Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

71–80 of 183 posts

Re: What Businessweek got wrong about Apple

#71
post #18
post #15

The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…

> Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the bottom. I imagine that would be very difficult to keep secret. Well the bloomberg article said that intelligence sources knew that those boards were going to Apple and Amazon, so presumably (if the story is true) someone did speak, maybe

But why would anyone do this knowing that at some point they were practically guaranteed to get caught?

Re: What Businessweek got wrong about Apple

#72
post #15

The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…

«Firstly, why would you add a new chip to a board, rather than alter an existing one?»

Altering the flash chip would be too obvious. Looking at the flash image (dumping it) or chip (x-raying it) would be the first thing anyone would do if they suspected something fishy. Swapping a flash chip with a compromised one is a textbook 101 supply chain attack...

However a small rogue chip sitting on the SPI link (between the flash chip and the BMC) can be very sneaky: it can replace legit code with evil code ONLY when the BMC is booting up and loading code from flash. The rogue chip would not do that when the flash is read for verification (think dieselgate: a VW car disabled cheats when it detected lab testing conditions!)

Also Bloomberg talks about this rogue chip being sometimes hidden within(!) the fiberglass layer of the PCB. This is the ultimate stealthy attack. No one expects the bare PCB itself to be already compromised by a backdoor even before components are soldered on it...

Re: What Businessweek got wrong about Apple

#73
post #72
post #15

The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…

« Firstly, why would you add a new chip to a board, rather than alter an existing one? » Altering the flash chip would be too obvious. Looking at the flash image (dumping it) or chip (x-raying it) would be the first thing anyone would do if they suspected something fishy. Swapping a flash chip with a compromised one is a textbook 101 supply chain attack... However a small rogue chip sitting on the SPI link (between t…

These are good points!

Re: What Businessweek got wrong about Apple

#74
Companies don’t give vehement denials like this unless they’re telling the truth. People claiming gag orders are crazy, mostly for thinking that Apple, or anyone else for that matter, would ever sign a document forcing them to lie to their customers (I’m not saying they wouldn’t lie, just that they wouldn’t sign anything that would force them to do so).

Re: What Businessweek got wrong about Apple

#76
post #29
post #23

The Norwegian National Security Authority ( https://nsm.stat.no/english/ ) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst...

What exactly did they know? Did they check anything themselves or did they hear the same story from the US IC that Bloomberg also heard? Supermicro servers are extremely popular in data centers. Yet no one has noticed anything and no one has found any malicious chips in them. Unless the Chinese secret services also hacked all of the firewalls, someone would have picked up some outgoing packets that are going to Chine…

My translation of the part pertaining to the national security authorities in Norway. Direct quotes from the authorities are shown as such:

--- NSM is aware of the issues with Supermicro.

"- We know about this, but can neither deny nor confirm it is correct. We register that this is being denied by the companies", says Monica Strom Arnoy, communication director in NSM to VG.

NSM has, however, been aware that Supermicro may have been compromised, long before Bloomberg's article.

"- We have known about this since June", says Strom Arnoy, who does not wish to further explain from where they have this information. ---

My reading is that they suspect Supermicro. Further, that they are familiar with the claims about Apple and Amazon but won't confirm or deny whether they are correct. Damming for Supermicro, less clear for Apple and Amazon

Re: What Businessweek got wrong about Apple

#77

From 2016: Report: Apple designing its own servers to avoid snooping Apple suspects that servers are intercepted and modified during shipping. "Apple has long suspected that servers it ordered from the traditional supply chain were intercepted during shipping, with additional chips and firmware added to them by unknown third parties in order to make them vulnerable to infiltration, according to a person familiar with…

Eh? Instead of verifying an existing design they'll just make one themselves? That could be compromised too?

Re: What Businessweek got wrong about Apple

#78
post #65

Earlier quoted context omitted.

Why would Apple and Amazon release such vehement denials, though? If it were an ongoing investigation, wouldn't they use more hedging and obfuscatory language? They could just as easily say "we're not aware of anything like this, but we take all allegations of this nature seriously and are looking into it". The whole situation is just odd.

Obviously to quiet their contractor and client fears. Shareholders know that replacing the hardware would be a major cost and PR damage intense.

It's still an odd strategic move though. They could get caught in the lie, in which case they would both be exposed to pretty serious legal and financial trouble.

Re: What Businessweek got wrong about Apple

#79
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

I think there is no way they would claim they are not under any gag order if they were forced to never confirm such an order, if there also is the option of not addressing it at all.

Re: What Businessweek got wrong about Apple

#80

Earlier quoted context omitted.

If this were true I would have expected some corporate waffle like "Apple takes supply chain security very seriously and regularly audits suppliers. We cannot comment on internal security matters but customers should be assured that blah blah blah." I wouldn't have expected this extremely strong denial which is one step short of outright calling Bloomberg liars.

No offense, but I think that your suggested statement would only lead to serious escalation for media enquiries, especially since this story came 2 days after the interview of the Apple CEO [1], where he underlined that privacy (and the relevant security measures) constitutes the core value of the company. [1] https://www.youtube.com/watch?v=VD1cP8SK3Q0

If Apple or Amazon are found to have lied in their statements I think they could be in serious legal trouble with both their customers but also (sadly, more importantly) their stock holders.
Post reply on HN