply with PED/PTS security requirements including very strict physical security requirements which are validated by PCI council approved laboratories and firms. You are not getting a device on the market or usable with any merchane…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#460Earlier quoted context omitted.
Add the USA to that list.
Are you saying companies should or that you know of companies that do?