Intel Warned Chinese Companies of Chip Flaws Before U.S. Government
wsj.com
wsj.com
Doesn't that mean that it is a “near certainty” that the U.S. Government was aware of it, because authorities (NSA, etc) routinely monitor all such communications?
I think you mean "overtly mandatory" in China's case.
The overt, pervasive mandatoriness of the Chinese system is another ballgame entirely.
If the Chinese gov't shows up and asks for basically anything, of course you give it. There is no questions, no lawyers. It is how things are done.
US tech companies do have lawyers and fight back at some stuff. Think about all those defamation cases where people try to sue Twitter to get the identities of people criticizing them.
How do you think that works in the Chinese social environment?
Technical issues are a bit different though. Australian intelligence does not have rooms in any AT&T building I think. Though perhaps they perform some legal tricks to give them access and then roundtrip the info.
I hope they at least feel bad doing so.
It is entirely possible that without being told neither government could have become aware of this in spite of having the communications that could make them aware if only someone read them. It's also entirely possible that the Chinese government became aware from being told by folks at those Chinese companies who received disclosures, and that the U.S. government wasn't. Eventually we might find out what the actual situation was.
From a purely legal and policy standpoint, the linked report is concerning. One would think that Intel ought to be aware of the national security implications of Meltdown/Spectre and should have alerted someone in the U.S. government, though they're probably not obligated to. And, of course, what if Intel had not be an American company?
The mitigations required OEMs to send firmware, microcode, and software updates.
They could shut down machines for which it is an excessive risk; though honestly I don't think they should be privileged as customers go.
Also, with all we know about the NSA, I'll be very surprised if the U.S. government didn't already knew and if they did, didn't try to take advantage of it.
I.e. an order (with due legal process) by USA government to not disclose that vulnerability to any Chinese companies would be possible and binding, but not the other way around. That's what being a USA company means, no matter where your sales are.
In that case, sure, but I was talking about a voluntary disclosure, which is the case here.
If Intel explicitly does some kind of US exceptionalism explicitly, the EU, China and other governments will probably require to be aware of the vulnerabilities no later than other governments.
How could the EU possibly let Intel sell CPUs, and let Intel inform other governments of vulnerabilities first? So that the other governments have a time window to play with the vulnerability against the EU?
Any such notification to agencies that matter would be classified information.
Now given that it’s Intel, the notification may have been “Reminder that our chips are working according to spec”, but I’m sure people knew.
Edit: The only reasonable path seems to inform every government simultaneously, at the same time as the public. How could the EU possibly let Intel sell CPUs, and let Intel inform other governments of vulnerabilities first? So that the other governments have a time window to play with the vulnerability against the EU?
There is a very practical morality at play here. The Chinese government runs protesters over with tanks, imprisons people without cause, attacks their neighbors without cause, etc. Would it be a good thing to aid such a government?
Putting all governments on the same moral plane is counterproductive and nonsensical. Not providing important information to your own government so that they can secure the very systems that protect you - that doesn't seem very practical.
Oh come on, you're making it too easy!
Just as the US would blacklist intel if they told another nation directly first. (this is even true if they told allied nations) we have seen that just being allies does not stop the US spying (and I'm sure does not stop the opposite as well just turns out the others might be better at keeping things hush hush)
Therefore the patriotic and responsible thing would be to help vendors patch their stuff before directly disclosing the bug to any party that would be likely to abuse the exploit.
The NSA doesn't play ball and responsibly disclose exploits to vendors immediately after discovering and profiling them, expressly because they want to use the exploits, so why should vendors be obligated to do the reverse?
No matter who is manufacturing what, it's Intels responsibility to ensure all those who _use_ their chips know of it immediately.
That seems to imply that Intel had planned to tell the US government some time between Jan 3 and Jan 9. That seems rather late.
I think that the distros list was notified before that, and I'd be quite surprised if there aren't a couple of government agencies monitoring it.
This article doesn't seem to say when the Chinese vendors were notified.
Intel has 8 customers accounting for 75% of revenue[1].
By numbers, America and Taiwan are tied for third in terms of volume per country. Singapore is #1, followed by China.
Even for just client computing, 3 customers account for 38% of their revenue.
None are the US government[2]
[1] https://www.investopedia.com/articles/markets/100214/inside-... [2] https://www.sec.gov/Archives/edgar/data/50863/00000508631700...
June: Google reports the problem to Intel.
Soon after: Intel/Google (unclear) informs related businesses (Lenovo, Microsoft, Amazon, ARM Holdings, others?).
Jan 3: Vulnerability leaked ahead of planned Jan 9 reveal.
A 6 month window where apparently nobody informed the US Gov. I'm legitimately kinda surprised - if it were a small window, meh, but clearly they (and every other government) would have wanted an earlier warning since they'd likely be vulnerable. That's a gigantic window for the info to leak and an automated exploit to be built (just look how fast it happened when the news became public).
...but as a counterpoint, this says June in the sub-heading: https://www.wsj.com/articles/intel-wrestled-with-chip-flaws-... (though I can't find supporting info in the body)
I'd love to find something conclusive :\ seems like everyone's implying different things / nobody actually has concrete evidence or dates.
https://en.wikipedia.org/wiki/Market_share_of_personal_compu...
So... what’s the problem exactly?
https://www.itwire.com/security/81538-intel-ceo-sold-shares-...
So... a bunch of OEMs were told in November.
I just don’t understand the significance of the China angle here.
They told a bunch of OEMs and they told ARM too. So does that mean they told GCHQ? Not really.
It would be negligent NOT to tell Lenovo when they make a massive chunk of all PCs globally.
Thousands of US corporations run Lenovo computers.
And the same idea applies to businesses that are suspicious of cloud computing security issues. Of course, these are probably obvious to everyone here and it's why these flaws are a big deal, cause a lot of cpus have been sold for cloud/vm installations, now what.
After the Meltdown/Spectre fiasco with Intel I'd be willing to bet China is weighing the performance penalty of switching to Zhaoxin CPUs versus paying Intel for buggy (and potentially backdoored via IME) CPUs.
The Chinese have shown over the past decades that they're fully capable of innovating and building strong businesses in segments where they didn't previously compete (Huawei in telco, Lenovo in consumer PCs, Xiaomi in smartphones).
Given that AMD was able to come up with Zen on a shoestring budget, who can say China can't do the same? They can certainly afford to throw money at R&D.
[0] https://techreport.com/news/33018/via-joint-venture-reveals-...
Back in 1812, finished cotton textiles dominated British exports, accounting for about half of all trade revenues, the fruit of a half century of progress in mechanized mass production. Proportionate to GDP, the industry was about three times the size of the entire U.S. automobile sector today. High-speed textile manufacture was a highly advanced technology for its era, and Great Britain was as sensitive about sharing it as the United States is with advanced software and microprocessor breakthroughs. The British parliament legislated severe sanctions for transferring trade secrets, even prohibiting the emigration of skilled textile workers or machinists. But the Americans had no respect for British intellectual property protections. They had fought for independence to escape the mother country’s suffocating economic restrictions. In their eyes, British technology barriers were a pseudo-colonial ploy to force the United States to serve as a ready source of raw materials and as a captive market for low-end manufactures. While the first U.S. patent act, in 1790, specified that "any person or persons" could file a patent, it was changed in 1793 to make clear that only U.S. citizens could claim U.S. patent protection.
http://foreignpolicy.com/2012/12/06/we-were-pirates-too/
https://www.pri.org/stories/2014-02-18/us-complains-other-na...
Also, between slavery and the Native American genocide(s), I'd say the 18th-century USA may not be a great moral reference point. For that matter, China's government at that time still practiced slavery, foot binding, judicial torture, and all kinds of fun stuff. Neither would be great models for a modern state.
[0] https://en.wikipedia.org/wiki/Intellectual_property_in_China... [1] http://money.cnn.com/2017/08/14/news/economy/trump-china-tra... [2] https://www.nytimes.com/2017/08/15/opinion/china-us-intellec... [3] https://www.reuters.com/article/usa-fighter-hacking/theft-of... [4] https://www.cbsnews.com/news/60-minutes-great-brain-robbery-... [5] https://www.networkworld.com/article/2223272/cisco-subnet/60... [6] http://www.politifact.com/punditfact/statements/2016/may/17/...
Because it's profitable.
Once upon a time, Japan was perceived the way we currently perceive China : a land where cheap, flimsy knockoffs were produced. The first camera made by Canon (which is, today, the most popular camera manufacturers in many segments of photography, such as journalism) was a 100% copy of Leica designs. There was literally no innovation whatsoever, just copy of german engineering.
But once the corporations acquired the base know how, developed better quality control and started to gain popularity in the low end, they reinvested their money into R&D, and they now are one of the best brands of the market, cornering both the low end and the high end. Almost every single western camera brand died except for Leica, which survived mostly on selling brand recognition to people who have more money than sense (this is particularly true for the people who buy the idiotic non-rangefinder Leica camera that are actually made by Panasonic which are virtually identical to other panasonic lumix models and sold at a premium because there's a Leica badge).
Most well known japanese brands started like Canon.
I believe we're already starting to see the transition from 'eh, knockoff' to companies that are reinvesting in R&D in China and this is going to eat at all the markets previously corned by silicon valley giants. Good smartphones are already a commodity. I have the Honor 8, which is made by Huawei, who build their own system-on-chips like Apple and Samsung. It's still running as fast as it was on day one and I probably won't feel the need to change for something else as long as it keeps working. The only thing they need to improve on is the camera quality and if they can manage to rival top end smartphones in terms of cameras in the future they will lay waste upon Samsung. Apple might survive because like Leica they have a heavy contingent of people with more money than sense that are loyal to status symbols/veblen goods.
Not sure why I'm being downvoted, it's a perfect example of a difficult problem (creating the metal ball) taking a long time to figure out when there isn't a shortcut. It's not a value judgement, other countries have had longer to figure this stuff out.
See this bug report by Jann Horn: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
Then each of these chip makers would have notified their direct customers who make original equipment (motherboards, SoCs, Add-on card etc). Then they would have to notify their firmware/software partner/vendors who have to fix the issue.
Since this was such a serious issue and at least 2 quarterly results were posted by all these publicly traded companies, I'm sure their lawyers, their external independent risk consultants, key members of the board and key investors were also told - especially as CYA when deciding to keep it a secret while giving market guidance (which had to be knowingly false?).
Each of these disclosures would have gone with boilerplate embargo legalese (bad things will happen to you if you speak about it). But all of them would have taken actions ranging for good to bad to evil (from insider stock trading to actively looking for ways to exploit the bug for competition spying).
While all this is going on, why would government not have known about this? Wouldn't one of the government certification programs like NIST FEDRAMP mandatorily require them to be notified of any vulnerabilities monthly?
And of course, all govt spy agencies would have surely known about this vulnerability as early as July/August given the amount of cross-continent communication that would have happened on this topic. And it's a whole another matter if they used the exploit for any operational/tactical advantage for any ongoing operations or as a backdoor installation for future operations, it's anyone's guess. If they did do that, we cannot be surprised because that is definitely their job. Thinking any other way is not part of the security mindset. It's not the trust everyone kind of thinking that lead to discovery of this vulnerability in the first place.
[0] https://www.washingtonpost.com/world/national-security/the-n...
"In 2012, China consumed 33% of the world’s integrated circuits (i.e. microchips) while the US consumed only 13.5%"
[0]https://qz.com/72542/china-just-surpassed-the-us-in-semicond...
Imagine the roles being reversed. Would we care if a Chinese chip maker notified Google before the Chinese government? I'm sure nobody on HN would be complaining. That makes it look like naive American-centrism.
Assuming you were trying to make a juxtaposition though experiment — what you should be asking is “Would China’s people care if a Chinese chip maker notified the US government first of vulnerabilities in their hardware?”
I suppose in the eyes of these governments, they are.
I wonder if Intel just did it over the unsecured line, knowing that the NSA/FBI wiretaps that one...
In the reverse direction, the US has tried to sentence Chinese military members - https://www.usnews.com/news/articles/2014/05/19/chinese-mili...
It also reveals weakness in Chinese, Russian and even Venezuelan Intel-based PCs and while you may not agree that customers in these countries deserve to get notified on par with top tier U.S. customers, (questionable stance), Intel clearly does, since at this point, it is a multinational corporation with large customer base outside the U.S.