Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

741–750 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#741
post #738

Earlier quoted context omitted.

If our team is resorting to unethical and immoral ways to gain that advantage, then we can't take the moral high ground and also can't complain when the other team also does "whatever it takes" to gain an advantage. Also, security through obscurity is, as we know, an illusion. Information always finds a way out. I understand your point, but there should be limits.

As I tell my small human, The good guy must do only good, or he is also the bad guy.

Good on you, man. The world needs more good guys.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#742

We need to get the fuck out of China. It is becoming less credible to throw our hands up and say "China has all the silicon manufacturing, guess we have to put up with it!" - this is national security, both directly via hardware in the DoD and through our economic stability. Saying "Well the Chinese companies are different" or "It's just rogue employees" or "We just have to accept it" is not good enough. We need a li…

How do you know that the DoD/CIA isn't behind this?

my bets on the lizard people

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#743
post #723

Earlier quoted context omitted.

Exciting, but not so ethical. We owe society to put our knowledge towards making it better for all people, not just "our team".

It's important though to make sure that your team keeps tactical advantage so that it can continue existing. Maybe someday mankind will find world peace but in our current world there are a lot of nations that hate each other still and wouldn't hesitate to take advantage of weaknesses of other nations for personal gain.

But once you create the technology and hand it over to someone else, you have no assurance that it's only going to be used against the "bad guys":

Judging by the number of parts ordered from Xerox, Zoppoth believes that spy cameras may have been installed in photocopiers all over the world, to keep an eye on U.S. allies as well as enemies

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#744

Earlier quoted context omitted.

All big and security-responsible companies issue their employees special phones and laptops when they go on business trips to countries like China or Russia and these are quarantined immediately after they return. They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). The more critical the field, the more you have to treat those devices as untrusted before attaching them to…

> They get wiped, X-rayed, disassembled and checked, including any accessory (chargers, mice, etc.). Given how sophisticated these attacks can be, I'd think they'd issue disposable equipment to be destroyed on return, like a cheap netbook or something. I don't see how you could trust an individual viewing a simple X-ray scan to detect some extra microchip the size of a signal conditioning coupler.

The post-trip inspection is not so that the device can be reused, it's so you can (try to) find out if it was compromised. A $3000 laptop is not a significant cost compared to the airfare, hotel bills, etc.

But it's useful to know when/if you're being targeted.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#745
post #510

Earlier quoted context omitted.

Also, as far as I understand the argument, it goes beyond "Canadian steel is a national security risk". A couple of years ago, Mexico was caught laundering $2B of Chinese aluminum to avoid US taxes. http://fortune.com/2016/09/09/chinese-aluminum-giant-is-tied... The theory, from the Trump crowd, is that Canada is also engaged in similar shady dealings with China. If true, that would put the US at risk.

Even if true, how does that make it a national security risk?

Maybe because it undermines fundamental US business interests, and therefore wellbeing? If so it still seems like a stretch to me. Doubtful we'd have no where else to source steel if war or disaster struck.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#746
post #81

Earlier quoted context omitted.

can you be sure that fabs haven't been infiltrated and masks changed between design and production in any factory, be it tsmc, samsung, glofo or intel?

The US did that in the late 70's or early 80's to the USSR and it resulted in one of the largest non nuclear explosions in history.

* allegedly

https://en.m.wikipedia.org/wiki/At_the_Abyss

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#747

We need open source hardware designs that can be built locally (where ever your local might be). This black box hardware crap has to stop. Smart people who know how all this works need to dump all their knowledge in to a design and a process. Trade secrets are keeping us not only limited in choices but exposed to bad actors who can control a link in the supply chain.

Ok, I’ll design the logo!

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#748
post #723

Earlier quoted context omitted.

Exciting, but not so ethical. We owe society to put our knowledge towards making it better for all people, not just "our team".

It's important though to make sure that your team keeps tactical advantage so that it can continue existing. Maybe someday mankind will find world peace but in our current world there are a lot of nations that hate each other still and wouldn't hesitate to take advantage of weaknesses of other nations for personal gain.

It's equally important to question your "team".

In the developed world, hatred is often manufactured to gain power... The leaders of a nation can cause more harm in their quest for glory than the average citizen of an opposing state.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#750
post #266

Earlier quoted context omitted.

I'd very much love to hear more stories if you have any!

We had MasterCard end-to-end test auditor on site. This is the first time ever you get to do a transaction with real transaction system with real credit card. Due to requirements we opted to have the only large meeting room to have outside our secure zone. This created an issue as we had no network access from there and in the end we decided to use slow GPRS terminal for the test. The end-to-end test starts with offl…

Impressive.

But am I wrong to have my hackles raised by a) the roll-your-own security nature of this, b) the reliance on a single developer's single stack implementation as what guarantees the integrity of the system? It seems like there are a lot of assumptions baked in.

I, too, would love to see a more detailed write-up--if there's a big idea here (almost a unikernel thought), it deserves to be shared and tried by fire.

Post reply on HN