Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

711–720 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#711

Earlier quoted context omitted.

Seriously, why are we still outsourcing chip manufacturing to other countries? Sure it's cheaper, but we sacrifice a lot to have a society of corporate slaves build our tech. Security, core domain knowledge, capability, corporate secrets, patent rewards and enforcement, etc... All of it you throw away the minute you ship your manufacturing out of the country. I've seen enough board printing machines out there to star…

Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another? The moment the option of taking control of a production line of som…

You're letting the perfect become the enemy of the good here

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#712

Earlier quoted context omitted.

That is also in the article... "17 people confirmed the manipulation of Supermicro’s hardware and other elements of the attacks. The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."

So not a single source. Might as well be going to war over invisible weapons of mass destruction. Also, Apple and Amazon both has said they do not agree with these claims. So far this is nothing more than propaganda.

so you prefer to believe official corporate statements saying they didn’t have security leaks, rather than a news agency with 17 independent sources confirming they had ??

That’s an interesting choice.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#713

Earlier quoted context omitted.

How do you know that the DoD/CIA isn't behind this?

Because it came from Chinese manufacturers. Did you read the article?

Why does that matter at all? How do you know the CIA didn't use Chinese spies to do this? Although from a different agency, the motto "Nothing Is Beyond Our Reach" is telling.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#714

Earlier quoted context omitted.

Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)

Certification [...] I can tell you - it's no joke :) I'm not so sure. "And then initial supplier inserted hardware that thwarted all those pressing considerations" sounds a punchline to me. :(.

That, at least, is a problem that cab be solved by tightening security at supplier site.

The safeties are mainly to guard against the rest of the world. For example it prevents tampering in transit, or even in our own company - disgruntled employee can't do anything.

Or think for a second about the fact that we leave the device for, hopefully, entirety if its life at the client site. We had clients that were shady businesses like strip clubs that no other companies would touch with a stick.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#715

Earlier quoted context omitted.

How do you know that the DoD/CIA isn't behind this?

What evidence do you have to suggest that?

None at all. I'm not saying it is the CIA. But it isn't like they do't have a history of wanting to spy on anyone they could.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#716
post #72

Earlier quoted context omitted.

To be clear, this is only for the ability to update the BIOS over the BMC interface, not for BIOS updates in general. (unlike some other vendors, where you need a support contract to be even able to download the updates) At least on some boards you can boot the USB drive image containing the BIOS updater through the BMC and do a remote update that way.

Supermicro doesn't publish changelogs for their BIOSes. Their disclaimer on their BIOS download page says, "don't update the BIOS unless you have to". It's a ridiculous stance for a server company. You buy Supermicro over Dell for the price. That's pretty much it.

Price, variation, and time to market.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#717

Earlier quoted context omitted.

Certification. Worked in the same industry, and there were very strict both hardware and software requirements for POS software. Having gone trough credit-card audits, early EMV certification programs, and certification to place non-payment software next to payment software on such systems, I can tell you - it's no joke :)

> I can tell you - it's no joke :) But still as a user I have no idea if I'm talking to a certified machine or not.

It's not your problem. For the transaction to take place it has to go to your bank and your bank trusts Visa/Mastercard to manage risks. You would be surprised to know most frauds are absorbed by banks. Nobody is interested in people fearing plastic because it causes people to increase very expensive debt plus additional interchange fee from every transaction.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#718
post #178

Earlier quoted context omitted.

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…

[deleted]

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#719

Amazon are going all out on the denial https://aws.amazon.com/blogs/security/setting-the-record-str...

Even if a national security letter wouldn't compel Apple or Amazon to lie, couldn't it compel the security team not to inform the executives or lawyers? Or at least this is an argument that's been going on for a while, can't remember if that issue has been settled.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#720

Earlier quoted context omitted.

Procedures change, as attacks get more sophisticated the next step could be disposable devices. But an attack like the one described in this article won't be mitigated by having a disposable device. On the other hand having your laptop "hijacked" while on a business trip will most likely involve some extra PCB or components that are a little more obvious that something that's "built in". Then again many companies or…

Does the security team have any motivation to reduce waste? Unless you're finding hacks in your devices already I see no reason to think they aren't just making you jump through hoops because it's funny.

Of course not. But remember that someone else is holding their purse strings so they might care about that.
Post reply on HN