Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

811–818 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#811
post #239

Earlier quoted context omitted.

> Modern ASICs are so complex that I'm sure that sneaking a tiny backdoor into the behemoth that's a modern CPU or embedded SoC would be almost trivial. I suspect putting in a backdoor would be difficult because they are complex. Wouldn’t it be far too easy for the backdoor to inadvertently cause reliability or performance issues? And the bug would have to be useful enough to warrant potentially destroying the semico…

Nobody cares about your wild, uneducated speculation.

Please be civil here.

https://news.ycombinator.com/newsguidelines.html

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#812

Earlier quoted context omitted.

This. I've even had an in-law say, "My brother works for the Defense Intelligence Agency, and he uses smart devices in his home, so they must be safe!", with no consideration that tech may not be his specialty, or he doesn't follow the daily IoT fiascos, or maybe he just thinks he won't get hacked. Dunno. Meanwhile, my year-old thermostat still wants me to connect it to wi-fi, and that will never happen.

Wait, can you use a Nest without connecting it to the internet?

Dunno - my thermostat is not a Nest. Works great without the internet.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#813
post #691
post #650

Earlier quoted context omitted.

Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's.

> Not really familliar with PCI DSS but it might be that the card-readers/terminals aren't PCI-compliant if opened? So not the manufacturer's issue but the customer's. I think that's the case. The EEV Blog guy did a teardown of and old one once and pointed out the numerous tamper-detection features that would clear the device if opened. However, if I were the customer here, I'd tell the supplier that from that point…

PCI DSS allows for "Mitigating Controls" if you need to deviate from specified requirements, provided it is well documented and is equal to or greater in security. Doing teardowns to review circumspect hardware, and applying one's own tamper protection deal (and with accompanying documentation and tracking/logged information) would very likely be sufficient to maintain complaince.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#814

Earlier quoted context omitted.

You can be as sarcastic as you want, but these stories are absolutely indicative of a much larger problem. It might be beyond the capacity of one company to fix, but in the aggregate they represent a serious political and economic threat and need to be dealt with one way or another. Preferably by literally anyone other than Donald Trump.

Speaking as someone who is _not_ a citizen of the USA and is well aware of his issues, he seems to be first US President who actually appears to have the guts to do something about it. I doubt an establishment politician would ever have imposed tariffs on 200 billion dollars of China imports.

If he stuck to just China I would agree. But by trying to change up numerous different agreements, he lost the goodwill needed to have a collective crackdown on China. Even if he is the first to be willing to pick these sort of battles in a long while, he has a new issue of picking too many battles. Seems like a Goldilocks problem.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#815
post #436

Earlier quoted context omitted.

>Counterpoint: even if we ignored the fact that you cannot possibly produce the volumes of chips necessary at the price necessary in your country rather than in "we don't have to acknowledge all the human rights violations" countries, why would you believe this problem goes away if chip manufacturing were done in your own country, rather than another? It's certainly easier to enforce laws and observe manufacturing pr…

Not really, no. Why do you think it be easier to police? In concrete terms: who do you expect to do the policing? Because this is the kind of work that requires an expert, to catch an expert, messing with a product created by people 100% ignorant of _what_ they're making. Just _that_ they're making them. Where are you going find enough experts to check the work of even a single production line?

Because "thousands of miles away in a country that actively encourages IP theft and other wrongdoings". It makes perfect sense. If you don't think that, try to run any business in another country. It's just obvious that it would be easier to do domestically. You just list other set of problems. Those problems only get compounded if we'are talking about another country.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#816
post #422

Earlier quoted context omitted.

It does. I've deployed systems that would not only notify staff when novel packets were observed but immediately isolate anomalous hardware through a combination of powerdown and network fabric reconfiguration.

The amount of false positives a system like that would generate would rapidly render such a system entirely unusable.

He was the "first employee and architect @ Kraken (2011-2015)". That might explain why Kraken spews out 502s all the time.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#817
post #191

Earlier quoted context omitted.

This article is more or less total bullshit. At _best_ that device might be a mechanism to cause failure intentionally. And there are tons of ways to detect it with commodity technology, and plenty of vendors who implement that technology for assembly manufactures commercially.

That’s what I thought but then it says it’s hooked to the BMC bus. It’s basically a small IME device with no java bloatware to run. I’d think it’s reasonably credible

My issue isn't whether or not it's possible for hardware to be insecure or whether or not it's possible for exploits to exist.

My issue is this Chinese undetectable super chip creating unpreventable wide-scale vulnerabilities.

For what it's worth, I've worked in hardware security and I own a hardware quality control startup.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#818
post #816
post #422

Earlier quoted context omitted.

The amount of false positives a system like that would generate would rapidly render such a system entirely unusable.

He was the "first employee and architect @ Kraken (2011-2015)". That might explain why Kraken spews out 502s all the time.

Dear snarky anonymous coward, as stated I left in 2015. I think you will find referenced issues occurred subsequent to that date under very different technical leadership.
Post reply on HN