Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

51–60 of 183 posts

Re: What Businessweek got wrong about Apple

#51
post #29
post #23

The Norwegian National Security Authority ( https://nsm.stat.no/english/ ) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst...

What exactly did they know? Did they check anything themselves or did they hear the same story from the US IC that Bloomberg also heard? Supermicro servers are extremely popular in data centers. Yet no one has noticed anything and no one has found any malicious chips in them. Unless the Chinese secret services also hacked all of the firewalls, someone would have picked up some outgoing packets that are going to Chine…

The article suggested the chips were hidden under components. You would have to tear apart the motherboard and know what to expect exactly. The number of companies who do this kind of audit must be in the single digit if any.

Now the article may or may not be a hoax, but a few years ago the NSA was exposed doing exactly that. So at the very least it is credible.

As for detection, I’d rather expect this devices to be activated on demand, like creating a backdoor, rather than sending streams of data from all servers, most of which (per the article) will be owned by an adult website or a mormon church which aren’t exactly strategic activities.

Re: What Businessweek got wrong about Apple

#52
This article sounded a bit weird to me from the technical level, but I just assumed it could be lack of clear understanding on the nitty-gritty from the journalist, or just me not knowing about hardware enough to know what's possible and how.

Given this is all getting a little fishy I'll share what had me thinking:

1. The article mentions "they were capable of doing two very important things: telling the device to communicate with one of several anonymous computers elsewhere on the internet..."

Servers tend to run on VPNs. This being a dormant backdoor is believable, but then the article mentions:

> "American investigators eventually figured out who else had been hit. Since the implanted chips were designed to ping anonymous computers on the internet for further instructions, operatives could hack those computers to identify others who’d been affected."

Which makes me believe the devices were active and somehow circumvented corporate VPNs. I'm unsure how undetectable this could be using the system's network stack (or if it would be possible at all)-- would the claim then be that this tiny device shipped with a whole TCP/IP layer and some sort of very powerful wireless capability?

2. It continues with: "and preparing the device’s operating system to accept this new code"

Is this possible? Where would a device like this need to be wired to be able to write to memory with some arbitrary payload to do this? From the pictures it looks like it has 6 pins maximum-- could this do? If so, wouldn't this mean this device would need to do some next-level signal processing that would probably require advanced computation? Could said computation be done by a processing unit that fits the size of this chip?

Moreover, assuming it takes control of the OS independently would imply there's some decent amounts of memory in here, to hold the payload, etc. no? But if it's just a backdoor that doesn't take control of the OS, then how is it communicating over the internet with other machines like the article claims?

Again, I might be wrong and things that I don't think possible might. I'm mostly just curious to know if my intuition is too naive. Please comment below if you know more about these things than I do.

EDIT: I was really disappointed that the article itself didn't go into these technicalities, because IMO this would be an impressive feat and newsworthy by itself. The lack of alternative coverage in sources more close to technical expertise was weird to me.

Re: What Businessweek got wrong about Apple

#54
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

My general response whenever there is something like this: Look at the past stories by the reporter. Bloomberg handily lists them for you. https://www.bloomberg.com/authors/AQrv1y2ieI0/jordan-roberts... Take a look at those stories in the strong light of being able to see them in retrospect and decide for yourself if this reporter is prone to going to press without a full understanding of the situation. I have my opi…

The headlines are somewhat over-the-top, but none of those articles show examples of them deliberately making up a story.

I wouldn't read it, because they seem to repeatedly overstate the possible impact of their stories. But if you work in the space, or are the victim of an attack, this thread-level-orange style of writing may feel entirely appropriate.

It's no different than, say, insinuating that something is wrong with . But instead of clearly explaining the criticism, to "let smart people figure it out for themselves". That's the laziest conspiracy sales tactic, and it exploits peoples' insecurities by tying the carrot ("I'm one of the smart ones!") to the stick of accepting whatever theory is being peddled.

Re: What Businessweek got wrong about Apple

#55
post #17

Earlier quoted context omitted.

Matt Levine likes to say that "everything is securities fraud".

Funnily enough, he actually covered this angle yesterday! Regular readers know that a major theme of this newsletter is Everything Is Securities Fraud, so in that vein, let us consider a hypothetical. What if: 1. Everything in the Businessweek story is true, Chinese spies planted hardware backdoors in computers built and used by major American companies, and the FBI investigated along with those companies and discove…

Pushing the conspiracy theory just for the sake of argument. You could imagine that some employees have been in contact with the NSA about these chips and been told that they cannot disclose anything to their employers. The management of Apple would deny the claim in good faith. It would be hard to make a claim that Apple meant to mislead investors.

Re: What Businessweek got wrong about Apple

#56
post #53

The rice is indeed small, but it is not small on an IC chip. When people check the chip, they usually use a tool called microscope, like this https://goo.gl/1XK4YK .

And there is xray to detect what is inside a chip like this: https://www.youtube.com/watch?v=XXDsM3mUv3Y

These are quite mature and popular technique.

Rice is too big to be unnoticed....

Re: What Businessweek got wrong about Apple

#57
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

[deleted]

Re: What Businessweek got wrong about Apple

#58
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

It's certainly beginning to look like Bloomberg got played. I don't know what the motivation would be for Bloomberg to deliberately deceive readers, but I can't help notice that the article came out at roughly the same time as Mike Pence was giving a speech whose central premise was that China is meddling in american politics, and all the attention currently focused on Russian hacking should be focused on Chinese hac…

Did you miss the other hacking news from yesterday?

https://www.cnbc.com/2018/10/04/doj-charges-7-russian-intell...

Re: What Businessweek got wrong about Apple

#59
post #3

My personal theory is this is a ploy to get people to believe Trump's anti-china narrative meant to distract from the Russia narrative.

As an outside observer of us politics it seems to me that the democrats want Russia as an external enemy whereas the republicans want China. Perhaps now it seems like the republicans have the upper hand but it is not obvious how it is going to end.

Re: What Businessweek got wrong about Apple

#60
post #51
post #29

Earlier quoted context omitted.

What exactly did they know? Did they check anything themselves or did they hear the same story from the US IC that Bloomberg also heard? Supermicro servers are extremely popular in data centers. Yet no one has noticed anything and no one has found any malicious chips in them. Unless the Chinese secret services also hacked all of the firewalls, someone would have picked up some outgoing packets that are going to Chine…

The article suggested the chips were hidden under components. You would have to tear apart the motherboard and know what to expect exactly. The number of companies who do this kind of audit must be in the single digit if any. Now the article may or may not be a hoax, but a few years ago the NSA was exposed doing exactly that. So at the very least it is credible. As for detection, I’d rather expect this devices to be…

well, the article said that amazon noticed pings to c&c servers in its beijing datacentre. it did also say that these were more sophisticated hardware attacks but didn’t make it clear if these chips were also found
Post reply on HN