The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…
> Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the bottom. I imagine that would be very difficult to keep secret. Well the bloomberg article said that intelligence sources knew that those boards were going to Apple and Amazon, so presumably (if the story is true) someone did speak, maybe
What Businessweek got wrong about Apple
71–80 of 183 posts
Re: What Businessweek got wrong about Apple
#72The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…
Altering the flash chip would be too obvious. Looking at the flash image (dumping it) or chip (x-raying it) would be the first thing anyone would do if they suspected something fishy. Swapping a flash chip with a compromised one is a textbook 101 supply chain attack...
However a small rogue chip sitting on the SPI link (between the flash chip and the BMC) can be very sneaky: it can replace legit code with evil code ONLY when the BMC is booting up and loading code from flash. The rogue chip would not do that when the flash is read for verification (think dieselgate: a VW car disabled cheats when it detected lab testing conditions!)
Also Bloomberg talks about this rogue chip being sometimes hidden within(!) the fiberglass layer of the PCB. This is the ultimate stealthy attack. No one expects the bare PCB itself to be already compromised by a backdoor even before components are soldered on it...
Re: What Businessweek got wrong about Apple
#73The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…
« Firstly, why would you add a new chip to a board, rather than alter an existing one? » Altering the flash chip would be too obvious. Looking at the flash image (dumping it) or chip (x-raying it) would be the first thing anyone would do if they suspected something fishy. Swapping a flash chip with a compromised one is a textbook 101 supply chain attack... However a small rogue chip sitting on the SPI link (between t…
Re: What Businessweek got wrong about Apple
#74Re: What Businessweek got wrong about Apple
#75Re: What Businessweek got wrong about Apple
#76The Norwegian National Security Authority ( https://nsm.stat.no/english/ ) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst...
What exactly did they know? Did they check anything themselves or did they hear the same story from the US IC that Bloomberg also heard? Supermicro servers are extremely popular in data centers. Yet no one has noticed anything and no one has found any malicious chips in them. Unless the Chinese secret services also hacked all of the firewalls, someone would have picked up some outgoing packets that are going to Chine…
--- NSM is aware of the issues with Supermicro.
"- We know about this, but can neither deny nor confirm it is correct. We register that this is being denied by the companies", says Monica Strom Arnoy, communication director in NSM to VG.
NSM has, however, been aware that Supermicro may have been compromised, long before Bloomberg's article.
"- We have known about this since June", says Strom Arnoy, who does not wish to further explain from where they have this information. ---
My reading is that they suspect Supermicro. Further, that they are familiar with the claims about Apple and Amazon but won't confirm or deny whether they are correct. Damming for Supermicro, less clear for Apple and Amazon
Re: What Businessweek got wrong about Apple
#77From 2016: Report: Apple designing its own servers to avoid snooping Apple suspects that servers are intercepted and modified during shipping. "Apple has long suspected that servers it ordered from the traditional supply chain were intercepted during shipping, with additional chips and firmware added to them by unknown third parties in order to make them vulnerable to infiltration, according to a person familiar with…
Re: What Businessweek got wrong about Apple
#78Earlier quoted context omitted.
Why would Apple and Amazon release such vehement denials, though? If it were an ongoing investigation, wouldn't they use more hedging and obfuscatory language? They could just as easily say "we're not aware of anything like this, but we take all allegations of this nature seriously and are looking into it". The whole situation is just odd.
Obviously to quiet their contractor and client fears. Shareholders know that replacing the hardware would be a major cost and PR damage intense.
Re: What Businessweek got wrong about Apple
#79Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…
Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…
Re: What Businessweek got wrong about Apple
#80Earlier quoted context omitted.
If this were true I would have expected some corporate waffle like "Apple takes supply chain security very seriously and regularly audits suppliers. We cannot comment on internal security matters but customers should be assured that blah blah blah." I wouldn't have expected this extremely strong denial which is one step short of outright calling Bloomberg liars.
No offense, but I think that your suggested statement would only lead to serious escalation for media enquiries, especially since this story came 2 days after the interview of the Apple CEO [1], where he underlined that privacy (and the relevant security measures) constitutes the core value of the company. [1] https://www.youtube.com/watch?v=VD1cP8SK3Q0