Setting the Record Straight on Bloomberg BusinessWeek’s Erroneous Article
aws.amazon.com
aws.amazon.com
-"and we fixed all critical issues before the acquisition closed" - How can you fix issues when the acquiring party is not yet under your control?
-"We further strengthen our security posture by implementing our own hardware designs for critical components such as processors [...]" - Own processor design by Amazon? They have the Alpine ARM-processor, but that type of processor is not the type of processor that runs on the allegedly compromised motherboards.
-What is Amazon exactly responding to? Amazon denies knowing of the hack ("was aware of") when acquiring the company. That's the same denial as in the BB article. But the main point in the BB-article is that is was Amazon that found out about the hack and notified US government. That doesn't mention any knowledge before the deal was struck? Only Apple clearly denies ever having found a malicious chip.
The Bloomberg-article just seems to well-sourced to be that easily denied. Not sure what kind of communication would be acceptable for Amazon and their law enforcement partners they are (still, according to BB) working with.
Surely, organizations that don't have anything to hide are talking a peek by now.
If there aren't a lot of reports of these hacks in the wild in the next couple of days... then we'll know who's not telling the truth, right?
I find it extremely hard to believe that uncle Sam would let a state sponsored espionage of this scale silently continue for 3 years without warning the public and cut off the pipe.
If the alleged hacking were true, wouldn't it be 100x more important to stop the spyware immediately than collecting comprehensive evidence on who's behind it? At the end of the day, it's not like U.S. would start a nuclear war against China if the allegation is proven true.
Does this imply that they are checking every piece of hardware that goes into a data center including looking at it for any additional or replaced malicious components?