UK cyber security agency backs Apple, Amazon China hack denials
reuters.com
reuters.com
> When [Bloomberg] asked China's foreign ministry for a response, a lot of times they'll say things like, you're crazy; we know nothing about this. Their response was a little more nuanced and contextual in the environment we're in now. Basically they said, we are a victim of these kinds of attacks, too. And, you know, they're right. The U.S. government - it's very, very good at these kinds of hardware attacks.
Supporting evidence for Bloomberg's claim: NSA interdiction of US export shipments [2].
[1] https://www.npr.org/2018/10/04/654518383/bloomberg-reporter-...
[2] https://www.theguardian.com/books/2014/may/12/glenn-greenwal...
Remember, astronauts couldn't have met aliens on the moon, if the moon landings were faked.
Now that's a debate I'd pay to watch.
Yes, you can actually buy the similar looking chip on Taobao.com by searching HHM1523C1[0] or HHM1526[1]. Some vendors even claims the chips they're selling are "Imported, 100% legit".
And, of course there can be another interpretation: We (China) bugged your server, because you (the U.S.) bugged ours first.
The water is so muddy right now, maybe wait for more information?
I didn't bring up trade wars at all, I don't think it's necessarily related (this kind of tradecraft was likely in the works for much longer than recent trade disputes).
So plain old espionage, executed for whatever the needs of the day might be.
As an aside, what do you think is draconian about such a law? It seems like there are reasonable arguments for why it would be in the national best interest to keep an ongoing investigation classified. In fact it seems like an unusually straight forward application of the cliche justification “for national security reasons.”
"Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances."
talks about Congress, not an executive branch. the latter can gag a person, or a company.
See, for example, https://en.wikipedia.org/wiki/New_York_Times_Co._v._United_S...
That would be bad enough, however the next step by the government would be to increase the fine amount, were Yahoo to hold out over time. Kick it up to $1 million per day and Yahoo would have folded no matter what. The problem is pretty straight forward: the government could push it as high as necessary to compel the result they wanted.
I don't think the U.S. government can compel companies to lie. It can, though, request them to.
If the NSA said "your servers were compromised by a state-sponsored scheme, and we'd like your co-operation in running counterintelligence operations" I think it would be fair for a company to say "yes". Particularly if part of the offer included help extracting infected hardware from said company's infrastructure.
If trustworthiness amounted for anything in today's world, all major news agencies would be out of business.
What makes you think the people denying it know about it though? E.g. if the head of Apple security got served an NSL, wouldn't that potentially prevent them from telling the company lawyers or the executive team?
HN has 5M monthly users. Obviously there isn't going to be any consistency.
If I had said something about trusting Bloomberg or the media then sure. But that’s a completely different topic that’s not even remotely related to whether Apple’s denials on potential NSL issues are reliable.
But there are definitely two (among many) strong tribes of HN-popular belief - let's call them the Gell-Mannicheans and the National Security Epistoleros. It's weird (to me) that they rarely meet in threads on stories concerning both! That could be because they live in different timezones or have different interests. It could be that the Epistoleros are just that much more numerous or that for some people epistolerism trumps gell-mannicheism. Or something else altogether. I find it a curious thing to observe and think about - it's not some underhanded 'zomg lolz, I have caught you in logic error' comment.
> That's not what you do when you're trying to brush something off.
It /could/ be what you do if good relations with the Chinese government are crucial to your business (true for both Apple and Amazon).
As for the UK NCSC, it's bizarre that they would comment at all. One possible motivation: eagerness to discover how to use such a backdoor themselves
> “The NCSC engages confidentially with security researchers and urges anybody with credible intelligence about these reports to contact us”
> Finally, in response to questions we have received from other news organizations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.
https://daringfireball.net/linked/2018/10/04/what-businesswe...
Judges aren't compilers who will faithfully follow all the rules as written down without deviation. They at specifically empowered to make decisions in light of new evidence, so why wouldn't they force companies to actively like if they are already adding exceptions to the first amendment?
This is a pretty mild statement, would not say it backs Apple and Amazon.
"Defence will continue to work with the ACSC [Australian Cyber Security Centre] to continue to monitor the situation," the spokesperson said.
http://www.abc.net.au/news/science/2018-10-05/supermicro-mal...
"We have no reason to doubt" is not a weasel statement. "At this stage" is a weasel statement, but only in the sense that it means "We haven't investigated this or seen any evidence ourselves, and until we do we'll go with the line taken by Apple and AWS."
This can be taken as meaning "The US has given us details and asked us to deny them" - which makes no sense, IMO.
Or "The US has given us no details" - which is rather more likely.
Even if taken at face value, it can only mean 2 things. 1. They already, thouroughly investigated it (draw your own conclusions what they found or any involvement) or 2. They just issued an official statement without possibly having the time to investigate the merits of the accusation. This not only doesn't pass the sniff test, its evidince of yet another turd on our lawn.
Chances are, American intelligence has been running counterintelligence operations through this network. That leaves lots of people in American intelligence who would prefer this remain a secret, without a similar restriction elsewhere.
Re: 1, if they investigated it then that means that "it" was something in the first place thus warranting the investigation.
Re: 2, that's the kind of thing you do when you need to inject uncertainty into the situation to buy yourself or your buddies time to tie up loose ends/burn evidence/figure out what story they'll tell the politicians.
a) officially deny anything happend
b) unofficially shift the blame to China
Whatever happens, my popcorn is ready.
"Nothing to see here - move along!" while thinking of a new means to hide this stuff in the server hardware...
“We are aware of the media reports but at this stage have no reason to doubt the detailed assessments made by AWS and Apple,” "The NCSC engages confidentially with security researchers and urges anybody with credible intelligence about these reports to contact us"
This is not backing.
Detecting such attempts on a brand new system would spur them to identify the source. They’d have found that chip, most likely.
Coincidence? Yeah probably, and very tin-foil hat, but who knows?
Most counterfeits differ in lower quality, not gorilla gorilla glass, lower brightness not quite actual white backlight, non IPS IPS LCDs, 7 year old 4 times repackaged "brand new" batteries etc. There are also replacements with straight up fake, dummy plastic parts thrown in, for example https://www.youtube.com/watch?v=TalLpLWaOV4. It becomes real brand problem when Staples "fixes" your product using scam parts.
It’s especially true in east Asia. Yes, there are plenty of counterfeits, but there are also plenty of legitimate ones too.
If I were cynical, and I am, I could see that Apple aren't telling the whole truth here.
If you don't want to find malicious chips in your servers, don't look. Just destroy the ones you suspect and don't examine them.