Ask HN: What's the latest on that “Big Hack” story by Bloomberg?
[1] https://www.bloomberg.com/news/features/2018-10-04/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies
[1] https://www.bloomberg.com/news/features/2018-10-04/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies
Pertinent quotes from the article [0]: "The goal of this effort, Elgin told the potential source, was to get to 'ground truth'; if Elgin heard from 10 or so sources that 'The Big Hack' was itself a piece of hackery, he would send that message up his chain of command. The potential source told Elgin that the denials of 'The Big Hack' were '100 percent right.'"
"According to the potential source, Elgin also asked about the possibility that Peter Ziatek, senior director of information security at Apple, had written a report regarding a hardware hack affecting Apple. In an interview with the Erik Wemple Blog, Ziatek says that he’d never written that report, nor is he aware of such a document. Following the publication of Bloomberg’s story, Apple conducted what it calls a 'secondary' investigation surrounding its awareness of events along the lines of what was alleged in 'The Big Hack.' That investigation included a full pat-down of Ziatek’s own electronic communications. It found nothing to corroborate the claims in the Bloomberg story, according to Ziatek."
[0] https://www.washingtonpost.com/blogs/erik-wemple/wp/2018/11/...
Given my limited experience with Supermicro, I’d look towards gross incompetence vs. spies.
Frankly, it would seem a waste of resources to place some nefarious chip — the facilities provided by the vendor are pretty trivial to compromise.
The last public statement from Bloomberg was that they were going to perform an in-house review. I'm just going to wait things out.
That said, the evidence for the viability and practicality of the alleged attacks has only grown. The alleged technique has already been demonstrated. See https://www.youtube.com/watch?v=C7H3V7tkxeA Nobody seriously doubts that China is motivated to perform such hacks, and we know that the NSA has performed similarly complex hacks (the cost+benefit calculus isn't always intuitive to outsiders). So whether it has or has not happened is really only consequential for the credibility of Bloomberg.