Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

791–800 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#792

Earlier quoted context omitted.

A good read is 'Poorly Made in China'. The product is different, but the problems are the same. * They drop changes and problems at the last minute, so you're over a barrel with your customers. * Relationships take months, maybe years to build. Switching suppliers is a long and costly exercise. * Often suppliers themselves are in communication, so your attempt to build a new relationship is scuppered by your current…

> * Are you going to admit to your customers and bosses that your products were faulty and you knew? If you can't answer that with a yes, maybe you don't have the backbone to work in anything critical. When you discover a fault in something, particularly a fault that might hurt someone, you have a moral obligation to speak up. To do otherwise is cowardice. Failure to speak up when we see shit is how stuff like the VW…

I think you’re right about the value of Made in America and societies where honesty (even about problems or risks) is valued.

The book I referenced included a number of instances where factories actively undermined individuals so that they had very little choice than to either go along with the situation, or press the ‘nuclear’ button and scupper the entire arrangement, including their own livelihood and career. That’s a tough choice for people to make.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#793
post #422

Earlier quoted context omitted.

The amount of false positives a system like that would generate would rapidly render such a system entirely unusable.

Not in a secure environment... where you are supposed to control the hardware, the software, and the network absolutely.

The only way to create such an environment is to totally disconnect it from the outside world -- I'm talking even power source, phones, internet, all of it has to be disconnected or else I can exfil data all day long and nobody would ever know.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#794
post #213

Earlier quoted context omitted.

It seems like many people take communist-like propaganda at face value. The Chinese government would like to have almost-complete control. The Chinese government publicly says it has high levels of control. But when they can't effectively regulate their medical (mass HIV infection from blood plasma needle reuse), food (tainted milk), or chemical (unlicensed mass CFC production) industries... reality seems to differ.

So, suppose you're Supermicro. When some CPC official comes around to tell you to make your technology a little easier for the intelligence department to access, you're going to do it. Companies in China (especially those in the tech sector) have to keep close ties to the government, and most of their leaders are members are of the party. You don't GET to be a multi-billion dollar tech company* in China without toein…

I see your *, so I assume you do know SuperMicro is a US company? And that the breaches reportedly happened at local Chinese subcontractors?

Everything you say seems to be valid for Chinese companies. Which SuperMicro... isn't.

If they want to start auditing their incoming supply from China more closely, or even shift production elsewhere, there's nothing except cost stopping them from doing so.

And the rub is that any competitor also using Chinese supply (for cost savings) is vulnerable to the same attack. SuperMicro was presumably targeted because of their size and global customers.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#796

Earlier quoted context omitted.

So not a single source. Might as well be going to war over invisible weapons of mass destruction. Also, Apple and Amazon both has said they do not agree with these claims. So far this is nothing more than propaganda.

Are you saying Bloomberg made the sources up, or that they exist but are all lying, because they won't go on the record?

Def possible they are lying. There are a lot of companies competing with white box manufacturers. If you can't name a single source, and you have two major companies saying these claims aren't accurate... then maybe you should hold off before making judgments.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#797
post #712

Earlier quoted context omitted.

So not a single source. Might as well be going to war over invisible weapons of mass destruction. Also, Apple and Amazon both has said they do not agree with these claims. So far this is nothing more than propaganda.

so you prefer to believe official corporate statements saying they didn’t have security leaks, rather than a news agency with 17 independent sources confirming they had ?? That’s an interesting choice.

17 independent sources doesn't mean anything. Again, this is the same as the sources that said their were weapons of mass destruction in Iraq. Companies and government use propaganda all the time, so until you have more information confirming these claims, then it is best to hold off before trying to say that Apple and Amazon denying the claims str proof that they are real.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#799
post #794

Earlier quoted context omitted.

So, suppose you're Supermicro. When some CPC official comes around to tell you to make your technology a little easier for the intelligence department to access, you're going to do it. Companies in China (especially those in the tech sector) have to keep close ties to the government, and most of their leaders are members are of the party. You don't GET to be a multi-billion dollar tech company* in China without toein…

I see your *, so I assume you do know SuperMicro is a US company? And that the breaches reportedly happened at local Chinese subcontractors? Everything you say seems to be valid for Chinese companies. Which SuperMicro... isn't. If they want to start auditing their incoming supply from China more closely, or even shift production elsewhere, there's nothing except cost stopping them from doing so. And the rub is that a…

Apple is not Apple Inc. in China, it is Apple Computer Trading (Shanghai) Co., Ltd. SuperMicro will have its own subsidiary/subcontractors to handle their operations in China.

As having worked for a subsidiary of a large multinational company in China, I can tell you that a lot goes on that you might find surprising. Middle management and those involved with establishing the deals with subcontractors would often have arrangements to make money through various means, such as through IP transfer or property theft. The subcontractors themselves are Chinese companies.

At our place a lot of shady things were going on and were, thankfully, found after a number of years. The global HQ had to step in and fire around 1/3 of employees working at the China branch.

Now, there is no reason to suggest that this was related to any government policy or request. But it should be clear by now that the CPC are not exactly opposed to shady things happening to foreign companies. My point is that this is an an environment where something like this can happen quite easily, especially when a lot of technology companies have close ties to the state.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#800

So the chip shown in the article looks like a typical SMD balun, it is a type of transformer used to adapt impedance between two transmission line. It’s designed to replace a series a lumped element (capacitor, inductors, resistors) normally used for impedance adaptation (in a T or Pi network). The most common used for the device is directly between an antenna an a RF front-end to serve as an antenna tuner. Technical…

It does look like a balun which is clever but based on the pinout I think it is meant to intercept SPI flash and patch it as needed.

Looks like I was correct. This image from Bloomberg article seems to indicate SPI flash (https://twitter.com/jamesdotcuff/status/1048221163607007233)
Post reply on HN