Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

541–550 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#541

Earlier quoted context omitted.

That would be in line with the requirements. You go through stringent certification with the software and hardware that has access to the actual PIN and then show that the application and application hardware never really has any access to it so that you can customize/update your software. This is the easy part. The hard part I remember was establishing secure communication between all components in the system (initi…

Agree the people and process side is very difficult to do well. Familiar with all those and more -- we have extremely good, dedicated employees who care deeply about doing those things right. We have some fun stories on this topic, like when we were using our PCI PIN approved secure room in our development office for the first time. We papered over the cage to prevent a security camera from being able to see employee…

404

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#542
post #510

Earlier quoted context omitted.

Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes. http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied... The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.

Even if true, how does that make it a national security risk?

It doesn't. They claimed that so they could enact the tariffs, otherwise it would be a WTO illegal tariff. I think Canada/others are arguing that it is not a security risk and therefore is indeed an illegal tariff. This is what I remember from some articles. Please correct/elaborate.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#543

Amazon are going all out on the denial https://aws.amazon.com/blogs/security/setting-the-record-str...

Yeah, I mean that's what I would say too if some government intelligence agency told me I cannot say a word about this and have to deny it vehemently! haha :)

There's definitely something afoot. Bloomberg probably wouldn't have gone forward with just an in-depth piece referencing so many major tech companies unless it had substance. But generally even when legally compelled, companies tend to prefer silence or curt denials over lengthy detailed contrary pieces.

Is there a federal investigation going on into some sort of sabotage by the Chinese government? Possibly, and if so, there's a lot of reason these companies could even be willingly participating in covering it up. All of them benefit from the investigation being uninterrupted, and nobody needs the bad press.

Could the story be, in fact, fabricated? Sure. Russian trolls have seen to sowing discord in far more than just our election. They stoked drama about The Last Jedi even, as recently claimed. Is it possible they're seeing if they can get a major news outlet to publish something with absolutely no basis in fact? Maybe.

There's a lot of interesting possible angles here, but with the number of large public companies involved, this morning is probably the start of this drama, not the end of it.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#544

Earlier quoted context omitted.

Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)

> I can tell you - it's no joke :) But still as a user I have no idea if I'm talking to a certified machine or not.

As a user, fraud is not your problem. Security isn’t there for your benefit.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#545

Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-h... From Apple: "Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we h…

I'm actually kind of sympathetic to Apple here.

One of the company I worked for once received request from a news outlet about potential rumor around us, and bullied our CEO into an interview to disprove that rumor.

Then the journalist picked several quotes out of context as proof that rumor being true.

While I don't trust megacorps, I don't know if I can trust journalists more when a major breaking news is on the line.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#546
post #280
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

> We could not measure all possible angular momentums but it was possible to measure one or two that would not be known to the attacker. You mean moment of inertia, not angular momentum. You could measure all of them! Given the moments for the three principal axes at any point, you can use the parallel axis theorem to calculate all the rest. In general, there are 10 degrees of freedom: 3 for the position of the cente…

Indeed there are only a finite number of moments. If this was not true you could effectively 3d scan an object by just measuring its inertia response.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#547

This reminds me of that old story about the Xerox copy machines that the Soviet Union bought. Where each unit was planted with a image recorder. And for years, the American spy agencies had a great laugh, that they were able to intercept all the documents that the Russians made a copy of. Back then, this was an off-network infiltration. Where the copied images, were retrieved during regular servicing intervals by a X…

Or the IBM Selectric Typewriter implant.

http://www.cryptomuseum.com/covert/bugs/selectric/

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#548
post #510

Earlier quoted context omitted.

Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes. http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied... The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.

Even if true, how does that make it a national security risk?

Their argument is that you need strong domestic steel industry to build tanks, ships, etc, in case of war. Not saying I'm agreeing with it just pointing out the stated rationale behind the tarrifs.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#549

Earlier quoted context omitted.

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

It's not the chips that are the problem. Most of Intel's fabs are in the US, and their assembly sites are in a number of countries.

I think people should know how stark the differences for assembly in the US are vs outside of it. Something that costs, at low prototype volumes mind you, $20 in China for a dozen boards or so, would run hundreds of dollars in the US and still take the same amount of time. As it scales up, the ratio might improve, but these aren't like 10%-20% differences.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#550
post #175

Earlier quoted context omitted.

Are you saying companies should or that you know of companies that do?

One of the companies named in thr Bloomberg article does. They just deatroy your laptop if it was in the hands of customs without your supervision for any length. US customs explicitly included, which is kind of wierd if you ask me.

That doesn't strike me as odd at all.
Post reply on HN