8 ms·
Statements from Amazon, Apple, Supermicro and Chinese government. https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-b
by zjfroot 8y ago
Statements from Amazon, Apple, Supermicro and Chinese government.
https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-beijing-respond https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...
From Apple:
"Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them. We have repeatedly and consistently offered factual responses, on the record, refuting virtually every aspect of Bloomberg’s story relating to Apple."
- TazeTSchnitzel 8y agoAssuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?
- rasz 8y agoNSL letter, under active investigation
- guelo 8y agoNSLs require secrecy not lying.
- gnode 8y agoCouldn't an NSL have been served to datacenter operators, along with the notification of the attack, and the organisation's management simply be unaware?
- iofiiiiiiiii 8y agoThey might volunteer to lie, though.
- alfalfasprout 8y agoThe snowden leaks among others show that most companies aware of PRISM ended up flat out lying about it. Either it's a type of NSL we haven't seen before or employees receive death threats, etc.
- lern_too_spel 8y agoNo, none of the companies lied about it. The companies worked with the FBI's Data Intercept Technology Unit. They would obviously have no knowledge of a dowstream data processing system like PRISM.
- deleted 8y ago[deleted]
- malmsteen 8y agothey have literally every reason to deny and literally no reason to say it's true
- BonesJustice 8y agoExcept, you know, to avoid committing securities fraud by making a material misrepresentation.
- insomniacity 8y agoThere is no way that the intelligence community would allow that fraud case to go ahead.
- lisper 8y agoThat assumes that 1) the intelligence community has the power to stop it and 2) that Apple believes this to be the case and 3) that Apple is confident that the intel community would use that power to protect them. That seems like a reach to me.
- jerf 8y ago#3 isn't the intel community protecting Apple, it would be protecting themselves, which is a lot more plausible. They don't want detailed information about the techniques coming out. Odds are good that the Bloomberg story is still incomplete in some critical way, and decent that even if the story as a whole is broadly-speaking "true" there's still an outright lie contained in it. My guess would be the way in which it was discovered. I work for a company that sells network appliances, and I've been questioned by customers as to why I'm doing an SRV DNS lookup instead of a standard A DNS record lookup in some software I wrote, and had every detail of how I use TLS picked over by some customers. (More power to them. Not a complaint.) Some people run really tight networks. I wouldn't be surprised the real discovery mechanism was someone noticing the packets heading out that had implausible source-dest pairs ("why is my internal network that barely knows the internet exists trying to send packets to $RANDOM_LOCATION?"). If the people discovering this were actually the intel agencies themselves, for instance, they'd find another story to tell rather than reveal that. I am absolutely, positively not claiming this is true; I have no more evidence of it than anyone else. I'm just giving an example of the sort of thing I mean. It's also possible the intel agencies slipped a hint to someone about what to look for; again, I have no info to that effect, just an example of why they might not want something to go to court.
- ajpikul 8y agoThis article is more or less total bullshit. At _best_ that device might be a mechanism to cause failure intentionally. And there are tons of ways to detect it with commodity technology, and plenty of vendors who implement that technology for assembly manufactures commercially.
- eecc 8y agoThat’s what I thought but then it says it’s hooked to the BMC bus. It’s basically a small IME device with no java bloatware to run. I’d think it’s reasonably credible
- ajpikul 8y agoMy issue isn't whether or not it's possible for hardware to be insecure or whether or not it's possible for exploits to exist. My issue is this Chinese undetectable super chip creating unpreventable wide-scale vulnerabilities. For what it's worth, I've worked in hardware security and I own a hardware quality control startup.
- MrEfficiency 8y ago> I wonder what reason Apple has to hide. The perception is that Apple is perfect and worth paying 3x the cost? EDIT: Curious if all of these Apple comments are going to disappear. I believe they have a strong marketing team to hide dissent.
- macintux 8y agoOr people recognize that statements like "The perception is that Apple is perfect and worth paying 3x the cost?" are hyperbolic nonsense.
- MrEfficiency 8y agoApple only has 5 accounts to downvote. its cute.
- dang 8y agoThis breaks the site guideline that asks you not to insinuate astroturfing or shillage without evidence. Please don't do that—it's a toxic trope that leads to dumber threads. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html Edit: looks like we've already warned you about this more than once. If you keep doing it we're going to have to ban you, so please don't post like this again. Ditto for unsubstantive comments in general.
- MrEfficiency 8y agoWhat evidence do you want? They only have 5 accounts with the ability to downvote. This is why comments always have -4 with anything critical of apple.
- dang 8y agoHN's software puts a floor of -4 on downvoted comments. Please stop this now.
- danimal88 8y agoI can think of a trillion reasons...
- MrBingley 8y agoWhat liars. Apple has done this before as well, when they said they had "never heard" of PRISM, despite a Snowden leak showing the exact opposite. https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data https://www.theguardian.com/world/2013/jun/06/us-tech-giants...
- enraged_camel 8y agoI mean what are they gonna say? "Yes, we have been aware that an unknown but possibly huge number of our servers have been compromised, but decided to keep our customers in the dark"?
- fcantournet 8y agoYour point being ?
- crunchlibrarian 8y agoI think the point is that actual honesty from these megacorps would be so surprising that even raising the possibility of it happening is so absurd it feels like parody writing.
- BryantD 8y agoLast week Facebook was reasonably transparent about a hack affecting tens of millions of users.
- crunchlibrarian 8y agoThis may be the first time in the history of the internet a statement from Facebook has ever been held up as an example of honesty and transparency from a corporation in America. The GDPR has already called out Facebook for lack of info in its response to the breach: https://www.cnbc.com/2018/10/02/facebooks-muddy-account-breach-response-could-be-the-new-norm.html https://www.cnbc.com/2018/10/02/facebooks-muddy-account-brea... Not sure why you'd pick that example.
- jpster 8y ago>Each time, we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them. An uncharitable reading, but this statement does not exclude the possibility of investigations by 3rd parties hired by Apple.
- buckminster 8y agoNeither does it exclude the possibility of internal investigations of which Apple's press office is unaware. If Tim Cook simply said this never happened I'd believe him. This elaborate denial suggests otherwise.
- joshgel 8y agoI mean: > The companies’ denials are countered by six current and former senior national security officials, who—in conversations that began during the Obama administration and continued under the Trump administration—detailed the discovery of the chips and the government’s investigation. One of those officials and two people inside AWS provided extensive information on how the attack played out at Elemental and Amazon; the official and one of the insiders also described Amazon’s cooperation with the government investigation.
- mzs 8y agoThe article says they shipped the boards to a company in Ontario, lawyerly: >…At no time, past or present, have we ever found any issues relating to modified hardware or malicious chips in SuperMicro motherboards in any Elemental or Amazon systems. Nor have we engaged in an investigation with the government.
- c789a123 8y agoThey have to deny it. If the allegation is true, it means the Chinese CCP Gov knows which computer parts are produced specially for US gov or certain big companies and target precisely. There has to be some deep link for information flow to allow that. Anyway, worth further digging.
- CobrastanJorji 8y agoThat seems plausible, given what we know about Amazon employees with ties to China disclosing private sales info or changing reviews in exchange for cash bribes. https://abcnews.go.com/Business/amazon-probes-report-workers-sold-confidential-info-deleted/story?id=57873582 https://abcnews.go.com/Business/amazon-probes-report-workers...
- sctb 8y agoMain discussion of that post: https://news.ycombinator.com/item?id=18138990 https://news.ycombinator.com/item?id=18138990.
- analyst74 8y agoI'm actually kind of sympathetic to Apple here. One of the company I worked for once received request from a news outlet about potential rumor around us, and bullied our CEO into an interview to disprove that rumor. Then the journalist picked several quotes out of context as proof that rumor being true. While I don't trust megacorps, I don't know if I can trust journalists more when a major breaking news is on the line.