Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

1–10 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#2
> Nested on the servers’ motherboards, the testers found a tiny microchip, not much bigger than a grain of rice, that wasn’t part of the boards’ original design.

> During the ensuing top-secret probe, which remains open more than three years later, investigators determined that the chips allowed the attackers to create a stealth doorway into any network that included the altered machines. Multiple people familiar with the matter say investigators found that the chips had been inserted at factories run by manufacturing subcontractors in China.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#3
Is there an article that describes a bit more in detail what the chips actually did (or were capable of doing)? They only say "the microchip altered the operating system’s core so it could accept modifications.", which I might interpret as circumventing signature checks to allow installing modified firmware on the systems? But how does the chip connect to the network and how does it receive commands?

That said, it's pretty scary that you can hide so much malicious functionality in such a small device, makes me wonder what might be hidden in my Lenovo. In any case it speaks highly of the auditing firm that they were able to locate this. I wonder if they performed an x-ray analysis of the board, as given the size of these chips it should be possible to embed such devices in one of the internal layers of the board as well, making them essentially invisible to optical inspection.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#5
The denials by Amazon, Apple, Supermicro and the Chinese Ministry of Foreign Affairs [1] are relatively pro forma, both directed by respective nation states involved in this matter. One of the reporters interviewed on Bloomberg noted Amazon and Apple could be directed by US national security interests to deny to protect the ongoing US investigation. Supermicro could similarly be directed by Chinese national security interests to protect plausible deniability.

There was a sense of realpolitik by one UK guest commentator on Bloomberg, comments along the lines of "hey, spying happens since time immemorial, put on some big boy pants, yes there is shock but not horror when the Snowden revelations came out, the US does it, too, etc.". I disagree with this sentiment, as while the attack was quite targeted, it puts into question a quite large supply chain network.

Kudos to Bloomberg putting in the 12+ month investigative journalism to pull off this scoop. Yet another validation of the reasons I subscribe to listening/watching them.

[1] https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#8
Fascinating. A company I used to work for dismissed this sort of situation as a problem and ended up using SuperMicro boards in a security crucial product. Their hardware has always been notably very crappy, with the IPMI interface defaulting to world-open unsafe parameters, but I'd not expected it to be this cleverly hardware backdoored. It's possible to neuter Intel ME, but that's only a small comfort with these motherboards.
Post reply on HN