11 ms·
There should be hundreds of thousands or millions of these hacked motherboards, and nobody has found a single one despite hardware geeks worldwide searching lik
by jackconnor 8y ago
There should be hundreds of thousands or millions of these hacked motherboards, and nobody has found a single one despite hardware geeks worldwide searching like it was Willy Wonka's final golden ticket. This story was bogus, it most likely came from a ton of rumors that got conflated, hence why they had to go with anonymous sources as opposed to any physical evidence. I'd be surprised if Bloomberg has any credibility in tech journalism by the end of the year, and a good chance they may end up stuck in a courtroom trying to defend the decision to run this piece (on the front page, no less) for a long, long time.
- 1001101 8y ago> hardware geeks worldwide searching like it was Willy Wonka's final golden ticket. The stuff of dreams for security researchers.
- compcoffee 8y ago>I'd be surprised if Bloomberg has any credibility in tech journalism If the tech world turns their back on Bloomberg, I'll give them more credibility; not less.
- jackconnor 8y agoI'm curious too. This seems like a sides thing, and of course a lot of people are anti-tech these days. But, to side with the publisher of garbage tech journalism just because you don't like tech seems a little counter-productive. You can hate tech people without willfully believing things you know are false.
- wepple 8y agoI’m curious; why?
- ElBarto 8y agoAssuming the story is real it is quite obvious that there aren't that many compromised motherboards. It wouldn't make sense and it would make the attack easier to detect and to publicly incriminate the culprit. As the attack is said to have been discovered 3 years ago it is also not surprising that housekeeping has already been done a long time ago.
- genie514 8y agoSupermicro is a fairly large player (4th largest) and they still manufacture servers. If this story were indeed true, none of these companies or any other company buy their servers. The story is simply fake news.
- ElBarto 8y agoWho knows. Obviously no-one would have publicised this, so if you weren't involved you would have had no idea. The story does report that Amazon completely dropped Supermicro as a supplier following this alleged hack (that should be verifiable even if the reason given would obviously be different).
- fludlight 8y agoBig companies are now scandal proof. No amount of negligence or criminality is bad enough to bring one down. Wells Fargo committed millions of counts of bank fraud, yet they still exist and people buy their services. BP destroyed a large part of the economy and ecosystem in the Gulf of Mexico, yet they still exist and people buy their products. One of their top lawyers just became Assistant Attorney General for the Department of Justice’s Environment and Natural Resources Division. VW built millions of cars with hardware designed to fake emissions testing data, yet they still exist and people buy their services.
- simonh 8y agoCrimes are committed by individuals, not companies. If execs at VW break the law, you go after the execs, you don’t put the whole company in jail or turf out all it’s employees on the streets.
- hexane360 8y agoI'd be on board with this position if it was applied consistently. But it's not. Companies take political action, companies take credit for innovation, etc. The whole basis of a company is that it limits the liability of the people who own it.
- ihuman 8y ago> they had to go with anonymous sources as opposed to any physical evidence What do you mean by the second part of this? Bloomberg should have received examples of comprised boards?
- wmeredith 8y agoI would say exactly that.
- deleted 8y ago[deleted]
- FractalParadigm 8y agoIf not received explicit examples, at the very least they should have been given some potentially affected SKUs to examine off-the-shelf boards.
- henryfjordan 8y agoOr gone to AWS/Apple and club and asked them to investigate before publishing...
- simonh 8y agoAccording to Bloomberg Apple and AWS had already investigated thoroughly, had talked to the government, and their executives were the ones who had leaked to Bloomberg in the first place.
- Operyl 8y agoThey did. Apple said they did 3 separate times, and in all times found absolutely nothing. Bloomberg chose to publish the story anyway.
- karavelov 8y agoPublished along the initial story were strong refutations from Apple, Amazon, Super Micro and Chinese Goverment. Some of them suggested that this is not the fist request from Bloomberg, so much that companies got annoyed to refute baseless speculations (see Apple response). So Bloomberg consulted with the companies and published despite the strong denials from all sides.
- sonnyblarney 8y ago"There should be hundreds of thousands or millions of these hacked motherboards" No, the boards would be selectively hacked. And we know it happens because 'we' do it as well. Surely there is evidence floating around but it's also unlikely that companies would want to admit the breach. I kind of believe Apple and Amazon though, there's too much risk if they were to be caught lying. This is a weird one ...
- jorblumesea 8y agoBut surely there's at least a few thousand of the hacked boards? The article mentioned a data center and entire companies being targeted. All it would take is someone to dig up some junked boards, unless they were intentionally destroyed to hide evidence. Unlike 0 days or other issues, this seems like it would be easy to reproduce. Just need to find the boards.
- sonnyblarney 8y agoThings are hacked often with a specific facility or installation in mind. It could be as little has a handful and that'd be enough to compromise a lot. I actually don't care what the truth [edit: truth of this specific BMRG story] is - the West needs a 'wake up call' on this one and any company installing hardware should be inspecting everything that comes in. Too much lax security out there, sadly, the US gov I don't think is competent enough in this area to provide guidelines. I wish there was a CIO right in the White House cabinet, who could work with the Valley + Security experts to provide minimum guidelines for everyone, and to make everyone aware of certain things. I'm glad the internet was designed to be 'open first' but not glad it was designed to be almost inherently insecure as well. 'Open but Secure' by default would be nice :)
- drb91 8y ago> I actually don't care what the truth is Why are you in this thread at all then?
- 8y ago
- deleted 8y ago[deleted]
- draw_down 8y agoExactly- where are they?! The Bloomberg story made verifiable claims (perhaps not exactly falsifiable due to their nature), so where is the verification? It's so strange to see people continue running with "they wouldn't have doubled down unless they were really certain, so it must be true".
- oh_sigh 8y agoWill they name their anonymous sources if it turns out they were played by them?
- gpm 8y agoProbably if they could prove it - but it's hard to imagine what they could find that would constitute proof.
- chenster 8y agoBloomberg probably has its own political agenda (guess who's administration is behind this?) for fabricating such elaborated fake news.
- stupidbird 8y ago>most likely came from a ton of rumors that got conflated, hence why they had to go with anonymous sources Just noting that anonymous sources aren't unknown sources — if Bloomberg says that these are people working in US Intelligence then they've very likely validated it, but are protecting their identities by request. Also worth noting that Amazon and Apple have a tremendous amount to lose here. That doesn't mean they're lying, but based no what we know, they have more incentive to lie than Bloomberg does. Also possible that they're already working with the government and have been asked to lie about it due to national security. Totally possible that Bloomberg was intentionally mislead or flat-out wrong either way. It just sounds like they've done the due diligence of checking with an abundance of sources, so it would be odd. They've made mistakes before, but I don't know that they've ever made one of this magnitude. The decision to publish or not publish a story like this isn't something that one person working at Bloomberg does on a whim, many people are involved. All other things aside, I tend to trust journalists more than corporations. There's not a lot of room to jump to a conclusion either way. Very solid 'maybe' territory all around.
- paxys 8y agoWhile something like this will no doubt be damaging to some large American tech companies, it is way worse for China. Are they really going to potentially devastate their entire economy over the long term over such an easy to detect hack?
- mschuster91 8y ago> Are they really going to potentially devastate their entire economy over the long term over such an easy to detect hack? That didn't make the NSA afraid of targeted interception campaigns. I believe that secret services are doing everything we normal people dream of already, including stuff such as the hardware injections either in the Supermicro case or in the stuff the NSA did, and a good bunch more which we don't even know of yet. Cyber warfare is all too real now.
- stupidbird 8y agoWe already know that they're constantly trying to hack American IP. Our economies are symbiotic. Hurting theirs would be hurting our own.
- deleted 8y ago[deleted]
- tootie 8y agoI doubt Bloomberg is that eager to dig a hole for itself. I wouldn't be surprised if someone with a vendetta was feeding them cooked information and fabricating a lot of very convincing evidence. That's pure speculation, but I just don't belligerent Bloomberg would run such an explosive story unless they were convinced it was true.
- VectorLock 8y agoWe all know somebody has to be obtaining these boards, finding the alleged malicious grains of rice and testing them to see if they are in fact just passive components? Where are they? Where is their presentation of finding nothing?
- deleted 8y ago[deleted]