Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

101–110 of 183 posts

Re: What Businessweek got wrong about Apple

#101
post #74

Companies don’t give vehement denials like this unless they’re telling the truth. People claiming gag orders are crazy, mostly for thinking that Apple, or anyone else for that matter, would ever sign a document forcing them to lie to their customers (I’m not saying they wouldn’t lie, just that they wouldn’t sign anything that would force them to do so).

That makes no sense. What do you think is the difference in "denial levels"? Kind of like Dragonball-Z power levels? Does a "vehement denial" cost the one making it any more than a "meek denial"? If making "vehement denials", coming at exactly the same cost as less strong denials, are more effective, you would just have made all PR companies/people extremely happy - they get a stringer weapon for free. All the have t…

Maybe vehemence isn't the right measure. It would be better to say specificity. "The allegations are false" leaves more wiggle room then to say "we don't have a business relationship with Suoermicro and a Company called Apple doesn't even exist".

Re: What Businessweek got wrong about Apple

#103
post #65

Earlier quoted context omitted.

Why would Apple and Amazon release such vehement denials, though? If it were an ongoing investigation, wouldn't they use more hedging and obfuscatory language? They could just as easily say "we're not aware of anything like this, but we take all allegations of this nature seriously and are looking into it". The whole situation is just odd.

Obviously to quiet their contractor and client fears. Shareholders know that replacing the hardware would be a major cost and PR damage intense.

Replacing the hardware would be cheap compared to the hit they could take getting caught in such an outright lie. Public companies have obligations to their shareholders not to lie about things like this. They're opening themselves up to lawsuits.

Re: What Businessweek got wrong about Apple

#104
post #65

Earlier quoted context omitted.

The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…

Why would Apple and Amazon release such vehement denials, though? If it were an ongoing investigation, wouldn't they use more hedging and obfuscatory language? They could just as easily say "we're not aware of anything like this, but we take all allegations of this nature seriously and are looking into it". The whole situation is just odd.

For me, the Apple piece is not as black and white.

> "Our best guess is that they are confusing their story with a previously-reported 2016 incident in which we discovered an infected driver on a single Super Micro server in one of our labs. That one-time event was determined to be accidental and not a targeted attack against Apple."

They deny Bloomberg's specifics, but basically admit that the general attack vector very much works.

Re: What Businessweek got wrong about Apple

#105
post #97

Earlier quoted context omitted.

Xray inspection by a human specialist

Further in the article, Bloomberg mentions a chip, smaller than a pencil tip, sandwiched inside the PCB itself, under other traces. That seems bananas difficult to pull off, but could x-ray inspection find such a thing if it existed?

I specifically mention non-automatic inspection as automatic one may well not have the "paranoid mode," unlike a human who specifically told to go over every individual square millimetre.

Re: What Businessweek got wrong about Apple

#106
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…

> "chinese whispers"

Does anyone have a better phrase for this?

A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how?

Does anyone have a concise alternative that conveys the same thing without implying anything about how Chinese people communicate in whispers, to get things wrong?

Re: What Businessweek got wrong about Apple

#107
post #97

Earlier quoted context omitted.

Xray inspection by a human specialist

Further in the article, Bloomberg mentions a chip, smaller than a pencil tip, sandwiched inside the PCB itself, under other traces. That seems bananas difficult to pull off, but could x-ray inspection find such a thing if it existed?

Yes, because the incident they reference was a mid-PCB-layer chip discovered by govt agencies using X-rays. The findings were presented at a private conference in Virginia. Sources who attended said "they've seen the xray pictures" etc.

Re: What Businessweek got wrong about Apple

#108

Earlier quoted context omitted.

The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…

> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…

Not a native speaker: Does it have additional meaning to the reference to the children's game where everyone whispers to their neighbor, passing a message along? If not, isn't that also known as the "telephone game"?

Re: What Businessweek got wrong about Apple

#109
I would say one specific detail (I haven't looked at it though) would challenge the truth of the rebuttal of both Amazon and Apple is that if it is confirmed that both have severed ties with Supermicro around the same time, the coincidence would really seem odd then.

Re: What Businessweek got wrong about Apple

#110

Earlier quoted context omitted.

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…

That is a good question, did the Chinese target specific customers, identifying the relevant sub-contractors and modify these boards?

Or are these boards commercial-of-the-shelf things that are mass produced?

In the latter case these boards can just end up anywhere, in the first case not so much. As a result using commodity boards would provide some degree of protection against such an attack as slipping a manipulated one into a specific target's servers would be a game of chance. Also the risk that the attack is discovered would be much higher.

Post reply on HN