Bloomberg’s chip story reveals murky world of national security reporting
techcrunch.com
techcrunch.com
I remember the furor on HN at the time, and to my recollection a lot of the allegations were about backdoors for the NSA into their data and such, and that's what the companies denied.
Looking at Google's statement[1] of the time, I'm not sure I can find any fault with it?
To me, the big revelations from Snowden were about the NSA capturing all data on the internet backbone, and tapping unencrypted links inside Google's network without their knowledge.
[0] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
It’s a bad world, everyone is at it, nobody can be trusted blindly.
An official cited anonymously by Bloomberg said the supply chain-level breach affected almost 30 companies, including Amazon Web Services and Apple.
In a statement published Thursday, Apple denied the Bloomberg report, claiming malicious chips were never uncovered.
"We are deeply disappointed that in their dealings with us, Bloomberg’s reporters have not been open to the possibility that they or their sources might be wrong or misinformed," read Apple's statement.
Amazon called the report "erroneous" in a blog post published Thursday. "At no time, past or present, have we ever found any issues relating to modified hardware or malicious chips in Super Micro motherboards in any Elemental or Amazon systems," the company said.
In a statement released Thursday, Bloomberg News said the story required more than a year of reporting and more than 100 interviews. They also said 17 individual sources confirmed the manipulated hardware."
"Our best guess is that they are confusing their story with a previously-reported 2016 incident in which we discovered an infected driver on a single Super Micro server in one of our labs. That one-time event was determined to be accidental and not a targeted attack against Apple."
Compare this to statement issued by Apple in 2017 when queried about the 2016 story:
"Apple is deeply committed to protecting the privacy and security of our customers and the data we store. We are constantly monitoring for any attacks on our systems, working closely with vendors and regularly checking equipment for malware. We’re not aware of any data being transmitted to an unauthorized party nor was any infected firmware found on the servers purchased from this vendor."
(taken from https://arstechnica.com/information-technology/2017/02/apple...)
While their 2017 denial was technically correct (it was an infected driver and not infected firmware) it's still a serious red flag on their credibility on these matters.
So if you assume that their current denial is technically correct, what loop hole is there in it? Because they seem to have covered all the bases.
"Apple never had any contact with the FBI or any other agency about such an incident." This holds true if private 3rd party was handling the incident.
"We are not aware of any investigation by the FBI, nor are our contacts in law enforcement." This is meaningless it might not be FBI them not being aware doesn't mean there is no investigation and so on.
Also, I don't think I'd accept the claim that "Apple has never found" is telling the truth if it was a 3rd party that found it. Because if a 3rd party informs Apple, that report right there constitutes Apple finding it.
The nsa were signals intelligence first, but their civilian mandate had (has) to do with protecting national interests in the "signaling" world (ie: the Internet etc). Arguably they were never very good at that... ("Snowden", "crypto backdoor"...).
But I believe "cyberspace" is now accepted as an actual thing, and so falls naturally under the FBI (cross border, spying on us soil) and police ("crime").
For example if the exploit was found on the motherboard prior to it being deployed in servers that would be consistent with Apple's denial (not suggesting that's what happened here, but more as an illustration of how Apple being specific actually leaves more wiggle room than broad statements).
I could be wrong. But we had previously paranoia about Japanese corporate spying 40 years ago.
On the other hand, "vehemently deny this or our business relationship will be soured" is exactly what you would expect from China on this. It's not as if censorship isn't in their playbook or putting a lid on this isn't in their interest.
It would be very disappointing to see US companies cowed by something like that, but it's not as if US companies knuckling under to China's censorship requirements is without precedent.
http://www.abc.net.au/news/2018-06-04/qantas-to-refer-to-tai...
Several American airlines (Delta, American, United, Hawaiian) agreed to comply:
https://www.bloomberg.com/news/articles/2018-07-24/u-s-airli...
* The Register's analysis https://www.theregister.co.uk/2018/10/04/supermicro_bloomber... (https://news.ycombinator.com/item?id=18146307)
* Joe FitzPatrick's analysis https://securinghardware.com/articles/hardware-implants/ (https://news.ycombinator.com/item?id=18144538)
Maybe it doesn't matter if these chips were implanted in the particular boards that they're alleged to have been in. No one is suggesting that this would be technically infeasible, so you can bet the PLA has planted them somewhere. I would, if I was defending China against Trump.
[1] That drunken Christmas party excepted.
I think this may be key in this case, which would give plausible deniability to Apple and Amazon. Conversely, I'm also not fully convinced by this argument, I think it applies more easily and more often when companies are directly subpoanaed by authorities not when there are the initiator. In the case of this kind of breach if one engineer find this issue I would think it would report to senior management first, before contacting the authorities. Also Apple directly stated there are not constrained by any gag order, which leave only one possibility if they genuinely think what they say is true: could it be an unkown unknown?
I’d be surprised if Justice Department guidelines allow completely going behind the back of the executives of a domestic public company, at least unless they are suspected.
How many days can this go on without _SOME_ report of these things after such a ball-buster story?
It doesn't make sense that no one has produced at least a picture of one. Why the need for secrecy here? It's not like the US govt made the chip, right? Right? RIGHT?
Even worse, feeding reporters false information is not that difficult. Given the scarcity of sources, it must be extremely difficult to get technically knowledgeable people who will corroborate these kinds of stories.
Consider who wins the most if the chip story turns out to be false: an administration hell-bent on reshoring US manufacturing capability.
Whether the story is true or part of some domestic propaganda operation, the result isn't good for the US.
This got me thinking, why plant a chip? I mean, it's hard to make, and will almost certainly be caught.
Imagine reading this after the Snowden leaks:
Today’s bombshell Guardian story has the internet split: either the story is right, and the biggest Silicon Valley companies are giving the NSA access to their data… or it’s not, and a lot of people screwed up.
The report contains elements are are near impossible, and has other aspects that are very unlikely.
It has also been denied far more strongly than the Snowden leaks were.
The biggest problem is really why would you do this? Either the report is wrong in significant ways, or it’s not true at all.
The chip they show in the article, is a ceramic package which it would be really hard to embed a semiconductor in (because of the temperatures required to fire the ceramic). It looks like it probably would sit on an alternate footprint for the BCM flash. A ceramic part like that (which they say is for signal conditioning) doesn’t belong at that location anyway.
If your going to develop some weird SMD capacitor sized package for a microcontroller... why not just develop a new BCM serial flash chip embedding the same functionally? At least that way the boards would look visually similar.
So much just doesn’t make sense to me.
My understanding is that there wasn’t involvement from google, that data was extracted without their knowledge from links between data centers.
EDIT: to the downvoters, its easy to play this game, Apple makes a large amount of very specific denials.
Each time, we have conducted rigorous internal
investigations based on their inquiries and each
time we have found absolutely no evidence to support
any of them.
Apple has never found malicious chips, “hardware
manipulations” or vulnerabilities purposely planted
in any server. Apple never had any contact with the FBI
or any other agency about such an incident. We are not
aware of any investigation by the FBI, nor are our
contacts in law enforcement.
What about investigations and law enforcement contacts via a third party (perhaps a specialized hardware security firm? ) Our best guess is that they are confusing their story
with a previously-reported 2016 incident in which we
discovered an infected driver on a single Super Micro
server in one of our labs.
You mean the story they explicitly denied with similar strength (and wiggle room to boot when the truth came out) Apple is deeply committed to protecting the privacy and
security of our customers and the data we store. We are
constantly monitoring for any attacks on our systems,
working closely with vendors and regularly checking
equipment for malware. We’re not aware of any data being
transmitted to an unauthorized party nor was any
infected firmware found on the servers purchased from
this vendor.
https://arstechnica.com/information-technology/2017/02/apple...Bloomberg is an upstart with an awkward funding model which has already faced serious, credible allegations of political interference and a lack of journalistic integrity (a major investigative story about corruption in China was allegedly spiked at a late stage by management for business reasons).
After the Xi story appeared, terminal sales in China slowed because government officials ordered state enterprises not to subscribe. The Bloomberg News website was also blocked on Chinese servers, and the company was unable to get visas for journalists it wanted to send to China.
In 2014, Grauer told staff at the Bloomberg Hong Kong bureau that the company's sales team had done a "heroic job" of mending relations with Chinese officials who had indicated their displeasure about publication of the Xi revelations. He also warned that if Bloomberg "were to do anything like" the Xi story again, the company would "be straight back in the shit-box."
On October 29, 2013, during a conference call, Winkler told four Bloomberg journalists in Hong Kong that the findings of their major investigation into "the hidden financial ties between one of the wealthiest men in China and the families of top Chinese leaders" would not be published. Less than a week later, a second planned article "about the children of senior Chinese officials employed by foreign banks," was also killed, according to Bloomberg employees
Was that off-the-record for the story? Or delibrately omitted? It seems unlikely they are part of the intelligence community so protected in any way; they're in another country and they must be somewhat known in the DC industry if Amazon used them commercially.
See eg. some silicon analysis on the iPhone 7 http://www.techinsights.com/about-techinsights/overview/blog...
I'm very interested to see where this goes. I hope we get to find out who is full or crap on this. Either Bloomberg got seriously played (I'm assuming they wouldn't just make up stuff for a good story or report based on sources that didn't appear credible) or Apple and Amazon are lying fearlessly and in great detail. This doesn't seem like the prism situation where it was pretty easy to reconcile the company PR statements with the snowden leaks.
A Defence spokesperson said the department was "aware of recent media reporting involving the unauthorised implantation of microchips within servers, used by United States corporations, in the production of Supermicro microchips".
"Defence will continue to work with the ACSC [Australian Cyber Security Centre] to continue to monitor the situation," the spokesperson said.
And from the Bureau of Meteorology:
The Bureau of Meteorology said it does not comment on security matters.
[1] http://www.abc.net.au/news/science/2018-10-05/supermicro-mal...
People lose trust to companies like Apple or Amazon if they lie. Bloomberg though? Nope, everything would just continue as normal. And Bloomberg is not even that bad. We just got used to bad journalism.
Either they can show an xray of a motherboard showing the chip, and can further explain how it exfiltrates data, or their story is rumour and bullshit, and they should be culpable for Supermicro's stock drop.
It's just that simple, and I'm calling them on it.
I'm waiting for another news outlet to bring more information. Additional sources will come forward and more reporting on this story will only get us closer to the truth.
So let's have some facts. Like an x-ray.
https://www.reuters.com/article/us-china-cyber-britain/uk-cy...
IMHO, this is a very big aspect and companies lie all the time. Even if this came out to be false, they don't get as much heat as they would get now.
Is the PR of fortune 500 companies bound to tell the truth always?
I'm a capitalist, but I cannot deny that it is in the best interest of companies to hide and deny negative news.