Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

751–760 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#751
post #200

Earlier quoted context omitted.

Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen: https://www.commbank.com.au/business/merchant-services/eftpo...

Clover CEO here. Won't comment on a competing device but this may not work the way you think. In Clover's approach the touch controller input isn't reaching the Application Processor running Android when in PIN entry mode. You can do patent search if you're interested.

What you're describing sounds like another backdoor of its own!

The general problem with most "industry security" approaches is that they simplistically attempt to wrestle ultimate Godmode-control for themselves, rather than working towards eliminating it.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#752

Earlier quoted context omitted.

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

> I wonder what reason Apple has to hide. The perception is that Apple is perfect and worth paying 3x the cost? EDIT: Curious if all of these Apple comments are going to disappear. I believe they have a strong marketing team to hide dissent.

This breaks the site guideline that asks you not to insinuate astroturfing or shillage without evidence. Please don't do that—it's a toxic trope that leads to dumber threads.

https://news.ycombinator.com/newsguidelines.html

Edit: looks like we've already warned you about this more than once. If you keep doing it we're going to have to ban you, so please don't post like this again. Ditto for unsubstantive comments in general.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#753

Earlier quoted context omitted.

For the folks commenting below that we should bring the manufacturing back to the US, why wouldn't the bad guys just start bribing American workers to insert the attack hardware into devices made here? It's not like Americans are somehow above being bribed.

Ignoring the abject amorality and greed that underpins Chinese culture will leave one confused like this.

Nationalistic slurs will get you banned here. Please don't stoop to that again.

https://news.ycombinator.com/newsguidelines.html

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#754

Earlier quoted context omitted.

Offshoring has its costs. It's the unknown unknowns that get you.

[flagged]

Nationalistic flamewar is not welcome here; neither are political or ideological flamewar. We ban accounts that use HN primarily for those things. Please read https://news.ycombinator.com/newsguidelines.html and follow the rules when posting here.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#755
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Was the secret service contacted? Card skimmers are a big no no. Family friend works for Dept of weights and measures and finds skimmers all the time on gas pumps. Scary stuff.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#756
post #29

Earlier quoted context omitted.

It sometimes feels like certain hardware protocols were designed to be insecure. I remember reading about IPMI issues back in 2013: https://www.itworld.com/article/2708437/security/ipmi--the-m...

"Designed to be insecure" is probably unfair to the designers of IPMI. Security was just not as big a concern as it is today.

Computer security as a field and area of concern is significantly older than IPMI.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#757

"Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not." Well played, Bloomberg. Well played.

I laughed at that line too.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#758

Earlier quoted context omitted.

Of course. Apple/Amazon can be coerced into denying this (via government requests or otherwise). Bloomberg can't, nor is there any advantage for them to publish false information.

> nor is there any advantage for them to publish false information. of course there is. It's called ad revenue and page views, both of which they're raking in today with these allegations. This story is all over the place. I don't trust Bloomberg with anything Apple at all and haven't for years now.

Here is one motivation for false information. Financial gain. Someone could have made a lot of money with put options.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#759
post #691
post #650

Earlier quoted context omitted.

Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's.

> Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's. I think that's the case. The EEV Blog guy did a teardown of and old one once and pointed out the numerous tamper-detection features that would clear the device if opened. However, if I were the customer here, I'd tell the supplier that from that point…

You all recognize the irony, right?

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#760
post #502
post #482

Earlier quoted context omitted.

How does that actually work? How far down the chain of related facts to the national security incident are parties allowed/required to lie? If facts can be used to triangulate the secret, that can't be disclosed, right? Are incidents like this like a little fact-bomb which can be used to legally hide other institutional facts under its cover?

There most likely are classified legal constructs that compel speech. You see that with the PRISM denials by Apple and Google.

s/legal/extralegal/

"Secret law" is an oxymoron.

Post reply on HN