Supermicro Hack: China Exploited a US Tech Supplier over Years [2021 follow-up]
bloomberg.com
bloomberg.com
Notably, one of the criticisms at the time was that Bloomberg didn't name credible sources with first-hand accounts of the events — understandably given the sensitivity. This time, it seems they have been able to do so.
Either way, I'm thrilled to see an outlet do original reporting and stand by their work in the face of universal condemnation. We are better off for having strong dissenting views informing us and expanding the narrative. I'm finding myself increasingly distrustful of the work of journalism outlets, but this (and those gone independent on Substack) gives me hope.
https://twitter.com/jordanr1000/status/1049684795448537088
https://www.bloomberg.com/news/articles/2018-10-09/new-evide...
Somebody owes a little apology here I think - if Bloomberg story confirms, which I now give a very good chance. Especially the "experts" that were so uniformly wrong. Schneier did recognize he was wrong, but only very matter-of-factly. I think there's more work to be done to figure out why so many people got so huge a story so wrong. I do not call for public shamings or anything, God forbid, but there should be some more work on this done than "ok, I was wrong, never mind", if turns out we had so many people get it wrong. There's a lot of trust placed in "experts" - in fact, disagreeing once with "experts" are now the grounds for a permanent ban from many platforms - and if they are getting things so wrong, we're finding ourselves in a very bad situation, information-wise.
When you say "naysayers" are you including other organizations who tried and failed to corroborate the original story? It's difficult to prove a negative but the Bloomberg story seems bogus to me because not a single other organization was able to find anything of the sort. If the hacking was this widespread, I tend to think someone else would be able to find something.
it is not needed because the quality of Huawei/ZTE and all the Chinese based tech vendors is so shockingly bad that no such backdoors are needed to achieve their objectives. shitty quality gives much better plausible deniability than a well designed backdoor in thoroughly tested code.
The big and only story IMO is that Huawei steals shit from other companies. I had my own work for control-plane on eNodeB stolen by colleagues in our Chinese site that then moved to Huawei. The company should be sanctioned all around the world and their CFO hopefully will rot in a US prison.
I guess someday we'll know for sure.
“If you think this story has been about only one company, you’re missing the point,” [FBI’s former assistant director for counterintelligence Frank Figliuzzi] said. “This is a ‘don’t let this happen to you’ moment for anyone in the tech sector supply chain.”
Perhaps the title could be adjusted to reflect that, although much of the article is still a follow-up to the earlier Supermicro story, and that is also reflected in the lede.
In particular, the article also includes allegations that Lenovo hardware used by the US military in Iraq was modified with specially-crafted backdoors:
“A large amount of Lenovo laptops were sold to the U.S. military that had a chip encrypted on the motherboard that would record all the data that was being inputted into that laptop and send it back to China,” Lee Chieffalo, who managed a Marine network operations center near Fallujah, Iraq, testified during that 2010 case. “That was a huge security breach. We don’t have any idea how much data they got, but we had to take all those systems off the network.”
The above quote is from a court testimony, and the article also links to a full transcript of it (in PDF):
https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/r9dKMMM0...
Although this would be old news, it appears to not have been reported upon before.
In any case, these are serious allegations. Bloomberg first published them over two years ago and faced criticism for not substantiating them further when all the parties mentioned in the article denied the claims. Eventually, the coverage of the whole story subsided without any definitive conclusion with regard to its veracity. Now Bloomberg appears to be doubling-down on the allegations. Hopefully this time the claims can either be confirmed as factual or disproved for good.
> NSA cannot confirm that this incident—or the subsequent response actions described—ever occurred.
Maybe I'm reading too much into it but to me this looks as if they were in fact tacitly confirming it (at the very least, it's a steep departure from the standard "no comment" response typically employed in such situations).
That's what being a journalist used to be about, before most of them became entertainers in service of political hacks.
> And how the hell is this not on the front page of hn?
Good question.
28 times? I only see it was submitted once, 3 hours ago (and the original article was apparently published only 4 hours ago)
[I also submitted it, FWIW]
Now, I only ever submitted a couple of stories myself, but as far as I recall they start at 1 point by default, and can only be upvoted, so this is the lowest possible value. I can also see other "[flagged]", "[dupe]" and "[dead]" stories from the past couple of hours in the "newest" feed. When I click on another account's story that was "[flagged]" and is "[dead]," I can still see it listed under that account's submissions.
For the record, I doubt any such story would be buried here intentionally. Perhaps there is some other automated mechanism to remove duplicates if the linked URL matches exactly.
It won't show up there if it was already submitted by someone else.