25 ms·
Apple Insiders Say Nobody Knows What’s Going on with Bloomberg's Hack Story
- longerthoughts 8y ago>"Seventeen individual sources, including government officials and insiders at the companies, confirmed the manipulation of hardware and other elements of the attacks." Is it possible that many of these sources received their information from others on that list of 17, propagating imperfect or inaccurate information? I'd assume it's standard practice for journalists to confirm that multiple sources aren't essentially from the same source, but this doesn't look great.
- vmchale 8y ago> I'd assume it's standard practice for journalists to confirm that multiple sources aren't essentially from the same source I do not believe it is.
- baq 8y agoWhen you drop a bomb of this size you'd better double check that. This case is exceptional and I'd like to believe it was treated accordingly by journalists.
- sieabahlpark 8y agoLol. Clicks are the metric they care about.
- randyrand 8y agoyou’re downvoted, but we should never forget the importance of this incentive
- travmatt 8y agoIf you think Bloomberg’s primary incentive is to sell newspapers then you should probably learn more about what Bloomberg actually is.
- singularity2001 8y agosorry for asking: what is the real incentive of Bloomberg? can I find the answer on Wikipedia?
- theyinwhy 8y agoYes, first sentence: "Bloomberg L.P. provides financial software tools"
- JumpCrisscross 8y ago> Clicks are the metric they care about Terminal sales are the metric Bloomberg cares about. SuperMicro was delisted from Nasdaq in August [1] after failing to meet its reporting reauirements “amid an ongoing audit committee investigation” [2]. This is a name already receiving attention from the analytic parts of Wall Street. Bloomberg has more to lose than BuzzFeed. [1] http://ir.supermicro.com/news-releases/news-release-details/supermicror-announces-suspension-trading-common-stock-nasdaq-and http://ir.supermicro.com/news-releases/news-release-details/... [2] https://www.marketwatch.com/story/super-micros-stock-set-to-be-delisted-as-filing-deadline-wont-be-met-2018-08-22 https://www.marketwatch.com/story/super-micros-stock-set-to-...
- ocdtrekkie 8y agoI'm honestly curious if this is part of like a Russian misinformation campaign. I can't imagine China would be involved (it looks bad for them), and this feels like maybe an attempt by a foreign power to manipulate the market in the US by messing with our media. I'm curious if Bloomberg's interviews were done in person with all of their corroborating sources or if VoIP or email was heavily in use for these. The idea that someone put in place an extensive, intentional plan to create a false story is perhaps the only way that all sides of this could be acting in good faith. Troll farms have, at the very least, exacerbated conspiracy theories like Pizzagate or QAnon, which very few people are likely to find credible. But the step up from that, the truly masterwork level of that, would be to fabricate a story that comes from an incredibly reliable source, that truly leaves the reader unsure of who to trust and what the reality is.
- seppin 8y agono
- philwelch 8y agoThere’s something going on here. I think the denials from Apple and Amazon are strong evidence that Bloomberg’s story isn’t the end of it if it’s even true in the first place, but it’s entirely possible that there are other layers to the other story that explain the evidence that Bloomberg and their sources have seen. And, regardless of the factual accuracy of this specific story, the overall question of supply chain security, particularly when it entails depending on geopolitical rivals, is an important one.
- jjtheblunt 8y agoWhat? Maybe the denials are just honest.
- stordoff 8y ago> it’s entirely possible that there are other layers to the other story that explain the evidence that Bloomberg and their sources have seen. I wonder if it could be a hypothetical - it's the sort of thing I could imagine coming up in a war games-like scenario (what would happen if China chose to use its access to compromise our supply lines?), and it was mis-relayed to Bloomberg or the documents they have seen (the sources or Bloomberg) do not clearly identify it as such. Maybe a stretch, but I'm struggling to reconcile Bloomberg's story with the explicit denials.
- crunchlibrarian 8y agoPutting aside the specifics of this story for a moment: I really hope that we don't enter a new era of tech journalism where we get story after story written by anonymous government sources, because I am about to lose my mind over the constant barrage of reporting in this style on politics. It's already creeping into business sections, just make it stop.
- gunlaw22 8y agoScared of something? You are projecting
- nixpulvis 8y agoUm yea, aren't you?
- crunchlibrarian 8y agoYes I am scared of anonymous sources writing with an agenda that is bullshit as often as not. Not sure when this became the norm in journalism for people to just take everyone at their word just because they are senior and they have an axe to grind but it's quite tiresome. If it's important stand up and put your name behind a story as a source, everyone just cowering in the corner because they want to keep their careers safe is making things worse, not better.
- cycrutchfield 8y ago>Not sure when this became the norm in journalism for people to just take everyone at their word just because they are senior and they have an axe to grind but it's quite tiresome. Anonymous sources have been around as long as journalism. It’s not like what those sources say is taken as a given, they are heavily corroborated against other sources of information, often documents/records/etc.
- codazoda 8y agoSome of the sources are said to be government. That same government is forcing anonymous sources by coming down hard on leakers, both inside and outside. That may or may not be what's happening here but it's certainly possible.
- SteveNuts 8y agoThis is either going to turn out to be an NSA gag order, or a total misunderstanding on Bloomberg's part. For me, this is the most interesting news story to follow in a decade.
- ethbro 8y agoThe response is equally interesting. I wouldn't have assumed people would be so quick to jump to "Well, private US companies are lying to the public because the US government is compelling them to." Times we live in...
- Alex3917 8y ago> I wouldn't have assumed people would be so quick to jump to "Well, private US companies are lying to the public because the US government is compelling them to." I mean ask Joe Nacchio how going up against the NSA worked out.
- RL_Quine 8y agoThe reason for that response is: * this all seems within reason, knowing the hardware * the denials are unusually strong If any of it is true or not I don't know, but the IPMI stuff is crappy, if not backdoored.
- dboreham 8y agoSince everyone assumed IPMI was crappy and potentially backdoored, that's why the story seems fishy. Why go to science fiction lengths to subvert some easily subervertable thing?
- jarfil 8y agoThe described hack is nowhere near science fiction levels. Even embedding a bare silicon chip in the layers of a board would be factible.
- 8y ago
- IBM 8y agoApparently these reporters have some questionable history with their reporting. https://twitter.com/GossiTheDog/status/1048322164653535232 https://twitter.com/GossiTheDog/status/1048322164653535232 https://twitter.com/RidT/status/1048349907487264768 https://twitter.com/RidT/status/1048349907487264768
- nabla9 8y agoIt was news reported vs. government denies. To know who is telling the truth you must know what the government policy really is related to NSA exploits and how bold NSA is when protecting secrets. These things can be verified only when whistleblowers release documents. Snowden and other whistleblowers have revealed multiple lies, including that Director of National Intelligence James Clapper lied under oath. That said, it's also possible that Riley & Co. rely on bad or unreliable sources.
- kerng 8y agoWow, didn't realize that is based in more then one year long investigation by Bloomberg. That seems to be quite thorough and am I already curious when companies will come forward with details.
- brianberns 8y agoThis is exactly what happened when both the US intelligence community and media decided that Saddam Hussein had weapons of mass destruction in the 00's. All the sources traced back to a handful of Iraqi dissidents who had made the story up to encourage American intervention.
- ams6110 8y agoNot just the US intelligence community but most of the Western world was convinced.
- longerthoughts 8y agoBased on independent intelligence or a relay of the bad US intelligence?
- brianberns 8y agoBad US intelligence. Secretary of State Colin Powell gave a detailed presentation at the United Nations that was seen around the world. It was all based on faulty sources.
- sitkack 8y ago> It was all based on faulty sources. Made up, manufactured "evidence", not faulty sources.
- badosu 8y agoPlease... I was a 12 year old boy in a poor city from Brazil and knew it was all garbage. At that time I did not even have internet and most people knew it was bullshit. The only thing that needed convincing was that the US would do it anyways, so better to have a smooth pathway.
- longerthoughts 8y agoQuite a skill to know that kind of thing with no direct involvement. Mind telling us the truth about what happened at Apple?
- smokeyj 8y agoIt's too specific to be fake. My money is on Amazon and Apple being under a gag order. Why would they be under such order? Maybe it's CHYNA, or maybe it's PRISM's big brother ;)
- longerthoughts 8y agoPeople are pitching the gag order theory a lot but would they be legally able to not only flat out deny the events but also that they’re under any gag order?
- ethbro 8y agoThe only gag order version that makes sense is "An incredibly small number of people at the companies were aware of this, and they've been lying to their own company." It's possible... but that starts to be fairly chilling and I can't see them being employed after this shakes out if it's true.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- taviso 8y agoAs far as I'm aware, legal experts agree there is no way to compel you to lie. Apple's general counsel has said on the record he doesn't know what Bloomberg are talking about, so how would they even verify this gag order was proper? https://twitter.com/dnvolz/status/1048283980913684480 https://twitter.com/dnvolz/status/1048283980913684480 Note that he volunteered to be on the record, he could have said that off the record or made no comment at all.
- ummonk 8y agoAdditionally, it probably wouldn't protect you from lying either when the SEC subsequently investigates.
- debt 8y agoInteresting, then why not sue? I imagine it’s because they’re lying and would have to turn over documents related to the incident.
- umanwizard 8y agoHow do you know they won't? The story broke yesterday, I think it takes a bit longer than that for a competent legal team to even decide whether to sue.
- strstr 8y agoThis is probably just BadBIOS2[1]. If this is as common as it sounds someone will get a chip and do a teardown and the similarities to BadBIOS will be gone. [1]https://en.m.wikipedia.org/wiki/BadBIOS https://en.m.wikipedia.org/wiki/BadBIOS
- Jedi72 8y agoI'm not saying it's a fake story, but the US is in the middle of a trade war. It could be a huge piece of propaganda. The sheer audacity of that though would be staggering.
- Analemma_ 8y agoI don’t buy it. I know it’s fashionable to be cynical about the media at the moment, but Bloomberg is not a rag and it’s owned by someone who is no fan of Trump or trade wars. It doesn’t add up.
- longerthoughts 8y agoBloomberg wouldn’t need to be deliberately deceitful - just misinformed by the government sources they’ve indicated they have.
- 21 8y agoIt would be something Russia would do, plant a fake story to massively discredit Bloomberg. It would go with their strategy of launching so many fake stories that nobody knows anymore what to belive. The problem with this theory is that Bloomberg says all the sources were from the American govt.
- CamperBob2 8y agoThat's not really a problem with the theory. If anything, it's a supporting argument.
- deleted 8y ago[deleted]
- prolikewh0a 8y agoRussia gave me cold and made me miss 2 days of work :<. It's definitely something they'd do.
- drb91 8y agoIt also doesn't make sense to reject it out of hand—it's not like Bloomberg (or any paper) is an infallible source of fact.
- crb002 8y agoWho, what, when, why, where? Bloomberg needs to tie it to specific SKUs of servers, get shipping records, see where they were sold after three years of use which is when they usually go out of warranty so researchers can get their hands on them.
- iask 8y agoPerhaps they’re afraid that some stiff regulations might come out of this, affecting their bottom line, so they just deny it?
- panda888888 8y agoYeah, I agree. I'm thinking that the attack/breach was so bad that it could have major consequences for these companies.
- simplecomplex 8y agoIf there was hidden hardware on a bunch of servers, where is the hardware now? Why doesn’t Bloomberg’s sources have the hardware or know which boards they were? Bloomberg provides zero evidence this happaned, outside of their anonymous sources.
- FractalParadigm 8y agoMy thoughts exactly. They're making claims that virtually everyone in tech is denying and haven't/can't produce any evidence. Not to mention, if this hardware had been trying to phone home, it's safe to assume it would have set off some kind of an alert at at least one of these places.
- dboreham 8y agoTo be fair, the article does mention that it set off alerts.
- pmart123 8y agoWhen you read the article, I believe they are alluding to the fact that Apple and Amazon did discover the vunerabilities. “In 2016, Apple informed Supermicro that it was severing their relationship entirely—a decision a spokesman for Apple ascribed in response to Businessweek’s questions to an unrelated and relatively minor security incident.”
- yonkshi 8y agoAnd Apple's own statement said that the journalist is probably confusion a separate, software based, incident with this incident. https://www.apple.com/newsroom/2018/10/what-businessweek-got-wrong-about-apple/ https://www.apple.com/newsroom/2018/10/what-businessweek-got...
- vmchale 8y ago> Not to mention, if this hardware had been trying to phone home, it's safe to assume it would have set off some kind of an alert at at least one of these places. Maybe at some big companies, but not anywhere I've worked. I hardly know anyone who audits outgoing traffic with dedicated hardware.
- elorant 8y agoSay you work for a company that uses SuperMicro boards on their servers. Is it possible to inspect them for the hack or you could have no way of telling if they're tampered? Because if there is then I guess in the following days we'll have confirmation from third parties.
- late2part 8y agoCorrect.
- twblalock 8y agoAt the end of this it could turn out that Buzzfeed’s journalism is more reliable than Bloomberg’s, which would be a sad state of affairs.
- judge2020 8y agoI've found that Buzzfeed News is pretty alright, but the main Buzzfeed website is definitely something to stay away from.
- vaughnegut 8y agoI've always thought of regular BuzzFeed as a vehicle to fund BuzzFeed News
- ambicapter 8y agoSince when does news make healthy margins? Its more like BuzzFeed News is there to provide a thin veneer of respectability to BuzzFeed.
- cthalupa 8y ago>Since when does news make healthy margins? That's exactly his point. He's saying they always wanted to be legitimate news, but didn't have the money, so they built their war chest using clickbait.
- astrange 8y ago> Since when does news make healthy margins? Most of the 20th century! Have you seen their expense accounts?
- notatoad 8y agoBuzzfeed has a legit investigative news division. their last highlight list is pretty impressive (in listicle form, because buzzfeed) https://www.buzzfeednews.com/article/markschoofs/the-year-in-investigations https://www.buzzfeednews.com/article/markschoofs/the-year-in...
- deleted 8y ago[deleted]
- ezVoodoo 8y agoTechnical possibility is one thing; proving the story has actually happened is another thing. Until now, what we get is a categorical denial of the story from all related parties. And all the evidence Bloomberg can provide so far is just vague anonymous sources. Talk is cheap, show me the code/server/chip if they ever exist. Otherwise, the story is just a blunt lie fabricated by Bloomberg serving as a propaganda to bash China amid the Sino-America trade war.
- panda888888 8y agoI'm tempted to give Bloomberg the benefit of the doubt. Tech companies don't want to be hacked. And if they are, they want to be able to say "we cleaned things up and everything is safe now," not "we were infiltrated several years ago and have no idea what the malware does or even which systems it impacts."
- ezVoodoo 8y agoFunny! So if you own a company and I say your company is dirty, there is literally nothing you can do except to admit that your company really IS dirty. Because if you deny, you'd be lying, based on your own logic.
- panda888888 8y agoNo, but Facebook is already in deep trouble in terms of how the average American views the company. I find it likely that they want to protect their reputation at all costs (including lying to congress...)
- ivirshup 8y agoI don't think China planting malicious hardware is under question, whether Apple was breached is.
- ezVoodoo 8y agoYou can let your imagination fly the way you want. But without hard evidence, it's just your imagination.
- crazygringo 8y agoI know Bloomberg isn't going to, and shouldn't, give up its anonymous sources... but it feels like Bloomberg's going to have to provide a lot more specifics if these reporters (and Bloomberg itself) are going to maintain their credibility -- concrete facts Apple can directly confirm or deny, as opposed to leaving Apple to guess at what it could be. E.g. if Apple contacted the FBI about this, then who at Apple did so (or at least what was their role), on what date, and what FBI office? Or how did Apple detect it in the first place, what happened next, etc. Even if sources can't provide technical details, they should certainly be able to provide names and dates.
- forapurpose 8y agoLost of news reports result in strong, aggressive denials. Bloomberg assembled extensive evidence, with around 17 sources. Perhaps Apple needs to provide more evidence than just a denial (though it's hard to prove a negative).
- jm__87 8y agoSo anyone can just claim anything now and it is up to the person being accused to prove their accuser wrong? We're just going to assume guilty until the accused can prove themselves innocent? That is not a world I want to live in.
- mcbits 8y agoAll of the companies mentioned in the original article have the resources to sue Bloomberg for defamation, so there's that possibility.
- makomk 8y agoI'm pretty sure US law would protect Bloomberg against any lawsuits unless Apple could prove that they definitely knew the story was false when they ran it. Short of that, nothing - not even massive journalistic failures - would make them liable.
- chrischen 8y agoIt also doesn’t make sense for China to do this. These chips would eventually be discovered and easily traces to China. The economic damage would be huge, and the value of the data they could gleam seems worthless by comparison.
- jacquesm 8y agoI have 10 Supermicro machines sitting in the room next door, bought through the years. If someone would tell me where to look I'd be happy to tear them down, but without any specifics, such as the serial numbers or SKUs of affected hardware it seems a bit thin. Though the hack itself sounds totally believable, compared to Van Eck Phreaking or powerline exfiltration it sounds pretty easy.
- chendragon 8y agoIirc the chips were supposedly found near the SPI flash for the BIOS if you can locate that, probably close to the IPMI/BMC chip.
- Scoundreller 8y agoSomeone needs to build nmap-style probe hardware that could be connected to the SPI bus and scan every device on it.
- mindslight 8y agoSPI works by paralleling all of the shared lines, and each chip having its own CS line. So you can't really enumerate like that, without already having enumerated the CS lines. I2C works closer to how you're thinking, but even there a hostile implant doesn't need to have an protocol-dictated address to corrupt someone else's traffic.
- jacquesm 8y agoOk, I will have a look if I can see anything interesting near the serial flash device.
- Havoc 8y agoThe other article about this on hn front page make reference to an animation of where the chip is
- 8y ago
- tlrobinson 8y ago> “Asked point blank if Apple is lying to the public in the interests of national security, this executive replied, "no."” If they were lying about this why wouldn’t they lie about lying about it?
- donohoe 8y agoThey’d say ‘no comment’ in that case IMHO
- andrewflnr 8y agoThat would be as good as telling the truth. If you're serious about lying, that would be obviously stupid.
- deleted 8y ago[deleted]
- walterbell 8y agoFrom 2016, https://arstechnica.com/information-technology/2016/03/report-apple-designing-its-own-servers-to-avoid-snooping/ https://arstechnica.com/information-technology/2016/03/repor... > Apple has begun designing its own servers partly because of suspicions that hardware is being intercepted before it gets delivered to Apple, according to a report yesterday from The Information. "Apple has long suspected that servers it ordered from the traditional supply chain were intercepted during shipping, with additional chips and firmware added to them by unknown third parties in order to make them vulnerable to infiltration, according to a person familiar with the matter," the report said. "At one point, Apple even assigned people to take photographs of motherboards and annotate the function of each chip, explaining why it was supposed to be there. Building its own servers with motherboards it designed would be the most surefire way for Apple to prevent unauthorized snooping via extra chips."
- MR4D 8y agoIf you have all the resources of a state actor to accomplish this, it’s owuld not be a chip on the motherboard, it would be a set of circuits in the motherboard. Why make something easy to photograph when you can embed it an area that can only be seen in an x-ray? That’s how I’d do it at least.
- thinkmassive 8y agoThe original Bloomberg article said some of the chips were so thin they were sandwiched between PCB layers.
- xevb3k 8y agoOr just replace an existing chip, which is the most logical way to do it...
- ggggtez 8y agoHow do you know they don't do that too? This is just one news story, from one manufacturer.
- panda888888 8y agoI believe the Bloomberg story. Why? Because of the fact that the chip was originally found on hardware owned by Elemental. Elemental would have been a great company to target. My guess is that Elemental was specifically targeted because the cost of doing so would be pretty small and with nearly a 100% chance of success. Back in 2015, Elemental was nearly guaranteed to be acquired by one of the greats (Apple, Google, Amazon, etc.) because they had grown too large to be acquired by smaller companies but were also unlikely to go public on their own. The company was doing very well, plus they had government clients. Knowing that Elemental would likely be acquired and infecting their hardware beforehand would have been pretty sophisticated but also an easy thing for a malicious party to do. Even if the hackers didn't know/plan for Elemental's acquisition, they still would have been a great target based on their government work. (I'm not trying to fault Elemental; I would expect the same thing to happen at basically any small company that employs maybe 10 hardware specialists) And if the story were fake, why would Elemental even be mentioned? It's too small and obscure to be of note otherwise.
- ardy42 8y ago> My guess is that Elemental was specifically targeted because the cost of doing so would be pretty small and with nearly a 100% chance of success. Back in 2015, Elemental was nearly guaranteed to be acquired by one of the greats (Apple, Google, Amazon, etc.) because they had grown too large to be acquired by smaller companies but were also unlikely to go public on their own. The company was doing very well, plus they had government clients. I don't think the acquisition potential had anything to do with it being a good target. It was all about the government clients. I could see the acquisition potential as actually being a downside. Apple, Google, Amazon, etc. have histories of acquiring companies just to withdraw their products from the market.
- NTDF9 8y agoWho else thinks this is another Vietnam, Gaddafi, Saddam Hussein moment?
- mulmen 8y agoI don’t know what that means, can you elaborate?
- jjcc 8y agoThe common factors of three cases I can see: 1.The lies were used to create hostility of public towards another country. 2.A lie was not considered as a lie at the time when the lie was presented. 3.Public don't remember the history and can be fooled again by media or government Just my speculation. I'm not the author
- NTDF9 8y ago> I don’t know what that means, can you elaborate? A political move where some external country is portrayed as doing something against American interests, without any proof, only to serve a political agenda by lying to their own populace. For example: Bombing American vessels: https://en.wikipedia.org/wiki/Gulf_of_Tonkin_incident https://en.wikipedia.org/wiki/Gulf_of_Tonkin_incident And the very famous George Bush lie and declaring war on Iraq: https://www.youtube.com/watch?v=WejYdT3Lof8 https://www.youtube.com/watch?v=WejYdT3Lof8 Once Iraq was destroyed, here is George Bush admitting he lied: https://www.youtube.com/watch?v=18M70UgmV40 https://www.youtube.com/watch?v=18M70UgmV40
- Waterluvian 8y agoDo you mean like a justification to massively pull a major industry out of China?
- housingpost 8y agoWhy are so many people ignoring the fact that Supermicro was delisted from Nasdaq over a month ago with continued delays and specious excuses from the company. Something really strange is going on there.
- bhouston 8y agoSomething is weird there. There is smoke but it is hard to know what exactly is the fire.
- Simulacra 8y agoPart of me wants to believe Apple and Amazon, but they're really under no obligation to tell us the truth. It's way more harmful for them to admit this happened.
- bilbo0s 8y agoIn this instance, just to be fair, Bloomberg did not present any concrete facts that can be confirmed or denied by the industry. (Concrete facts would also have the benefit of being able to be confirmed, or not, by reporters not affiliated with Bloomberg or FAANGs.) As it is, Bloomberg just kind of said, there is this issue that we're certain exists. So the industry is left to guess what the issue is in so many ways. I think we'll all need to wait for the outside reporters and investigators to run some of this information down to get a better idea of what's going on. Because right now, even most of us are just guessing at what it could be.
- jarfil 8y agoMoreover, what if they got a gag order which put them under obligation of never confirming the attack?
- diogenescynic 8y agoAnd if they did admit it, it would immediately cause a panic and stock drop.
- astrange 8y ago> but they're really under no obligation to tell us the truth. They are legally required to tell the truth.
- kaycebasques 8y agoSomebody in another thread discussed the hack as a brute force strategy where the attackers compromised a lot of hardware without knowing where it would end up. If that’s the case, then I’d imagine that you could audit a bunch of this hardware from various places in the wild and see if any of them have the “extra” hardware. My understanding of the situation may be mistaken, however.
- mattnewton 8y agoAs an ex-apple employee, all I’ll say is this means basically nothing. Everything was on a strict need-to-know basis and a condition of your employment was respecting that. I would be very surprised if more than a handful of Apple employees even knew what exactly what was purchased from Supermicro, so a random sample of employees absolutely would know nothing about this. Unless senior means Senior Vice President, it’s meaningless. That being said, SVP level people did categorically deny it, and I can’t see them doing so unequivocally unless they really believe that will hold up on the court of public opinion for their entire tenure there.
- noobermin 8y ago>A senior security engineer directly involved in Apple’s internal investigation described it as “endoscopic,” noting they had never seen a chip like the one described in the story, let alone found one. “I don’t know if something like this even exists,” this person said, noting that Apple was not provided with a malicious chip or motherboard to examine. "We were given nothing. No hardware. No chips. No emails."
- vehementi 8y agoNot once have we ever seen a tiny grain of sand sized malicious chip on the motherboards we bought that I've seen in the racks I inspected in the datacenters I had access to!
- craftyguy 8y agoHey folks, we have a testimony from an anonymous person on the internets claiming there's nothing to see here. Case closed!
- geezerjay 8y agoYes, and I never saw Belgium.
- solarkraft 8y ago
- anon7429 8y agoBig claims require equally big evidence and big sources, otherwise it's he said/she said. I'm doubtful about the story but not against it entirely until more evidence and sources can be presented. If not, it smells like clickbait trying desperately to get traffic, and they just flushed their reputations down the drain.
- bilbo0s 8y ago>I'm doubtful about the story but not against it entirely until more evidence and sources can be presented... This is a reasonable position. I'm with you. I'm waiting for some independent reporters and investigators to run some of this stuff down.
- jethro_tell 8y agoAlso, some technical detail about what a chip with three pins can do. Was it working with another chip? Enabling intelME? There's just not a ton you can do with chip of that size. Is the story that the board had an extra undocumented chip, or that the chip was used to exfiltrate data?
- rootw0rm 8y agowow, just a 3 pin chip? I agree, that is fairly limiting.
- jethro_tell 8y agobut we don't know what it was doing, maybe the back door is else where in the motherboard and this things job is to prop the back door open every now and then.
- Scoundreller 8y agoA 3 pin chip could talk over i2c: 1 pin for GND, 1 pin for CLK and 1 pin for data. Where is VCC coming from? Via pull-up resistors connected to the data line and capacitance. I’ve seen MCUs run without direct VCC connections under these circumstances. Either that or the chip is connected to VCC and a PCB ground plane on the other side of the chip. Edit: boards are often sandwiched between VCC and GND layers. One could have a functioning device with just a few obvious “pins”/“leads”.
- kalleboo 8y agoThe Apple timeline in the Bloomberg article doesn't seem to make any sense. Apple found an "accidentally" malicious driver on a Super Micro board in 2016, and that caused them drop them right away. So if Apple found a batch of 7,000 manipulated boards a year earlier, why would that not cause them to drop Super Micro as a supplier? A government gag order is plausible, but is a government keep-buying-malicious-hardware order a thing?
- billylindeman 8y agoIn the case of investigating potentially state sponsored espionage I think it's plausible to keep buying the malicious hardware so the investigation can continue as they work their way up the supply chain.
- jasonlotito 8y ago> So if Apple found a batch of 7,000 manipulated boards a year earlier, why would that not cause them to drop Super Micro as a supplier? You don't want to tie the two events together. If the article is accurate, the hope would be that by waiting, the could garner support with comments like yours. e.g. Let's wait 6 months before you do something in response to something today so you can say that this has nothing to do with the even 6 months ago.
- flylib 8y agoBloomberg's reputation about take a big hit
- _iyig 8y agoThere’s an easy way for Bloomberg to prove, or least provide a great deal of support for, their story. Show us an affected motherboard. If this problem was so widespread and they have so many well-informed sources, surely that shouldn’t be difficult.
- whatever1 8y agoSince when is it easy to steal corporate equipment walk out from the premises and surrender it to third parties to take photos so that a random hacker news user feels satisfied ?
- myrandomcomment 8y agoLook I worked at a company that built boards in China. Every board is xrayed to verify every level of the board for every trace. They are matched vs. known good perfect board. If anything is wrong the board is destroyed. The boards I am talking about where complex 26+ layer boards which is way more then any standard motherboard. HW wise this is not impossiable, just improbable. The better method would be in software, replacing the on board system management software (intel ME) for example with a compromised version. That is very doable.
- andrewstuart2 8y agoI would think it would be much easier to validate software via simple hashing than physical hardware, via x-ray. Sure, you can verify traces, etc, but with current lithography at 14 nanometers, I have pretty much no doubt that there is no economical way to validate tens of thousands of meter-long boards.
- klodolph 8y agoYou don't necessarily have direct access to the storage system for the software you want to validate.
- myrandomcomment 8y agoYou could see every trace on the board at each layer. A chip like this story talks about would standout. Also at each point on the board you could probe (traces) end to end. It’s complex. Also the is the integery testing .. a machine that has 1000s of needles that pushes down on the top and bottom of the board at each contact point and test the resistance and conductivity end to end. Put something in the board in the path and the numbers come back wrong.
- myrandomcomment 8y agoSignal integrity is really important as it can lead to grey failures down the line. It is really important to find them before you stuff the boards with $$ of components that you can not save if the board is bad.
- myrandomcomment 8y agoOne interesting bit of fall out here would be companies moving out of China proof or no proof. One of the startups I worked at had fab in China and San Jose. The devices we sold to the government could only come from the US fabs. There were a few non-gov customers that insisted on the same.
- wincy 8y agoWhat was the price difference between US and China fab prices? 2x? 3x? 10x?
- myrandomcomment 8y agoFor us to build it? IIRC not 2x but enough that it made a difference.
- paulcarroty 8y agoWell, totally denial is PROFITABLE for Apple. They just "defend" his brands: our overpriced hardware is so special, you should paid to much! Absolute the same situations with slow down of their smartphones - whey info will be available for all, they just said "oh, we are so sorry!".
- RantyDave 8y agoThis whole thing is bollocks. If it were for real, we'd have the firmware dumped from that thing in minutes flat.
- PascLeRasc 8y agoI personally don't believe Bloomberg's reporting based on Apple and Amazon's strong denial and outright accusation of being misinformed, and that there's no third-party datacenter worker/homelabber posting that they've found this. But I'm glad this story has come up in the midst of the discussion on online voting machines. This kind of hardware manipulation would be much more powerful there and the hack Bloomberg describes is technically possible. The whole story reeks of this XKCD: https://xkcd.com/2030/ https://xkcd.com/2030/
- poolmaster 8y agoI am shocked that "hackers" here could believe the news are true. Go back to learn some college computer architecture and VLSI courses.
- ggggtez 8y agoI'm fairly amazed by the amount of skepticism here. A story this big is certain to get a lot of people looking into it. It would be pretty boneheaded for them to run a story like this with no evidence. I suggest the skeptics keep an open mind, instead of categorically denying it could be true, just because a couple of for-profit companies don't want to see their stock plummet the way Supermicro did. Nothing reported so far is out of the realm of plausible, considering the value of a successful supply-chain attack against tech companies.
- okket 8y agoThis is exactly why I am skeptical. Every detail in this story is plausible, but at whole it is just improbable. For a prior see https://en.wikipedia.org/wiki/BadBIOS https://en.wikipedia.org/wiki/BadBIOS
- dillondoyle 8y agoI am also shocked. Especially hearing the same BS talking points I see right now in US politics attacking credibility of news. No, reporters don't make up sources and an anonymous source reported by a big institution !== 'might as well be made up' as someone already commented in this thread. I would love to see some research on accounts and comments on HN similar to Twitter analysis post 16. Seems to me any time China is broached the HN thread gets more comments than average. Many posts read to me as strongly defensive or taking straw man/obfuscation type tactics. But then again that could be personal bias I don't know the actual human composition of HN comments - which is why I would love to see some research on HN comments/accounts.
- pawelmurias 8y ago> I am also shocked. Especially hearing the same BS talking points I see right now in US politics attacking credibility of news. Tons of news outlets abandoned credibility in the Trump era.
- AsyncAwait 8y ago> No, reporters don't make up sources and an anonymous source reported by a big institution !== 'might as well be made up' What would you call Iraq WMD stories?
- writepub 8y agoGiven the impasse, I'm inclined to believe one of two things: 1. US intelligence planted & played along for this story, for a long time. 2. The story is true on all fronts: i.e. those inside Apple with knowledge about this are lying to senior executives under immunity protection from US intelligence/law Personally, I think #2 to be a lot more likely - US intelligence has managed to sneak in backdoors into tech forever, in cahoots with sympathizers who probably have immunity agreements if outed.
- tapirl 8y agoIs there an article showing the concrete steps/evidences on how such small chips are used to steal info? If such a small chip can steal info, why can't the remaining other large quantity of "normal" chips on the same board?
- okket 8y agoOh, they can. See Intel Management Engine.
- Animats 8y agoMany people bought Supermicro motherboards. If this is real, we should be hearing more about it soon. There's so much attack surface at the motherboard "management" hardware level that some kind of attack wouldn't be all that hard.
- yuanotes 8y agoAs Chinese I think this is FAKE news. The people work in GOV in China know very little about technology. The smartest guy here don't work for GOV since those jobs are less paid.
- Havoc 8y agoWell I bought shares in supermicro & expect to make a tidy profit. There is just too much lined up against that single article...
- novaRom 8y agoSupermicro underperforms, especially Nvidia continues to win their traditional area of business. There is a small chance Nvidia will acquire Supermicro, but right now Supermicro is still too expensive for a company in decline.
- Havoc 8y agoIt took a 40% hit on news that has a high chance of being BS. That to me is worth a gamble
- novaRom 8y agoIt might be plausible this chip is not for spying, but rather a doomsday switch. It works like a switch which disables the whole system working correctly if enabled by a simple signal. There are many critical paths on the board which can be disabled with that very simple approach. You don't even need a sophisticated IC for that.
- kristofferR 8y agoThis story is good news regardless of who is right. Even if this attack actually didn't happen, you can be damn sure that the tech giants now massively will intensify efforts to prevent hardware hacks like this will ever happen to them.
- tanilama 8y agoI would believe Bloomberg if they had some detailed reports/demonstration as regards the mechanism of how this attack actually happens, not some nebulous picturing of some vague concepts the reporters themselves seem don't understand.
- phkahler 8y agoAnd now for wild speculation: What if the NSA or other US TLA was behind the hardware hack? While it would obviously require a coverup, I have no idea what leverage the government could have to keep it quiet - that would be a massive 1st amendment violation.
- amaccuish 8y agoOr, you know, it could be the NSA, since we've seen pictures of what they can do to a cisco router, and especially after the big web services made a push for TLS everywhere. Does anyone more knowledgable know if this must be an at-the-factory thing, or if it's possible to do this afterwards, "interdiction" as the bloomberg story put it?
- nachman 8y agoAs a long-time lurker, my turn to contribute: Look into Softbank.