Earlier quoted context omitted.
The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…
> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…
What Businessweek got wrong about Apple
111–120 of 183 posts
Re: What Businessweek got wrong about Apple
#112Earlier quoted context omitted.
Why would Apple and Amazon release such vehement denials, though? If it were an ongoing investigation, wouldn't they use more hedging and obfuscatory language? They could just as easily say "we're not aware of anything like this, but we take all allegations of this nature seriously and are looking into it". The whole situation is just odd.
For me, the Apple piece is not as black and white. > "Our best guess is that they are confusing their story with a previously-reported 2016 incident in which we discovered an infected driver on a single Super Micro server in one of our labs. That one-time event was determined to be accidental and not a targeted attack against Apple." They deny Bloomberg's specifics, but basically admit that the general attack vector…
Re: What Businessweek got wrong about Apple
#113Earlier quoted context omitted.
Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…
I think there is no way they would claim they are not under any gag order if they were forced to never confirm such an order, if there also is the option of not addressing it at all.
I think there is no way they would claim they are not
under any gag order if they were forced to never confirm
such an order
I've always thought such denials are pointless.You think everyone at Google knows every secret gag order they're under? Of course not, that would get leaked within minutes.
If I was the NSA I'd find a "patriotic" mid-level or junior employee with the power I wanted to subvert, and give them a gagging order that stopped them telling their boss.
That way the Google PR can honestly say that the CEO and legal team haven't seen or heard of a gagging order.
Re: What Businessweek got wrong about Apple
#114The Norwegian National Security Authority ( https://nsm.stat.no/english/ ) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst...
Obviously could be many factors, but does strike me as odd.
Re: What Businessweek got wrong about Apple
#115Earlier quoted context omitted.
> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…
That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…
If you are blocking outbound, I could still this going unnoticed if you're not actively reviewing denials.
But, if you are properly watching dns lookups from OOB and it's anything other than necessary services (ntp, ldap, syslog), then this would get picked up pretty quickly.
Re: What Businessweek got wrong about Apple
#116Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…
Another twist, maybe someone in the government does not want this to come out officially, because they would be forced to take action against China.
On the other hand, maybe this is exactly what the government wants, so they "leak" this information - be it true or false - on purpose.
In the end, the world is so messed up currently that every conspiracy theory seems to be equally plausible.
Re: What Businessweek got wrong about Apple
#117Earlier quoted context omitted.
That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…
Most places I know of isolate their OOB management network, requiring a vpn or jumpbox to access it. However, if someone did let their OOB network full outbound access, I could see this slipping through. I could imagine that simply going to a CDN or cloud provider like AWS/Cloudfront/cloudflare/akamai with a dns lookup along the lines of updates.supermicro.cdn-front.com wouldn't be too suspicious. At that point, you'…
Re: What Businessweek got wrong about Apple
#118Earlier quoted context omitted.
But why would anyone do this knowing that at some point they were practically guaranteed to get caught?
Because "getting caught"'s only consequence is that you have to use a new method. There is no punishment, no negative cost to be applied retroactively to compare it to the received benefits. The net effect still is highly positive since while it worked you got what you wanted. Same as in every spy operation, ever.
Re: What Businessweek got wrong about Apple
#119Earlier quoted context omitted.
The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…
> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…
https://en.wikipedia.org/wiki/Chinese_whispers#Etymology
> As the game is popular among children worldwide, it is also known under various other names depending on locality, such as Russian scandal,[3] whisper down the lane, broken telephone, operator, grapevine, gossip, don't drink the milk, secret message, the messenger game, and pass the message among others.[1] In France, it is called téléphone arabe (Arabic telephone) or téléphone sans fil (wireless telephone).[4][better source needed] In Malaysia, this game is commonly referred to as telefon rosak, which translates to broken telephone. In the United States, the game is known under the name telephone – which in this use is never shortened to the colloquial and more common word phone.
Re: What Businessweek got wrong about Apple
#120Earlier quoted context omitted.
> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…
Not a native speaker: Does it have additional meaning to the reference to the children's game where everyone whispers to their neighbor, passing a message along? If not, isn't that also known as the "telephone game"?
> Chinese whispers is the British term for what is known as the telephone game in the United States
and then lists several other names for the same game. I've also met people who when discussing confusing messages say "send three and fourpence, we're going to a dance", which is a result of 'Chinese whispers' being applied to the input "send reinforcements, we're going to advance". The reference to the pre-decimal coinage ('three and fourpence', i.e. three shillings and four pence, approx £0.17) in this old phrase shows how long the concept has been around in British English (we decimalised in 1971).