5 ms·
The Big Hack: The Software Side of China’s Supply Chain Attack
- reustle 8y agoBloomberg is really doubling down on this story
- taurath 8y agoWell one can definitely say that the people at Bloomberg don’t doubt their story. Is it at all possible that higher ups making statements from Apple or Amazon didn’t know? Even if so, I don’t see any way for some sides credibility to not be severely harmed by the end of this. And Facebook now enters the fray, saying there was an attack (though doesn’t seem to be claiming they were effected by the chip in previous article?) Edit - I read the dates of the articles wrong, and thought this was a new one this morning. It was posted alongside the original story, but main point of comment still stands so keeping it up.
- SiempreViernes 8y agoTheir account seems pretty solid and the story itself I think is less incredible than what Snowden leaked: a password check bypass on the hardware remote access systems is all they need basically.
- sparsely 8y agoIs it possible that only lower level Apple/Amazon employees were involved in the investigation and that they are forbidden from telling anyone else, even senior legal executives?
- 086421357909764 8y agoIt's actually possible they have a National Security Gag order. If that's the case they could only deny anyway.
- okket 8y agoBut they don't, they explicitly mentioned they are not under a gag order, which is the first thing you are forbidden to mention when you are gagged. That is the reason why "warrant canaries" exist. https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- usrusr 8y agoI think what GP was suggesting is that lower level employees might be under individual gag order, keeping them from ever reporting the incident to their higher ups (including those responsible for the warrant canary).
- deleted 8y ago[deleted]
- pskk 8y agoThe Norwegian national security agency has confirmed that they were aware of the allegations against SuperMicro since June, but they won't confirm if it's true (nor are they denying it) and they noted that they are also aware that Amazon/Apple are denying it. As for why Apple/Amazon are denying it I wonder if it's because they don't want to burn bridges. If they confirm the allegations, how would that play out in the Chinese business world?
- baybal2 8y agoWell, all of the above mentioned want a slice of Chinese pie. I'd say that market linkage in between China and USA in tech was just beginning to heal up after the credit crisis, but before that Chinese companies were rather wary of going to USA because it is expensive and risky market to enter, and instead chose easier markets for overseas expansion. As any hope of rapprochement is now done for, they will revert to their old ways. Comrades from AS4134 must be now scrambling everybody and everything into damage control mode. I think they firmly believed that they had an impenetrable cover.
- hugelgupf 8y agoDo you have a source for the Norwegians?
- pskk 8y agoHere you go, it's close to the bottom: https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-installerte-spionverktoey-i-maskinvare https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst... It's from a quote by the head of communications at NSM.
- 086421357909764 8y agoMy guess is Gag order for the US govt.
- chefkoch 8y agoThat would be the only reason i can think of. Otherwise the SEC could really make there life miserable.
- ezVoodoo 8y agoThat secret "Chinese weapon" you hold on your finger tip is a very common electronic component called the signal conditioning balun, worth $0.29 and sold here https://www.mouser.com/ProductDetail/TDK/HHM1932A2?qs=6JAMGB%252bEdkzXmsGhC2t69w%3D%3D&gclid=EAIaIQobChMI6Zielt3u3QIV2QMqCh2LnAysEAQYAyABEgID8vD_BwE https://www.mouser.com/ProductDetail/TDK/HHM1932A2?qs=6JAMGB.... The Bloomberg report can really win the Ignorance and Stupidity Award of this year.
- krackers 8y agoThey note in the article that the chip is of the same color and scale as a signal conditioning coupler.
- puzzlingcaptcha 8y agoObviously they didn't get a hold of an actual chip, they just claim they were made to look inconspicuous (like a signal conditioning coupler).
- fapjacks 8y agoMy word... You have quite the narrow comment history...
- mcqueenjordan 8y agoAWS Reply: https://aws.amazon.com/blogs/security/setting-the-record-straight-on-bloomberg-businessweeks-erroneous-article/ https://aws.amazon.com/blogs/security/setting-the-record-str...
- FartyMcFarter 8y ago> We further strengthen our security posture by implementing our own hardware designs for critical components such as processors, (...) Do they? I haven't heard about this before.
- mcqueenjordan 8y agoYes, AWS rolls its own hardware in some cases.
- angled 8y agoDoes this story have the potential to invalidate any CC assessments / certifications? eg, this one for Ubuntu from earlier this year that was assessed at EAL 2: https://fmv.se/Global/Bilder/Verksamhet/CSEC/Certification%20Report%20Ubuntu%20LTS%2016.04.4.pdf https://fmv.se/Global/Bilder/Verksamhet/CSEC/Certification%2...
- hnzix 8y ago"Playgrounds hung in space, castles hermetically sealed, the rarest rots of old Europa, dead men sealed in little boxes, magic out of China..."
- maerF0x0 8y agoThis has been posted several times and there are tons of comments: [1]: https://news.ycombinator.com/item?id=18146438 https://news.ycombinator.com/item?id=18146438 [2]: https://news.ycombinator.com/item?id=18138328 https://news.ycombinator.com/item?id=18138328 [3]: https://news.ycombinator.com/item?id=18145645 https://news.ycombinator.com/item?id=18145645 [4]: https://news.ycombinator.com/item?id=18138990 https://news.ycombinator.com/item?id=18138990 [5]: https://news.ycombinator.com/item?id=18141328 https://news.ycombinator.com/item?id=18141328
- deleted 8y ago[deleted]
- donald123 8y agoThis article just refers to some firmware vulnerabilities from Apple back in 2015, which is nothing uncommon, and Apple had taken proper measures to mitigate that. Besides it has nothing to do with China's attack.
- samspenc 8y ago> “In 2015, we were made aware of malicious manipulation of software related to Supermicro hardware from industry partners through our threat intelligence industry sharing programs,” Facebook said in an emailed statement. “While Facebook has purchased a limited number of Supermicro hardware for testing purposes confined to our labs, our investigations reveal that it has not been used in production, and we are in the process of removing them.” Facebook confirmed this happened. But looks like Apple and Amazon are denying it.