Earlier quoted context omitted.
That would be in line with the requirements. You go through stringent certification with the software and hardware that has access to the actual PIN and then show that the application and application hardware never really has any access to it so that you can customize/update your software. This is the easy part. The hard part I remember was establishing secure communication between all components in the system (initi…
Agree the people and process side is very difficult to do well. Familiar with all those and more -- we have extremely good, dedicated employees who care deeply about doing those things right. We have some fun stories on this topic, like when we were using our PCI PIN approved secure room in our development office for the first time. We papered over the cage to prevent a security camera from being able to see employee…
The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
541–550 of 818 posts
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#542Earlier quoted context omitted.
Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes. http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied... The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.
Even if true, how does that make it a national security risk?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#543Amazon are going all out on the denial https://aws.amazon.com/blogs/security/setting-the-record-str...
Yeah, I mean that's what I would say too if some government intelligence agency told me I cannot say a word about this and have to deny it vehemently! haha :)
Is there a federal investigation going on into some sort of sabotage by the Chinese government? Possibly, and if so, there's a lot of reason these companies could even be willingly participating in covering it up. All of them benefit from the investigation being uninterrupted, and nobody needs the bad press.
Could the story be, in fact, fabricated? Sure. Russian trolls have seen to sowing discord in far more than just our election. They stoked drama about The Last Jedi even, as recently claimed. Is it possible they're seeing if they can get a major news outlet to publish something with absolutely no basis in fact? Maybe.
There's a lot of interesting possible angles here, but with the number of large public companies involved, this morning is probably the start of this drama, not the end of it.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#544Earlier quoted context omitted.
Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)
> I can tell you - it's no joke :) But still as a user I have no idea if I'm talking to a certified machine or not.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#545Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…
One of the company I worked for once received request from a news outlet about potential rumor around us, and bullied our CEO into an interview to disprove that rumor.
Then the journalist picked several quotes out of context as proof that rumor being true.
While I don't trust megacorps, I don't know if I can trust journalists more when a major breaking news is on the line.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#546I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…
> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker. You mean moment of inertia, not angular momentum. You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the cente…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#547This reminds me of that old story about the Xerox copy machines that the Soviet Union bought. Where each unit was planted with a image recorder. And for years, the American spy agencies had a great laugh, that they were able to intercept all the documents that the Russians made a copy of. Back then, this was an off-network infiltration. Where the copied images, were retrieved during regular servicing intervals by a X…
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#548Earlier quoted context omitted.
Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes. http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied... The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.
Even if true, how does that make it a national security risk?
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#549Earlier quoted context omitted.
> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?
It's not the chips that are the problem. Most of Intel's fabs are in the US, and their assembly sites are in a number of countries.
Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple
#550Earlier quoted context omitted.
Are you saying companies should or that you know of companies that do?
One of the companies named in thr Bloomberg article does. They just deatroy your laptop if it was in the hands of customs without your supervision for any length. US customs explicitly included, which is kind of wierd if you ask me.