DHS Press Secretary on Recent Media Reports of Potential Supply Chain Compromise
dhs.gov
dhs.gov
How true is this? I know US-CERT is within DHS, but what else does DHS do in this area?
I did a bit of searching and found https://fcw.com/articles/2018/02/14/dhs-supply-chain-securit..., which seems to imply that until 8 months ago, DHS wasn't doing much (or anything) in this area. If that's the case, I don't see how a statement from them regarding supply chain security can carry any weight. You don't go from nothing to being an expert in 8 months.
The major shift over the last decade or two to the commercial world being the source of a lot of risk vectors that impact the govt, means that govt capabilities to have oversight and control, or even warning, is severely limited. This case is a great example of that, as more and more threats to the govt are coming through commercial and personal devices.
Said another way, foreign adversaries don't need to target military equipment to have major capacity to spy on, or impact US government activities and policies. Private companies have to request support from DHS when there isn't a known risk to military supply chain. 99% of companies don't do this because 1. They don't want to, 2. The govt makes it hard to do and 3. It's not advertised well.
The US Govt is not structured to handle this at scale and there is no real solution without making a HUGE shift in private sector oversight that would be incredibly unconstitutional.
- Their product is fungible, folks on the front line buying motherboards may just chose to avoid SuperMicro to avoid awkward conversations with their boss.
- They were having financial issues before, had some shady accounting and got delisted from Nasdaq. They're now traded over the counter.
- Last quarter their net earnings were $17M; that'll most likely be wiped and they'll go in the red.
- They've got $120M in the bank and $700M in quarterly operating expenses.
- The market can stay irrational longer than you can stay liquid.
Many companies are now likely auditing their systems for mystery chips. Many companies have learned of the hacked firmware distributed to Apple. Many in-progress orders may have been halted.
This may be fatal to them.
Hard to handle such circumstances in the natsec space when specific information is, by it's very nature, unverifiable.
https://www.theregister.co.uk/2018/08/22/supermicro_facing_n...
What is the story about?; Why was it released?; Is the timing significant?; Who are and will continue to be SM's customers? ...prospects for future customers? ...prospects for current and future earnings?
If you like the answers to those questions (and those are just the ones I could think of in 30 secs), you know what to do.
Cheers!
It’s not just about control. It’s about corporate advantage as well.
These are companies that take your money and then hack you.
What are you basing this on other than speculation?
How would one go about analyzing it?
Who would be on the so-called dream team?
Asking for a friend.
For reference here is a picture of similar package (called wlcsp or variation of thereof): https://img.youtube.com/vi/edERx4x5eY0/maxresdefault.jpg
(scroll down to the bottom)
It's a Ceramic balun HHM1522E1 patch 0805 signal adjustment 880MHz ~ 960MHz
There were suspicious events that signal that something is up, like when Apple completely switched from Supermicro to other vendors or when they started to develop processes to prevent supply chain hardware attack around time when CIA supposedly found the bug (2015-2016).
iPhone is also switched from Qualcomm modem to US designed and fabricated by Intel.
Also, their work on supply-chain security is also at the same time that Apple was more publicly promoting the security of their own hardware. So those two things could be entirely co-incidental.
That said, short of a release of internal documents, I don't think anyone outside has a decent idea of what's going on.
Qualcomm is based in San Diego, CA.
Under the First Amendment Supermicro would have to prove actual malice—that is that Bloomberg knee its reporting was false or acted with reckless disregard for the truth. That’s a very difficult standard to meet.
In other words, they said nothing at all.
Snowden showed us otherwise.