8 ms·
Intel Warned Chinese Companies of Chip Flaws Before U.S. Government
- adamnemecek 9y agoI’m guessing that the Chinese govt is a lot more likely to drop intel than the us one.
- downrightmike 9y agoChina does have a home grown chip that will look more attractive to them: https://www.pcworld.com/article/3086107/hardware/chinas-secretive-super-fast-chip-powers-the-worlds-fastest-computer.html https://www.pcworld.com/article/3086107/hardware/chinas-secr...
- blattimwind 9y agoThe SW26010 is about as useful for servers and desktops as 10 million Soviet foot soldiers are in a sea battle.
- kogepathic 9y agoYup. Especially since China is already manufacturing their own x86 through a joint venture with Via Technologies. [0] After the Meltdown/Spectre fiasco with Intel I'd be willing to bet China is weighing the performance penalty of switching to Zhaoxin CPUs versus paying Intel for buggy (and potentially backdoored via IME) CPUs. The Chinese have shown over the past decades that they're fully capable of innovating and building strong businesses in segments where they didn't previously compete (Huawei in telco, Lenovo in consumer PCs, Xiaomi in smartphones). Given that AMD was able to come up with Zen on a shoestring budget, who can say China can't do the same? They can certainly afford to throw money at R&D. [0] https://techreport.com/news/33018/via-joint-venture-reveals-kx-5000-x86-socs-for-chinese-pcs https://techreport.com/news/33018/via-joint-venture-reveals-...
- throwaway7645 9y agoThey also routinely steal blueprints to US technology as well as the rest of the world. They make billions in IP theft annually. I'm not saying they can't innovate (being one of the first advanced civilizations), but they're currently so behind in many areas that corporate espionage + cheap knockoff is super profitable. Why spend billions in R&D?
- gonvaled 9y agoWhy would disregarding the Mickey Mouse Industrial Complex be immoral?
- coldtea 9y agoSo, just like US in the early days? Back in 1812, finished cotton textiles dominated British exports, accounting for about half of all trade revenues, the fruit of a half century of progress in mechanized mass production. Proportionate to GDP, the industry was about three times the size of the entire U.S. automobile sector today. High-speed textile manufacture was a highly advanced technology for its era, and Great Britain was as sensitive about sharing it as the United States is with advanced software and microprocessor breakthroughs. The British parliament legislated severe sanctions for transferring trade secrets, even prohibiting the emigration of skilled textile workers or machinists. But the Americans had no respect for British intellectual property protections. They had fought for independence to escape the mother country’s suffocating economic restrictions. In their eyes, British technology barriers were a pseudo-colonial ploy to force the United States to serve as a ready source of raw materials and as a captive market for low-end manufactures. While the first U.S. patent act, in 1790, specified that "any person or persons" could file a patent, it was changed in 1793 to make clear that only U.S. citizens could claim U.S. patent protection. http://foreignpolicy.com/2012/12/06/we-were-pirates-too/ http://foreignpolicy.com/2012/12/06/we-were-pirates-too/ https://www.pri.org/stories/2014-02-18/us-complains-other-nations-are-stealing-us-technology-america-has-history https://www.pri.org/stories/2014-02-18/us-complains-other-na...
- astebbin 9y ago
- lawl 9y agoThe HN policy of allowing paywalls with a bypass should really be changed to allowing links to the bypass: https://l.facebook.com/l.php?u=https://www.wsj.com/articles/intel-warned-chinese-companies-of-chip-flaws-before-u-s-government-1517157430 https://l.facebook.com/l.php?u=https://www.wsj.com/articles/...
- GirlsCanCode 9y agoWhat does this add to the conversation?
- oneweekwonder 9y agoWhy you are downvoted for supplying a non-paywalled link idk but thanks it worked for me to read the article!
- Pyxl101 9y agoA simpler version of the same link is to replace "wsj.com" with "fullwsj.com".
- boyinschool 9y agoWith China being a much larger consumer than the U.S.[0], it is a logical decision to warn those first who would have a larger loss than others. Ultimately, by preventing China from gaining vulnerabilities, we in turn will help the U.S. in a greater sense by hopefully achieving a >95% protection rate on chips. "In 2012, China consumed 33% of the world’s integrated circuits (i.e. microchips) while the US consumed only 13.5%" [0]https://qz.com/72542/china-just-surpassed-the-us-in-semiconductor-manufacturing-and-the-trend-is-likely-to-accelerate/ https://qz.com/72542/china-just-surpassed-the-us-in-semicond...
- chx 9y agoSo Intel knowingly ships faulty chips which smells of fraud and reveals a weakness in all of USA computers to another country which is known to employ cybercriminals ... how on earth do they get away scot free? No criminal charges?
- netsharc 9y agoSo, the people employed by the NSA who hacks other nations' computers and networks... are they cyber-criminals too? I suppose in the eyes of these governments, they are. I wonder if Intel just did it over the unsecured line, knowing that the NSA/FBI wiretaps that one...
- robocat 9y ago> So, the people employed by the NSA who hacks other nations' computers and networks... are they cyber-criminals too? In the reverse direction, the US has tried to sentence Chinese military members - https://www.usnews.com/news/articles/2014/05/19/chinese-military-members-face-us-hacking-economic-espionage-charges https://www.usnews.com/news/articles/2014/05/19/chinese-mili...
- averagewall 9y agoThey absolutely are. Just as soldiers invading another country are breaking the law in that country - they don't even apply for a visa! America imprisons foreign spies and so do other countries. Warfare, government hacking and spying are weird crimes that people everywhere support when their own country does it but not when an enemy does. They don't even care if they're right or wrong, just root for their home team.
- AsyncAwait 9y ago> So Intel knowingly ships faulty chips which smells of fraud and reveals a weakness in all of USA computers to another country which is known to employ cybercriminals It also reveals weakness in Chinese, Russian and even Venezuelan Intel-based PCs and while you may not agree that customers in these countries deserve to get notified on par with top tier U.S. customers, (questionable stance), Intel clearly does, since at this point, it is a multinational corporation with large customer base outside the U.S.
- amluto 9y ago> An Intel spokesman declined to identify the companies it briefed before the scheduled Jan. 9 announcement. The company wasn’t able to tell everyone it had planned to, including the U.S. government, because the news was made public earlier than expected, he said. That seems to imply that Intel had planned to tell the US government some time between Jan 3 and Jan 9. That seems rather late. I think that the distros list was notified before that, and I'd be quite surprised if there aren't a couple of government agencies monitoring it. This article doesn't seem to say when the Chinese vendors were notified.
- phkahler 9y agoThe US government is not a PC maker. The goal of the disclosure was to help companies figure out how to patch systems. Why would anyone expect the government to be notified first?
- achamayou 9y agoThey're a pretty big customer for Intel?
- developerdanny 9y agoSo?
- Sephr 9y agoAs a customer and not an OEM, what would they do with this information other than ask other parties to hurry with updates? The mitigations required OEMs to send firmware, microcode, and software updates.
- microcolonel 9y ago> As a customer and not an OEM, what would they do with this information other than ask other parties to hurry with updates? They could shut down machines for which it is an excessive risk; though honestly I don't think they should be privileged as customers go.
- Radle 9y agoIn some systems the PC maker controls the update path and not the operating system. As such it was important to get PC makers on the Team, otherwise users would have been left undefended.
- Sephr 9y agoOEM doesn't mean operating system, it means original equipment manufacturer (e.g. PC maker). You seem to have misread my comment.
- averagewall 9y agoSurely no vulnerabilities should be disclosed to the US government earlier than the public because it does abuse them to hack people's computers, and it doesn't make its own systems that would need protecting any more than private companies do. It's like giving a hacker group advanced notification. Imagine the roles being reversed. Would we care if a Chinese chip maker notified Google before the Chinese government? I'm sure nobody on HN would be complaining. That makes it look like naive American-centrism.
- electrograv 9y agoOf course we wouldn’t think negatively of being told first; that’s the whole point. Assuming you were trying to make a juxtaposition though experiment — what you should be asking is “Would China’s people care if a Chinese chip maker notified the US government first of vulnerabilities in their hardware?”
- sanxiyn 9y agoIntel notified Lenovo. Intel didn't notify the Chinese government.
- zaxomi 9y ago> It is a “near certainty” Beijing was aware of the conversations between Intel and its Chinese tech partners, because authorities there routinely monitor all such communications, Mr. Williams said. Doesn't that mean that it is a “near certainty” that the U.S. Government was aware of it, because authorities (NSA, etc) routinely monitor all such communications?
- justicezyx 9y agoSeems a generally-accepted-leaning-to-be-true assumption regarding NSA (or any nation-state-backed security or spying agencies with advanced technologies in a similar level as US).
- dustingetz 9y agoYeah but you'd need like 1:10 ratio of persons employed to monitor the comms of persons of interest. So there can't be that many persons/orgs under regular surveillance or huge numbers of people would be employed for the monitoring.
- akerro 9y agoCan we also assume that any country with global wiretapping systems - US, Germany, Russia, China, India could intercept this information?
- hishnash 9y agoYes through you may have left out the UK (with GCHQ) who do most of the spying for the NSA within the US, so as to ensure the NSA doesn't break any rules as they are permitted to take data from another nations department but have restrictions on local citizen data ;) they intern share data they gather on the in UK.
- angry_octet 9y agoI think we can assume Intel have heard of cryptography.
- deleted 9y ago
- behringer 9y agoIntel wanted to protect their customers before the US attacked them.
- f4rker 9y agozing
- williamscales 9y agoI would be very surprised if the NSA did not already know about these vulnerabilities. It's unfortunate that we can't count on the NSA doing the responsible thing for national security (which would be to notify Intel). But if these bugs were found by several independent researchers this year, it's hard for me to believe that the NSA didn't already find them. If they didn't, they are falling down on the job.
- appstateguy 9y agoThere's been a brain drain [0] going on at the NSA, so it wouldn't surprise me if they missed it. [0] https://www.washingtonpost.com/world/national-security/the-nsas-top-talent-is-leaving-because-of-low-pay-and-battered-morale/2018/01/02/ff19f0c6-ec04-11e7-9f92-10a2203f6c8d_story.html https://www.washingtonpost.com/world/national-security/the-n...
- dgoldstein0 9y agoSure, but these flaws aren't particularly new - specter has been possible in some form likely for the last 20 years.
- hishnash 9y agobut a lot of this brain drain has gone to private security companies that then sell vulnerabilities to national bodies. (Like the one in Israel that sold a load of 0day exploits for the iPhone to the CIA)
- jwilk 9y agoPaywall-free archived copy: https://archive.is/stHQc https://archive.is/stHQc
- NotSammyHagar 9y agoThis series of flaws surprised me, I now really see why you want to run government computing on their own cloud. I naively trusted that vm separation would be enough and you couldn't leak things that way. I know there have already been flaws exposed where the memory wasn't scrubbed between sessions but I thought that was all fixed :-) And the same idea applies to businesses that are suspicious of cloud computing security issues. Of course, these are probably obvious to everyone here and it's why these flaws are a big deal, cause a lot of cpus have been sold for cloud/vm installations, now what.
- chisleu 9y agoXen has had plenty of exploits. There are certainly exploits still out there, maybe even known exploits.
- foobarbazetc 9y agoLenovo was the #1 manufacturer of PCs worldwide in 2016. https://en.wikipedia.org/wiki/Market_share_of_personal_computer_vendors https://en.wikipedia.org/wiki/Market_share_of_personal_compu... So... what’s the problem exactly?
- foobarbazetc 9y agoThis article gives a better timeline because WSJ doesn’t say when: https://www.itwire.com/security/81538-intel-ceo-sold-shares-on-same-day-oems-informed-of-bugs-report.html https://www.itwire.com/security/81538-intel-ceo-sold-shares-... So... a bunch of OEMs were told in November. I just don’t understand the significance of the China angle here.
- swarnie_ 9y agoMakes a better headline for project fear.
- eccbits 9y agoIt's well known that the main cyber threats come from two nationstate actors: Russia & China.
- sdm 9y agoDon't forget that the US still tops those rankings.
- foobarbazetc 9y agoYeah but... so what? They told a bunch of OEMs and they told ARM too. So does that mean they told GCHQ? Not really. It would be negligent NOT to tell Lenovo when they make a massive chunk of all PCs globally. Thousands of US corporations run Lenovo computers.
- mr_spothawk 9y agoDidn't a Google researcher identify the flaw in the first case? If Alphabet (aka, public-NSA) didn't clue in the gov, I'd be incredibly surprised.
- Groxx 9y agoThe timetable is a bit strewn throughout the article, but from what I can make out: June: Google reports the problem to Intel. Soon after: Intel/Google (unclear) informs related businesses (Lenovo, Microsoft, Amazon, ARM Holdings, others?). Jan 3: Vulnerability leaked ahead of planned Jan 9 reveal. A 6 month window where apparently nobody informed the US Gov. I'm legitimately kinda surprised - if it were a small window, meh, but clearly they (and every other government) would have wanted an earlier warning since they'd likely be vulnerable. That's a gigantic window for the info to leak and an automated exploit to be built (just look how fast it happened when the news became public).
- empath75 9y agoThere is approximately zero chance that someone at the NSA didn’t find out about it before it was publicly announced.
- angry_octet 9y agoAnd it has to be assumed that they would already by monitoring the Swiss research team also.
- foobarbazetc 9y ago“Soon after” == “November 29” according to this article: https://www.itwire.com/security/81538-intel-ceo-sold-shares-on-same-day-oems-informed-of-bugs-report.html https://www.itwire.com/security/81538-intel-ceo-sold-shares-...
- Groxx 9y agoThanks! I was hoping there were dates somewhere... ...but as a counterpoint, this says June in the sub-heading: https://www.wsj.com/articles/intel-wrestled-with-chip-flaws-for-months-1515110151 https://www.wsj.com/articles/intel-wrestled-with-chip-flaws-... (though I can't find supporting info in the body) I'd love to find something conclusive :\ seems like everyone's implying different things / nobody actually has concrete evidence or dates.
- vinay_ys 9y agoGoogle Project Zero researchers discovered this bug in May, 2017. They notified Intel, AMD, ARM and likely other chip-makers (Qualcomm, Broadcom, Marvel, Microtek, Huawei etc) directly. Intel is just the lead actor in this mega-production. See this bug report by Jann Horn: https://bugs.chromium.org/p/project-zero/issues/detail?id=1272 https://bugs.chromium.org/p/project-zero/issues/detail?id=12... Then each of these chip makers would have notified their direct customers who make original equipment (motherboards, SoCs, Add-on card etc). Then they would have to notify their firmware/software partner/vendors who have to fix the issue. Since this was such a serious issue and at least 2 quarterly results were posted by all these publicly traded companies, I'm sure their lawyers, their external independent risk consultants, key members of the board and key investors were also told - especially as CYA when deciding to keep it a secret while giving market guidance (which had to be knowingly false?). Each of these disclosures would have gone with boilerplate embargo legalese (bad things will happen to you if you speak about it). But all of them would have taken actions ranging for good to bad to evil (from insider stock trading to actively looking for ways to exploit the bug for competition spying). While all this is going on, why would government not have known about this? Wouldn't one of the government certification programs like NIST FEDRAMP mandatorily require them to be notified of any vulnerabilities monthly? And of course, all govt spy agencies would have surely known about this vulnerability as early as July/August given the amount of cross-continent communication that would have happened on this topic. And it's a whole another matter if they used the exploit for any operational/tactical advantage for any ongoing operations or as a backdoor installation for future operations, it's anyone's guess. If they did do that, we cannot be surprised because that is definitely their job. Thinking any other way is not part of the security mindset. It's not the trust everyone kind of thinking that lead to discovery of this vulnerability in the first place.
- DannyBee 9y agoIt's interesting how many folks in this thread claim the US government is a "huge" intel customer. I do not believe that to be true. Certainly, they buy computers with Intel chips in them, but in terms of chip purchases (IE who intel was probably notifying), they are probably nowhere in volume. Intel has 8 customers accounting for 75% of revenue[1]. By numbers, America and Taiwan are tied for third in terms of volume per country. Singapore is #1, followed by China. Even for just client computing, 3 customers account for 38% of their revenue. None are the US government[2] [1] https://www.investopedia.com/articles/markets/100214/inside-intel-look-mega-chipmaker.asp https://www.investopedia.com/articles/markets/100214/inside-... [2] https://www.sec.gov/Archives/edgar/data/50863/000005086317000012/a10kdocument12312016q4.htm https://www.sec.gov/Archives/edgar/data/50863/00000508631700...