Chinese spies had acces to Dutch chip maker NXP's systems for over two years
nltimes.nl
nltimes.nl
How do you change the phone number without access to the phone authenticator in the first place?
>states that the hackers caused no material damage, but did steal intellectual property
I wonder what valuable IP they could have gotten, as last time I interacted with them, they had their hardware design files on airgapped networks for which you needed a second laptop to access and had no internet connection or open USB ports making hacking impossible. But that was a long time ago.
Intel Management Engine - https://en.wikipedia.org/wiki/Intel_Management_Engine
"Several weaknesses have been found in the ME. On May 1, 2017, Intel confirmed a Remote Elevation of Privilege bug (SA-00075) in its Management Technology.[36] Every Intel platform with provisioned Intel Standard Manageability, Active Management Technology, or Small Business Technology, from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME"
https://www.intel.com/content/www/us/en/developer/tools/in-b...
1- "...The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off..."
2- The Intel Management Engine is the remote privilege escalation.(Read on the known and unpublished vulnerabilities).
3- Over-the-Air Firmware Updates...
If I say more we both will end on a secure facility.
Mate I feel like you're getting your security know-how from watching Mission Impossible.
"Over-the-Air" doesn't actually mean you can magically beam SW updates wirelessly through the air to the Intel chip like in the hacker/spy movies, as airgapped networks, as per name, don't have wireless cards.
Intel ME still requires a network connection to the internet/network from which you want to apply the update. If you're on an airgapped network this becomes impossible to do without first breaching the airgapped network physicality, but this is not what happened according to the article, they just compromised some employee Microsoft/O365 account which is on the less secure network anyway and probably stole whatever IP they could find shared through the e-mail accounts and on Sharepoint.
If you have a wireless card then your system was never airgapped to begin with. Parent makes some wild confusions.
Is dismounting your Motherboard what you mean by not having a card?
That's just the wireless controller on the chip but its not enough to have wireless communication actually work. You still need a wireless PHY which modulates the digital signal into radio waves, and an antennae attached to actually have wifi. On it's on it does nothing, it's just a piece of silicon that can't achieve radio communication.
"AIR-FI: Generating Covert Wi-Fi Signals from Air-Gapped Computers" - https://arxiv.org/abs/2012.06884
"In this paper, we show that attackers can exfiltrate data from air-gapped computers via Wi-Fi signals. Malware in a compromised air-gapped computer can generate signals in the Wi-Fi frequency bands. The signals are generated through the memory buses - no special hardware is required."
The notion that I am going to establish any kind of foothold in your system that's properly air gapped via TEMPEST is silly.
But, more importantly, the IME needs to be able to receive a signal to update, not transmit.
And to the IoT reference - such a computer wouldn't be (or rather shouldn't be) regarded as airgapped.
If you do add an antenna to your 'airgapped' computer, well, just don't.
Is there a third way?
Not via the processes discussed in the article.
You can contact the phone company if using a cellphone (i.e. transfer the phone number to a new sim)
When my phone was stolen a few weeks ago, I tried to transfer my phone number to a different company but they wouldnt let me... they told me all I had to do was buy a sim card from the same company. Security is a joke (also physical security).
Not just one, several: Russia, Israel, Iran, North Korea, even the US used NSA to hack into Airbus and Siemens while UK used GCHQ to hack into Gemalto, basically every country which has the technical capabilities will try to do that.
China is the proeminent one because it's the west's largest economic adversary and because they actually use the stolen IP to make their own bootlegs and not just for security and intelligence like the other nation states.
They can just pay off someone in security or IT and there you go.
They don't seem to have done this here but they will if they don't get in another way. I'm sure. What we call insider threat is basically every spy agency's MO since history began.
I mean maybe. A lot of Europeans seem pretty confused about ASML.
And for everyone who also hadn't heard about this: https://money.usnews.com/investing/news/articles/2023-10-24/...
> AMSTERDAM (Reuters) - Several Dutch lawmakers on Tuesday challenged the Netherlands' Trade Minister over whether the U.S. has acted correctly in unilaterally imposing new rules regulating the export to China of another chipmaking machine made by ASML Holding.
"Leaked documents show connections between PVV and Russia" - https://nltimes.nl/2023/10/19/leaked-documents-show-connecti...
[1] https://nltimes.nl/2023/11/27/cabinet-formation-leader-resig...
A secure system for sharing information is basically a door with a lock. You break the lock and steal something, you have broken the law.
Law enforcement at that scale is highly asymmetrical. Large powerful countries can act like bullies because "what are you gonna do about it?".
Yeah, we have the UN and international courts and what not, but those are toothless as without a superior power to act as the enforcer, they can wipe their ass with your laws, complaint or court ruling and do as they please anyway.
However none of that implies:
> There's nothing wrong with stealing and copying.
It signals a very scary zero-sum mentality of getting ahead at any cost. But like, it's the college student who cheats on every exam... yeah you're getting good grades. Yeah you eventually figured out how to copycat the stuff. What's that worth? Is the output enough?
I do appreciate a lot though the counter view in this thread that IP is a made up fiction, that it's artificial, and that we could probably be much greater a world if we had reward mechanisms to give other than complete & total control for 20+ years.
The only solution is tit for tat damages.