No, the boards would be selectively hacked.
And we know it happens because 'we' do it as well.
Surely there is evidence floating around but it's also unlikely that companies would want to admit the breach.
I kind of believe Apple and Amazon though, there's too much risk if they were to be caught lying.
This is a weird one ...
I actually don't care what the truth [edit: truth of this specific BMRG story] is - the West needs a 'wake up call' on this one and any company installing hardware should be inspecting everything that comes in.
Too much lax security out there, sadly, the US gov I don't think is competent enough in this area to provide guidelines.
I wish there was a CIO right in the White House cabinet, who could work with the Valley + Security experts to provide minimum guidelines for everyone, and to make everyone aware of certain things.
I'm glad the internet was designed to be 'open first' but not glad it was designed to be almost inherently insecure as well. 'Open but Secure' by default would be nice :)
Why are you in this thread at all then?
I think what parent touches on in their "tangent" is indeed the most important thing to come out of this story.
What you said is not a conspiracy theory.
Of course this event is a conspiracy.
But it doesn't matter - this is happening 100% guaranteed.
'We' do it and China has become far more aggressive in these areas these days ... so if they could be doing it, they would be.
Someone should come up with a bit of proof though.
" this is happening 100% guaranteed."
I don't know what brave new world we have entered where journalists, or even online users for that matter, make confident claims about things for which there is no physical evidence.
I worked at a large high-tech firm with business in the middle east, including content-filtering solutions and we were basically 'required' to work with Western governmental entities of a 'security nature'.
The US has massive clandestine projects in this regard and some of them are not so secret - consider the recent Wikileaks: [1]
"The US intelligence agency has been involved in a concerted effort to write various kinds of malware to spy on just about every piece of electronic equipment that people use. That includes iPhones, Androids and computers running Windows, macOS and Linux."
[1] https://www.independent.co.uk/life-style/gadgets-and-tech/ne...
All countries with active spy/clandestine agencies are spying on one another using malware, spyware, hardware hacking, phishing, social engineering, whatever. And many firms are complicit to one degree or another.
That Apple or AWS etc. may have been compromised with a specific attack makes for a really weird story - but that this is happening in general is a non-story - of course it is. It's not about this specific attack really.
See: Joseph Nacchio and Qwest
What if it's the Chinese government that's putting pressure on Apple and Amazon? What would Tim Cook do if he was told on no uncertain terms that Apple would be kicked out of China and its iPhone production lines shuttered if it confirmed this story? Even if the chance they'd go through with their threats is small, it's an enormous risk to Apple and taking it would be hard to justify to its shareholders. FAANG companies are clamoring for access to the Chinese market, and that gives the Chinese government a lot of leverage.
I don't think it likely though because such a nuclear option from the CN government would have the effect of basically destroying their position in the global supply chain.
I could believe it if the denials so far felt incomplete or ambiguously worded as if they were tiptoeing around something that they were not allowed to disclose. I could believe it if all we had coming from Apple and Amazon was the usual lawyer-speak "I won't confirm of deny" bullshit. Instead we've had completely unambiguous "this is completely false and never happened". If it turns out to be a lie it's going to be devastating for the trust in Apple or Amazon.
I mean think about it, if for some reason the US or Chinese agencies wanted to downplay or shift the blame they had so many easier ways to do it that would put them in an awkward position if somebody manages to prove the existence of these backdoored mobos. If the best spin they could come up with was "just deny everything and make sure to do so at a regular interval so people are constantly aware of our denial" they really need better PR people.
Well, at this point everybody is watching for weasel words, so a categorical denial is the only thing the government can demand that wouldn't provoke suspicion.
> If it turns out to be a lie it's going to be devastating for the trust in Apple or Amazon.
Oh, please. Companies have had millions of credit card numbers stolen, and nothing happens.
Apple and Amazon would get a bit of bad press. The tech folks wouldn't trust them any less than they already do. And it would blow over in a couple weeks at worst.
At this point, my Bayesian priors are lowering on Bloomberg, but they are not necessarily going up on Amazon or Apple.
since when taking a photo of the claimed motherboard with a foreign spy chip on it is considered as "dismantle" company property?
> discredit your employer knowing that it's likely to damage them and ruin you
I thought those huge number AAPL and AMZN investors deserve some truth.
The informant may have perfectly accurate information but be completely unable to provide physical evidence. For instance: they could have been briefed on the matter, but still have no physical access to the datacenter or to the location where the compromised servers were taken to.
A lot of the demands for physical proof make the false assumption that someone who knew about the spy chips and talked to Bloomberg would have had physical access to an example. That's simply not the case. How many of us work as software engineers in Fortune 500 companies, and how many of us could walk into one of our employer's datacenters and take a photo of the motherboard of a particular machine that we frequently work with? Not many, I'd imagine.
Have they seen any actual hard evidence? Noone is disputing that the described attack vector is possible, but if Bloomberg has not properly verified if it actually has happened, then their article becomes a lie; and if they have properly verified it (as opposed to blindly trusting unnamed sources), why are they seemingly unable to show any hard evidence or details to the public?
What? The allegations are against super micro boards produced in China.
One of the allegations was that special purpose video encoder boards from a hardware startup that Amazon acquired (Elemental) were targeted. These aren't off the shelf boards that anyone can buy.
What details and evidence about these boards have these sources provided to Bloomberg? Are there any details or evidence?
How about no.
There's next to no way that Bloomberg's sources would still have access to the boards, and that should be considered given all of the calls here to see them.
Ah, the Mockingbird sings...
> High Confidence:
> Iraq is continuing, and in some areas is expanding, its chemical, biological, nuclear and missile programs contrary to UN resolution.
> Iraq could make a nuclear weapons in months to a year if it acquired sufficient weapons-grade fissile material.
https://www.scribd.com/doc/259216899/Iraq-October-2002-NIE-o...
I'm not sure where this "the IC is this blameless group that only looks like they screw up because of those pesky politicians" meme came from, but it has no basis in reality.
Time and again, we see the CIA, and other of US' TLA-agencies, directly causing world turmoil - and yet a blind eye is turned, because "at least its our guys doing it", etc.
The world would be a much, much better place if American citizens paid more attention to what their spy masters are doing in the world. Secrecy is the lynchpin of all corruption: the fact that American's worship their secret-keeping institutions as beyond reproach, the reason we have so much turmoil in the world.
It doesn't work like that... "at least its our guys doing it" isn't some honest maxim we spout off in American fervor. It's akin to Winston knowing that when the 2-minutes-hate starts, whether you are into it or not, you stand up and blend in. Otherwise, those spy masters you mention make your life very uncomfortable, or take it away entirely. We just live here man, you don't think we actually are in charge and can make any difference...do you?
Is it a democracy or not? Are you a brave people, or are you really a nation of cowards?
The world burns while Americans do everything they can to not take responsibility for their government.
The talking heads you see on TV telling you "America thinks XYZ", or "America won't stand for <foo>!", are just that...talking heads. They aren't us, we don't know them, they don't come over and share meals...they are just a few elite that can't shut their mouth in front of a camera. It's just as shitty here as it is where you are from, most likely.
Now we have lots of propaganda. You know, like the USSR and North Korean propaganda... mantras that say we are the bravest, most "free", most prestigious people on the planet. It's just propaganda though, no one that lives here believes that nonsense. If they do, they just got off the boat...give them a year and their tune will change.
disclaimer: I'm an unhappy veteran.
As the draft NIE went up the intelligence chain of command, the conclusions were treated increasingly definitively. Only the summary of the NIE was partially declassified, and it omitted most of the reservations and nonconforming evidence. The fact that the NIE concluded that there was no operational tie between Saddam and al Qaeda did not offset this alarming assessment."
https://www.rand.org/content/dam/rand/pubs/research_reports/...
I wouldn't call the IC or even the CIA "blameless" for Iraq either and I don't appreciate you putting the word in my mouth (we also probably share a generally sour view of the CIA - they have done too many godawful destabilizing things around the world). The IC weren't the ones ordering the troops to invade any country on flimsy politically-massaged evidence though.
What's the logic in this? This is like saying Saudis must be Christians because we are Christians as well
More specifically though, the Snowden docs showed how the usa does this kind of stuff on a one-off basis.
Also, I gave up hunting karma on HN a while back, i'd rather speak my mind honestly than be artificially censored by chasing a number.
The phone companies all denied providing metadata to the NSA when the story first came out. I couldn't find the WaPo article from the same week, which I remembering reading in hardcopy, but here's a cite for the same from NPR: https://www.npr.org/templates/story/story.php?storyId=540913.... Did the SEC sue Verizon here?
They're very careful to say that they never turned phone records over to the NSA - who's to say they didn't turn phone records over to the DoJ, FBI, or any other agency, which then bounced them over to the NSA? I think they do have an out here. Plus, I'm not certain the SEC would sue over a matter of national security, even if Verizon was directly lying.
Compare that with Apple's statement, which is forcefully blunt and has no wiggle room:
On this we can be very clear: Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement.
The fact that they then asked Bloomberg to retract the story is also going a step further. The next step would be a libel lawsuit against Bloomberg, but that would be the thermonuclear option.All of that said, the BMC on supermicro boxes is running a super old unpatched Linux and is absolutely chock full of exploits:
https://www.cvedetails.com/google-search-results.php?q=super...
I had to root one several years ago to fix a broken server we couldn't take out of service for $reasons.
I'm waiting for the libel lawsuit. The absence of one is something I can't reconcile and leads me to thinking perhaps Apple doesn't want to through the discovery process for such a lawsuit which leads me to wonder why they wouldn't...
No comment is the proper action for no admission. However, Tim Cook and Andy Jassy put out public statements if they were willingly lying, they will be prosecuted by SEC
That such a potentially damaging allegation has not been met with a more forceful (read: lawyerly) response is "weird". That this dropped in one publication with quite a bit of detail is "weird". The timing of the responses, the rumors of trouble at SuperMicro, the timeframe of the alleged compromised boards. It's all weird.
I'm waiting for the other shoe to drop on this one.
Just noting that anonymous sources aren't unknown sources — if Bloomberg says that these are people working in US Intelligence then they've very likely validated it, but are protecting their identities by request.
Also worth noting that Amazon and Apple have a tremendous amount to lose here. That doesn't mean they're lying, but based no what we know, they have more incentive to lie than Bloomberg does. Also possible that they're already working with the government and have been asked to lie about it due to national security.
Totally possible that Bloomberg was intentionally mislead or flat-out wrong either way. It just sounds like they've done the due diligence of checking with an abundance of sources, so it would be odd. They've made mistakes before, but I don't know that they've ever made one of this magnitude. The decision to publish or not publish a story like this isn't something that one person working at Bloomberg does on a whim, many people are involved.
All other things aside, I tend to trust journalists more than corporations. There's not a lot of room to jump to a conclusion either way. Very solid 'maybe' territory all around.
That didn't make the NSA afraid of targeted interception campaigns.
I believe that secret services are doing everything we normal people dream of already, including stuff such as the hardware injections either in the Supermicro case or in the stuff the NSA did, and a good bunch more which we don't even know of yet.
Cyber warfare is all too real now.
The other way around. Apple and Amazon have very strong incentives to tell the truth. This has significant implications for their business (i.e. stock price) and if there is one thing that executives want to avoid, it's SEC filings based on false information given to the market.
Meanwhile, Bloomberg has the reputation of journalists with patchy histories of security news reporting. Perhaps they've been fed a line by government sources, but there is little financial incentive to fix any errors.
Bloomberg is wrong. Apple and Amazing have every incentive to strongly deny the story.
Bloomberg is right. Multiple employees up to executive level at 30 US companies and the government know about it and are actively leaking to Bloomberg about it. Numerous boards are out there at 30+ companies as physical evidence. There’s no way Apple and Amazon could risk denying this so strongly. It’s already being widely leaked - according to Bloomberg - the cat is well and truly out of the bag and wailing it’s ass off.
It just doesn’t make any sense for Apple and Amazon to put their reputations on the line in that second scenario.
If true, this is vastly different from the government requesting a backdoor or various warrant canaries, this would be an actual national security threat.
> governments have the right to mandate corporate speech “if the information in the disclosure is reasonably related to a substantial governmental interest and is purely factual.”
(https://www.reuters.com/article/us-otc-speech/when-the-gover...)
Since that would not be the case here, I do not believe it would be legally defensible for the government to compel false statements out of both Apple and Amazon.
(IANAL, so do take this with a grain of salt)
The government could say "look here, this is an actual national security issue" and Apple, Amazon, etc could say "oh shit, you're right - how can we help?"
If this were a real national security risk, what incentive would Apple, Amazon, etc have to tell divulge the truth rather than cooperating with the government? This is vastly different than saying no to a requested NSA backdoor.
(I just wanted to point out all options)
OTOH, no experienced intelligence professional would leak information they are not absolutely sure other people have.
The stuff of dreams for security researchers.
What do you mean by the second part of this? Bloomberg should have received examples of comprised boards?
I don't know about you, but I certainly couldn't get a photo of the motherboard of a dev server I work with every day, let alone take a reporter to go take a look at it. That doesn't mean I don't have accurate information to base a story on, and it doesn't mean someone else can't corroborate that information.
Reporting isn't about gathering physical evidence, it's about gathering and cross-checking testimony and documents. If credible people in the government and an NGO testify that there was a poison gas attack at a certain location, a reporter can legitimately write an article about it. That reporter isn't going to sit on the story until they go to the attack site, collect samples, and sent them to a lab; nor should they.
As you say, reporting is about cross-checking documents. In this case, the relevant documents would be the technical details of that malware - photos of the motherboard with the inserted hardware, schematics and analysis of where and how the inserted chip connects to the "real" parts, dumps of the firmware alterations, microscopy analysis of the extra chip after decapping it. Instead, Bloomberg provided "this is where it could have been" CGI illustration and "this is how the mechanism might have been" description of the process. All details about the attack seem to be made up by Bloomberg, they're not based on any real hard data from their sources.
This implies that none of their sources had (or provided to Bloomberg) sufficient detail to assume that this is what happened - if the sources say "well, there was a major supply-chain attack but we're not giving the details" then that's not sufficient to report what the Bloomberg article did, making up the details without knowing them. If the sources provided enough detail to Bloomberg, then this is the point where Bloomberg should release those details to the public.
I disagree. What if you have a the text of a government report describing the reactions to its discovery in detail (e.g. "an implant was found attached to the BMC of some Supermicro boards, here's our plan for securing the supply chain against implants as small as 1x1mm...")? What if they were shown a report but not given a copy? What if you have consistent testimony from five credible people whose backgrounds check out who read the only copy of the report in a secure reading room? What if all that is verbally confirmed by other insiders?
> In this case, the relevant documents would be the technical details of that malware - photos of the motherboard with the inserted hardware, schematics and analysis of where and how the inserted chip connects to the "real" parts, dumps of the firmware alterations, microscopy analysis of the extra chip after decapping it.
The Bloomberg reporters aren't security researchers. All of the stuff you describe is well outside their areas of expertise or what they can be reasonable expected to do. They're doing their job if they report what they learn from others, it's not their job to perform research or replicate research themselves.
Journalism is more like history than archeology, but a lot of people seem to want it to be the other way around.
Where are they? Where is their presentation of finding nothing?
It's so strange to see people continue running with "they wouldn't have doubled down unless they were really certain, so it must be true".
As the attack is said to have been discovered 3 years ago it is also not surprising that housekeeping has already been done a long time ago.
Obviously no-one would have publicised this, so if you weren't involved you would have had no idea. The story does report that Amazon completely dropped Supermicro as a supplier following this alleged hack (that should be verifiable even if the reason given would obviously be different).
Wells Fargo committed millions of counts of bank fraud, yet they still exist and people buy their services.
BP destroyed a large part of the economy and ecosystem in the Gulf of Mexico, yet they still exist and people buy their products. One of their top lawyers just became Assistant Attorney General for the Department of Justice’s Environment and Natural Resources Division.
VW built millions of cars with hardware designed to fake emissions testing data, yet they still exist and people buy their services.
https://www.forbes.com/sites/afontevecchia/2012/07/16/hsbc-h...
If the tech world turns their back on Bloomberg, I'll give them more credibility; not less.