5 ms·
If you look at Apple denial (https://www.apple.com/newsroom/2018/10/what-businessweek-got-wrong-about-apple/ https://www.apple.com/newsroom/2018/10/what-busines
by ig1 8y ago
If you look at Apple denial (https://www.apple.com/newsroom/2018/10/what-businessweek-got-wrong-about-apple/ https://www.apple.com/newsroom/2018/10/what-businessweek-got...) they make a curious statement:
"Our best guess is that they are confusing their story with a previously-reported 2016 incident in which we discovered an infected driver on a single Super Micro server in one of our labs. That one-time event was determined to be accidental and not a targeted attack against Apple."
Compare this to statement issued by Apple in 2017 when queried about the 2016 story:
"Apple is deeply committed to protecting the privacy and security of our customers and the data we store. We are constantly monitoring for any attacks on our systems, working closely with vendors and regularly checking equipment for malware. We’re not aware of any data being transmitted to an unauthorized party nor was any infected firmware found on the servers purchased from this vendor."
(taken from https://arstechnica.com/information-technology/2017/02/apple-axed-supermicro-servers-from-datacenters-because-of-bad-firmware-update/ https://arstechnica.com/information-technology/2017/02/apple...)
While their 2017 denial was technically correct (it was an infected driver and not infected firmware) it's still a serious red flag on their credibility on these matters.
- JdeBP 8y agoThere's a whole discussion of that at https://news.ycombinator.com/item?id=18145815 https://news.ycombinator.com/item?id=18145815 .
- 21 8y ago> While their 2017 denial was technically correct So if you assume that their current denial is technically correct, what loop hole is there in it? Because they seem to have covered all the bases.
- ig1 8y agoIt could be trivially done through technicalities. For example if the exploit was found on the motherboard prior to it being deployed in servers that would be consistent with Apple's denial (not suggesting that's what happened here, but more as an illustration of how Apple being specific actually leaves more wiggle room than broad statements).
- qaq 8y agoWas discussed in previous thread. They make very narrow statements: "Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server." This holds true if it was found by a 3rd party. "Apple never had any contact with the FBI or any other agency about such an incident." This holds true if private 3rd party was handling the incident. "We are not aware of any investigation by the FBI, nor are our contacts in law enforcement." This is meaningless it might not be FBI them not being aware doesn't mean there is no investigation and so on.
- radicalbyte 8y agoWouldn't this fall under the remit (and expertise) of the NSA? I thought that the FBI were like Interpol - i.e. federal-level cops. The NSA being the technical spooks (and the CIA being the meat-based spooks).
- e12e 8y agoI believe there's been a bit of a shake up since 90s - at the time secret service got the hacker beat, because: wirefraud. But also the FBI, because: felony crossing state borders. The nsa were signals intelligence first, but their civilian mandate had (has) to do with protecting national interests in the "signaling" world (ie: the Internet etc). Arguably they were never very good at that... ("Snowden", "crypto backdoor"...). But I believe "cyberspace" is now accepted as an actual thing, and so falls naturally under the FBI (cross border, spying on us soil) and police ("crime").
- eridius 8y agoThe Bloomberg article claimed Apple employees found the chip. So even if what you're saying is true, the article is at least wrong about how it was discovered, and that casts the rest of it into doubt as well. Also my recollection is the article claimed Apple was talking to the FBI, not Apple was contracting with a 3rd party who talked to the FBI. Similarly regardless of whether Apple was talking to the FBI directly or was going through a 3rd party, both constitute Apple "being aware" of an FBI investigation. So this only works if Apple contracted a private 3rd party to audit their servers, the 3rd party found the chips, didn't tell Apple, and talked to the FBI all without informing Apple of the issue. This strikes me as extremely implausible. Also, I don't think I'd accept the claim that "Apple has never found" is telling the truth if it was a 3rd party that found it. Because if a 3rd party informs Apple, that report right there constitutes Apple finding it.