Live data from Hacker News

The Big Hack: The Software Side of China’s Supply Chain Attack

bloomberg.com

1–10 of 31 posts

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#3
Well one can definitely say that the people at Bloomberg don’t doubt their story. Is it at all possible that higher ups making statements from Apple or Amazon didn’t know? Even if so, I don’t see any way for some sides credibility to not be severely harmed by the end of this.

And Facebook now enters the fray, saying there was an attack (though doesn’t seem to be claiming they were effected by the chip in previous article?)

Edit - I read the dates of the articles wrong, and thought this was a new one this morning. It was posted alongside the original story, but main point of comment still stands so keeping it up.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#4
The Norwegian national security agency has confirmed that they were aware of the allegations against SuperMicro since June, but they won't confirm if it's true (nor are they denying it) and they noted that they are also aware that Amazon/Apple are denying it.

As for why Apple/Amazon are denying it I wonder if it's because they don't want to burn bridges. If they confirm the allegations, how would that play out in the Chinese business world?

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#5
That secret "Chinese weapon" you hold on your finger tip is a very common electronic component called the signal conditioning balun, worth $0.29 and sold here https://www.mouser.com/ProductDetail/TDK/HHM1932A2?qs=6JAMGB.... The Bloomberg report can really win the Ignorance and Stupidity Award of this year.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#6
post #3

Well one can definitely say that the people at Bloomberg don’t doubt their story. Is it at all possible that higher ups making statements from Apple or Amazon didn’t know? Even if so, I don’t see any way for some sides credibility to not be severely harmed by the end of this. And Facebook now enters the fray, saying there was an attack (though doesn’t seem to be claiming they were effected by the chip in previous art…

Their account seems pretty solid and the story itself I think is less incredible than what Snowden leaked: a password check bypass on the hardware remote access systems is all they need basically.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#7
post #3

Well one can definitely say that the people at Bloomberg don’t doubt their story. Is it at all possible that higher ups making statements from Apple or Amazon didn’t know? Even if so, I don’t see any way for some sides credibility to not be severely harmed by the end of this. And Facebook now enters the fray, saying there was an attack (though doesn’t seem to be claiming they were effected by the chip in previous art…

Is it possible that only lower level Apple/Amazon employees were involved in the investigation and that they are forbidden from telling anyone else, even senior legal executives?

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#8
post #4

The Norwegian national security agency has confirmed that they were aware of the allegations against SuperMicro since June, but they won't confirm if it's true (nor are they denying it) and they noted that they are also aware that Amazon/Apple are denying it. As for why Apple/Amazon are denying it I wonder if it's because they don't want to burn bridges. If they confirm the allegations, how would that play out in the…

Well, all of the above mentioned want a slice of Chinese pie.

I'd say that market linkage in between China and USA in tech was just beginning to heal up after the credit crisis, but before that Chinese companies were rather wary of going to USA because it is expensive and risky market to enter, and instead chose easier markets for overseas expansion.

As any hope of rapprochement is now done for, they will revert to their old ways.

Comrades from AS4134 must be now scrambling everybody and everything into damage control mode. I think they firmly believed that they had an impenetrable cover.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#9
post #5

That secret "Chinese weapon" you hold on your finger tip is a very common electronic component called the signal conditioning balun, worth $0.29 and sold here https://www.mouser.com/ProductDetail/TDK/HHM1932A2?qs=6JAMGB... . The Bloomberg report can really win the Ignorance and Stupidity Award of this year.

Obviously they didn't get a hold of an actual chip, they just claim they were made to look inconspicuous (like a signal conditioning coupler).

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#10
post #7
post #3

Well one can definitely say that the people at Bloomberg don’t doubt their story. Is it at all possible that higher ups making statements from Apple or Amazon didn’t know? Even if so, I don’t see any way for some sides credibility to not be severely harmed by the end of this. And Facebook now enters the fray, saying there was an attack (though doesn’t seem to be claiming they were effected by the chip in previous art…

Is it possible that only lower level Apple/Amazon employees were involved in the investigation and that they are forbidden from telling anyone else, even senior legal executives?

It's actually possible they have a National Security Gag order. If that's the case they could only deny anyway.
Post reply on HN