Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

111–120 of 183 posts

Re: What Businessweek got wrong about Apple

#111

Earlier quoted context omitted.

The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…

> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…

In France it is the "Arab telephone" !

Re: What Businessweek got wrong about Apple

#112
post #104
post #65

Earlier quoted context omitted.

Why would Apple and Amazon release such vehement denials, though? If it were an ongoing investigation, wouldn't they use more hedging and obfuscatory language? They could just as easily say "we're not aware of anything like this, but we take all allegations of this nature seriously and are looking into it". The whole situation is just odd.

For me, the Apple piece is not as black and white. > "Our best guess is that they are confusing their story with a previously-reported 2016 incident in which we discovered an infected driver on a single Super Micro server in one of our labs. That one-time event was determined to be accidental and not a targeted attack against Apple." They deny Bloomberg's specifics, but basically admit that the general attack vector…

That quote seems to be describing a software attack, not a hardware attack.

Re: What Businessweek got wrong about Apple

#113

Earlier quoted context omitted.

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

I think there is no way they would claim they are not under any gag order if they were forced to never confirm such an order, if there also is the option of not addressing it at all.

  I think there is no way they would claim they are not
  under any gag order if they were forced to never confirm
  such an order
I've always thought such denials are pointless.

You think everyone at Google knows every secret gag order they're under? Of course not, that would get leaked within minutes.

If I was the NSA I'd find a "patriotic" mid-level or junior employee with the power I wanted to subvert, and give them a gagging order that stopped them telling their boss.

That way the Google PR can honestly say that the CEO and legal team haven't seen or heard of a gagging order.

Re: What Businessweek got wrong about Apple

#114
post #23

The Norwegian National Security Authority ( https://nsm.stat.no/english/ ) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst...

This is completely anecdotal, but I'm on several mailing list for bulk buyers of off-lease server equipment. Typically these list are 90% Dell, HP, IBM. About 6 months ago I started to notice a huge percentage of SuperMicros being sold. Sometimes the whole list was nothing but SM servers.

Obviously could be many factors, but does strike me as odd.

Re: What Businessweek got wrong about Apple

#115

Earlier quoted context omitted.

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…

That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…

Most places I know of isolate their OOB management network, requiring a vpn or jumpbox to access it. However, if someone did let their OOB network full outbound access, I could see this slipping through. I could imagine that simply going to a CDN or cloud provider like AWS/Cloudfront/cloudflare/akamai with a dns lookup along the lines of updates.supermicro.cdn-front.com wouldn't be too suspicious. At that point, you'd be looking for dns lookups and not firewall hits.

If you are blocking outbound, I could still this going unnoticed if you're not actively reviewing denials.

But, if you are properly watching dns lookups from OOB and it's anything other than necessary services (ntp, ldap, syslog), then this would get picked up pretty quickly.

Re: What Businessweek got wrong about Apple

#116
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Another option is the attacker has those companies "by the balls". They knew that the supply chain was completely compromized, and has been for a while. Admitting this, after so much time, is financial suicide in the best case. Maybe the companies are even being blackmailed by the attackers.

Another twist, maybe someone in the government does not want this to come out officially, because they would be forced to take action against China.

On the other hand, maybe this is exactly what the government wants, so they "leak" this information - be it true or false - on purpose.

In the end, the world is so messed up currently that every conspiracy theory seems to be equally plausible.

Re: What Businessweek got wrong about Apple

#117
post #115

Earlier quoted context omitted.

That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…

Most places I know of isolate their OOB management network, requiring a vpn or jumpbox to access it. However, if someone did let their OOB network full outbound access, I could see this slipping through. I could imagine that simply going to a CDN or cloud provider like AWS/Cloudfront/cloudflare/akamai with a dns lookup along the lines of updates.supermicro.cdn-front.com wouldn't be too suspicious. At that point, you'…

Sounds like many things would have to go right in the defender's court. Optimism is not a good defense strategy :)

Re: What Businessweek got wrong about Apple

#118
post #71

Earlier quoted context omitted.

But why would anyone do this knowing that at some point they were practically guaranteed to get caught?

Because "getting caught"'s only consequence is that you have to use a new method. There is no punishment, no negative cost to be applied retroactively to compare it to the received benefits. The net effect still is highly positive since while it worked you got what you wanted. Same as in every spy operation, ever.

I'm not sure about that - this could really bolster the MAGA crowed, and I can imagine calls in the near future for manufacturing to be moved to the US. I doubt much will actually move, but it's a possibility.

Re: What Businessweek got wrong about Apple

#119

Earlier quoted context omitted.

The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…

> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…

I had never even heard the phrase until this thread. A quick google/wikipedia shows me it's the British term for what we in the US call "telephone". I guess I learned something new today.

https://en.wikipedia.org/wiki/Chinese_whispers#Etymology

> As the game is popular among children worldwide, it is also known under various other names depending on locality, such as Russian scandal,[3] whisper down the lane, broken telephone, operator, grapevine, gossip, don't drink the milk, secret message, the messenger game, and pass the message among others.[1] In France, it is called téléphone arabe (Arabic telephone) or téléphone sans fil (wireless telephone).[4][better source needed] In Malaysia, this game is commonly referred to as telefon rosak, which translates to broken telephone. In the United States, the game is known under the name telephone – which in this use is never shortened to the colloquial and more common word phone.

Re: What Businessweek got wrong about Apple

#120
post #108

Earlier quoted context omitted.

> "chinese whispers" Does anyone have a better phrase for this? A Chinese workmate called me out for using that phrase in his presence. Until then I had used the phrase since childhood without thinking that there were connotations and with nobody complaining. However, after that one fateful conversation I did see that my language could be improved. But how? Does anyone have a concise alternative that conveys the same…

Not a native speaker: Does it have additional meaning to the reference to the children's game where everyone whispers to their neighbor, passing a message along? If not, isn't that also known as the "telephone game"?

I was going to reply "I don't know, it's all Greek to me" but then decided that was not a good idea. So, [0] says

> Chinese whispers is the British term for what is known as the telephone game in the United States

and then lists several other names for the same game. I've also met people who when discussing confusing messages say "send three and fourpence, we're going to a dance", which is a result of 'Chinese whispers' being applied to the input "send reinforcements, we're going to advance". The reference to the pre-decimal coinage ('three and fourpence', i.e. three shillings and four pence, approx £0.17) in this old phrase shows how long the concept has been around in British English (we decimalised in 1971).

[0] https://en.wikipedia.org/wiki/Chinese_whispers

Post reply on HN