Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

91–100 of 183 posts

Re: What Businessweek got wrong about Apple

#91
post #56
post #53

The rice is indeed small, but it is not small on an IC chip. When people check the chip, they usually use a tool called microscope, like this https://goo.gl/1XK4YK .

And there is xray to detect what is inside a chip like this: https://www.youtube.com/watch?v=XXDsM3mUv3Y These are quite mature and popular technique. Rice is too big to be unnoticed....

No, you cant inspect inside chips with this Xray machine, its used for inspecting solder joints under the package.

Re: What Businessweek got wrong about Apple

#92
post #15

The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…

>Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the bottom. I imagine that would be very difficult to keep secret.

like offering cheaper, gray market source of capacitors to plant owners? that one got out what, 3 years after the fact? and only after hardware started dying en masse.

Re: What Businessweek got wrong about Apple

#93
Consider that Apple also stated this a few years back:

>"We have never heard of PRISM. We do not provide any government agency direct access to our servers, and any government agency requesting customer data must get a court order."

Their whole business is built around lying to customers.

Re: What Businessweek got wrong about Apple

#94
post #90
post #64

Earlier quoted context omitted.

This also illustrates why hardware implants do not work as a mass infiltration tool. The idea is not getting caught, otherwise risking the whole operation. Implementing a threat like this is counterproductive.

Intel ME seems pretty successful though.

This amazes me. Everyone freaks about the Chinese doing it, whereas we're surrounded by millions of computers doing the same thing - or at least able to - without us even knowing or being able to block it.

Re: What Businessweek got wrong about Apple

#95

Earlier quoted context omitted.

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…

That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time.

This, or the story is false, purposely or not.

Re: What Businessweek got wrong about Apple

#96

Very strong denial. Frankly, if true and Apple is saying this kind of a "no" shareholders will sue. Two possibilities: Left hand doesn't know (or can't know) what the right hand is doing at Apple. Top secret? Bloomberg was a victim of a hoax, some nation state (huh huhm!) wants to target China for something so they need a story. Based on what I've read here these past days, I'm leaning towards the second one. Apple c…

Assuming the story is true then acknowledging it would be more damaging that denying it (and they may have been directed to deny).

Remember also all the denials regarding PRISM.

If this is being correctly handled by the intelligence services (and you can have your doubts on that following these leaks) then nothing further will come out anyway.

For what it's worth, the Register mentions that Apple suddenly dropped Supermicro as a supplier.

The bottom line is that those denials don't really contribute much information.

Re: What Businessweek got wrong about Apple

#97
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

"before servers are put into production at Apple they are inspected for security vulnerabilities" A chip smaller than a grain of rice nested between motherboard layers. What tools could detect such a chip? While I don't doubt Apple inspects, the zero-day threat always exists.

Xray inspection by a human specialist

Re: What Businessweek got wrong about Apple

#98
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

> Either way, the proof is in the pudding: every hardware pentesting shop will be going after these boards like they're looking for golden tickets. Either we'll get our die shot, or Bloomberg's getting their pants sued off.

From the story, this seems to have happened several years ago.

I wouldn't be surprised if house cleaning had been done for some time.

If the story is true then I doubt that the Chinese would have flooded the market with these boards. It must have been relatively targeted.

Re: What Businessweek got wrong about Apple

#99
post #97

Earlier quoted context omitted.

"before servers are put into production at Apple they are inspected for security vulnerabilities" A chip smaller than a grain of rice nested between motherboard layers. What tools could detect such a chip? While I don't doubt Apple inspects, the zero-day threat always exists.

Xray inspection by a human specialist

Further in the article, Bloomberg mentions a chip, smaller than a pencil tip, sandwiched inside the PCB itself, under other traces. That seems bananas difficult to pull off, but could x-ray inspection find such a thing if it existed?

Re: What Businessweek got wrong about Apple

#100
> "As a matter of practice, before servers are put into production at Apple they are inspected for security vulnerabilities and we update all firmware and software with the latest protections."

They do not have equipment to detect this kind of attack, period. It's not viable for each device, and it's not even viable for sampling a subset of devices from a given production batch. Some components are physically inaccessible and would require desoldering of other components to even access them in any way.

These kinds of attacks cannot be generically detected in any economically feasible way; it must be prevented by drastically clamping down the supply chain and the logistics chain.

Post reply on HN