{"id":9318,"date":"2019-10-13T06:51:05","date_gmt":"2019-10-13T10:51:05","guid":{"rendered":"http:\/\/pappp.net\/?guid=e2374e01d0f2806860c6c0e28ef8626c"},"modified":"2019-10-13T06:51:05","modified_gmt":"2019-10-13T10:51:05","slug":"planting-tiny-spy-chips-in-hardware-can-cost-as-little-as-200","status":"publish","type":"post","link":"https:\/\/pappp.net\/?p=9318","title":{"rendered":"Planting tiny spy chips in hardware can cost as little as $200"},"content":{"rendered":"<p class=\"syndicated-attribution\">Source: <a href=\"https:\/\/arstechnica.com\/?p=1584039\">Ars Technica<\/a><\/p>\n<div style=\"background-color : #fff7d5;\n\t\t\tborder-width : 1px; padding : 5px; border-style : dashed; border-color : #e7d796;margin-bottom : 1em; color : #9a8c59;\">Article note: The ongoing game of there being no evidence for that high profile Bloomberg implant article, but it being obviously not-that-hard for such a thing to happen makes for interesting theorizing and reading. \r\nI expect we'll eventually find an example in the wild, but probably not where they claimed.<\/div><div>\n<figure><img src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2016\/11\/CircuitBoard_byCarlDrougge-800x588.jpg\" alt=\"Planting tiny spy chips in hardware can cost as little as $200\" referrerpolicy=\"no-referrer\"\/><p><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2016\/11\/CircuitBoard_byCarlDrougge.jpg\" rel=\"noopener noreferrer\" >Enlarge<\/a> (credit: <a rel=\"noopener noreferrer\" href=\"https:\/\/www.flickr.com\/photos\/drougge\/\" >Carl Drougge<\/a>)<\/p>  <\/figure><div><a name=\"page-1\"><\/a><\/div>\n<p>More than a year has passed since <em>Bloomberg Businessweek<\/em> grabbed the lapels of the cybersecurity world with a bombshell claim: that Supermicro motherboards in servers used by major tech firms, including Apple and Amazon, <a href=\"https:\/\/www.bloomberg.com\/news\/features\/2018-10-04\/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies\" rel=\"noopener noreferrer\" >had been stealthily implanted with a chip the size of a rice grain<\/a> that allowed Chinese hackers to spy deep into those networks. <a href=\"https:\/\/www.reuters.com\/article\/us-china-cyber\/apple-amazon-deny-bloomberg-report-on-chinese-hardware-attack-idUSKCN1ME19J\" rel=\"noopener noreferrer\" >Apple, Amazon, and Supermicro<\/a> all vehemently denied the report. The <a href=\"https:\/\/www.cyberscoop.com\/rob-joyce-bloomberg-story-supply-chain\" rel=\"noopener noreferrer\" >National Security Agency dismissed it<\/a> as a false alarm. The Defcon hacker conference awarded it <a href=\"https:\/\/pwnies.com\/winners\/\" rel=\"noopener noreferrer\" >two Pwnie Awards<\/a>, for \"most overhyped bug\" and \"most epic fail.\" And no follow-up reporting has yet affirmed its central premise.<\/p>\n<p>But even as the facts of that story remain unconfirmed, the security community has warned that <a href=\"https:\/\/www.wired.com\/story\/supply-chain-hacks-cybersecurity-worst-case-scenario\/\" rel=\"noopener noreferrer\" >the <em>possibility<\/em> of the supply chain attacks it describes is all too real<\/a>. The NSA, after all, has been <a href=\"https:\/\/theintercept.com\/2019\/01\/24\/computer-supply-chain-attacks\/\" rel=\"noopener noreferrer\" >doing something like it for years, according to the leaks of whistle-blower Edward Snowden<\/a>. Now researchers have gone further, showing just how easily and cheaply a tiny, tough-to-detect spy chip could be planted in a company's hardware supply chain. And one of them has demonstrated that it doesn't even require a state-sponsored spy agency to pull it off&mdash;just a motivated hardware hacker with the right access and as little as $200 worth of equipment.<\/p>\n<p><\/p>\n<\/div><p><a href=\"https:\/\/arstechnica.com\/?p=1584039#p3\" rel=\"noopener noreferrer\" >Read 14 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1584039&amp;comments=1\" rel=\"noopener noreferrer\" >Comments<\/a><\/p><div>\n<a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=kKM9KvCTUA4:0Y0-qQTGA-s:V_sGLiPBpWU\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?i=kKM9KvCTUA4:0Y0-qQTGA-s:V_sGLiPBpWU\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=kKM9KvCTUA4:0Y0-qQTGA-s:F7zBnMyn0Lo\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?i=kKM9KvCTUA4:0Y0-qQTGA-s:F7zBnMyn0Lo\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=kKM9KvCTUA4:0Y0-qQTGA-s:qj6IDK7rITs\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?d=qj6IDK7rITs\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a> <a href=\"http:\/\/feeds.arstechnica.com\/~ff\/arstechnica\/index?a=kKM9KvCTUA4:0Y0-qQTGA-s:yIl2AUoC8zA\" rel=\"noopener noreferrer\" ><img src=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?d=yIl2AUoC8zA\" border=\"0\" referrerpolicy=\"no-referrer\"\/><\/a>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Carl Drougge)<br \/>\nMore than a year has passed since Bloomberg Businessweek grabbed &#8230;<\/p>\n<p> <a href=\"https:\/\/pappp.net\/?p=9318\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[226],"tags":[],"class_list":["post-9318","post","type-post","status-publish","format-standard","hentry","category-news-2"],"_links":{"self":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/9318","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9318"}],"version-history":[{"count":0,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/9318\/revisions"}],"wp:attachment":[{"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}