Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

121–130 of 183 posts

Re: What Businessweek got wrong about Apple

#121
Political mind games.

Right now, most of the tech industry, and a good portion of the news media are at odds with the executive branch of the government.

This article puts at least one popular news outlet against several tech industry giants. Divide.

What comes after divide? ...and who has the most to gain? I doubt it's actually our executive branch. I think they could be getting played just as much as Bloomberg and the Tech industry.

Re: What Businessweek got wrong about Apple

#122
post #115

Earlier quoted context omitted.

Most places I know of isolate their OOB management network, requiring a vpn or jumpbox to access it. However, if someone did let their OOB network full outbound access, I could see this slipping through. I could imagine that simply going to a CDN or cloud provider like AWS/Cloudfront/cloudflare/akamai with a dns lookup along the lines of updates.supermicro.cdn-front.com wouldn't be too suspicious. At that point, you'…

Sounds like many things would have to go right in the defender's court. Optimism is not a good defense strategy :)

Heh. One colleague has "Hope is not a valid deployment strategy" as a signature.

Most places might be blocking this type of activity by default. For most of our security audits, it's just assumed that the SM IPMI or Dell idrac is vulnerable to one exploit or another. We mitigate that by controlling the traffic. I feel this is common practice in most places that understand vlans and firewalls.

However, while blocking is easy, being aware of something like this is on another level altogether. Unicorn jumping over a rainbow level rare. You really have to be logging outbound attempts and dns lookups. Where I work, there is a full security team and they are at an insane level where they log the allowed traffic. One told me that the allowed traffic is more interesting than the denied traffic. Denied just tells them what we anticipated, while active helps them establish a pattern and look for deviations.

Re: What Businessweek got wrong about Apple

#123
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Another option is the attacker has those companies "by the balls". They knew that the supply chain was completely compromized, and has been for a while. Admitting this, after so much time, is financial suicide in the best case. Maybe the companies are even being blackmailed by the attackers. Another twist, maybe someone in the government does not want this to come out officially, because they would be forced to take…

Puts these somewhat irrational Trump claims from July into context? *This is speculation/conspiracy, but if they've been looking into this for years, I could see the Trump admin using this as leverage to bring Apple manufacturing and/or offshore cash back to the US in exchange for covering up this alleged national security issue.

>https://www.businessinsider.com/trump-claims-again-apple-is-...

Re: What Businessweek got wrong about Apple

#124
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Why do you so blindly believe amzn/aapl over bloomberg? You do realize that reputation is a huge part of success, particularly in the security and hardware space. Of course amazon and apple will deny this story. For starters, they are probably under a gag order from the government to not leak anything regarding their findings since the investigation is still ongoing. Secondly, it is of no benefit to admit they failed in oversite on their side with this one.

Re: What Businessweek got wrong about Apple

#125

Earlier quoted context omitted.

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…

That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…

I'd appreciate a detailed explanation of the steps needed to get from putting this chip on a motherboard to actionable intelligence useful to a hostile nation state.

If we're talking about being able to make changes at the OS level, surely those should be relatively easy to spot?

If we're talking about copying packets, wouldn't that be useless under most circumstances?

If we're talking about doing whatever on a mass scale, surely most of the data would be junk and a huge and very clever backend would be needed to sift out the useful elements?

Presumably none of this is impossible, but I haven't yet seen a good description of how it's all supposed to fit together.

Re: What Businessweek got wrong about Apple

#126
post #122

Earlier quoted context omitted.

Sounds like many things would have to go right in the defender's court. Optimism is not a good defense strategy :)

Heh. One colleague has "Hope is not a valid deployment strategy" as a signature. Most places might be blocking this type of activity by default. For most of our security audits, it's just assumed that the SM IPMI or Dell idrac is vulnerable to one exploit or another. We mitigate that by controlling the traffic. I feel this is common practice in most places that understand vlans and firewalls. However, while blocking…

That's my point. Security people were analyzing network traffic for decades trying to spot something that doesn't fit, host-wise, pattern-wise or even packet-wise (see The Museum of Broken Packets[0], for example). And someone managed to somehow hide all this traffic from security experts working for Amazon and Apple, for months or years? I'm very curious to see how.

[0] http://lcamtuf.coredump.cx/mobp/

Re: What Businessweek got wrong about Apple

#127
post #43

Earlier quoted context omitted.

I'm not convinced which story is strictly the correct one yet but I don't think the strength of the denial is an argument for either. It just shows that it's important that your narrative wins, truth or not.

The burden of proof should be on the side pushing the accusations. In that sense, Apple’s denial puts it squarely back to Bloomberg to prove it’s not bulshit. Until then it would be fair to discard their narrative.

Hmmm... Sort of like Kavanaugh.

Re: What Businessweek got wrong about Apple

#128
post #41
post #13

Earlier quoted context omitted.

> Two possibilities: Left hand doesn't know (or can't know) what the right hand is doing at Apple. Top secret? I am sure the CEO must know both the hands, if the hands don't know each other. Also that Apple is going to release a strong denial must also have been known to Tim. I don't think that's the case here. Your second possibility looks more plausible.

If you talk to anyone with a TS/SCI clearance, you'll know that it is very common to be unable to discuss or divulge what you're working on to your superiors. There are MANY material things that CEOs do not know about TS/SCI information.

Can they say that "our servers /info" has been compromised? I mean, what's the point,Apple is not FBI /NSA owned. They have the right to know material things, even if specifics might be lacking.

Yes, looks like Apple dropped SuperMicro as their supplier in 2017. Why is that $64k question.

Re: What Businessweek got wrong about Apple

#129
DoD contracts for the military require the hardware to be sourced and made in the US to prevent compromise. I wonder if one day we will see the DoD require any Cloud contractor that has DoD datacenters to source from the US or NAFTA countries...and what impact that would have. I've heard ramblings about a lot of companies moving their manufacturing and sourcing from China to Vietnam already.

Re: What Businessweek got wrong about Apple

#130

From 2016: Report: Apple designing its own servers to avoid snooping Apple suspects that servers are intercepted and modified during shipping. "Apple has long suspected that servers it ordered from the traditional supply chain were intercepted during shipping, with additional chips and firmware added to them by unknown third parties in order to make them vulnerable to infiltration, according to a person familiar with…

Eh? Instead of verifying an existing design they'll just make one themselves? That could be compromised too?

Because using a 3rd party design you have to ask or guess what each chip does, and they might not want to tell you everything for IP reasons. When you create your own board, you know what every little chip and trace does exactly, and it's a lot easier to detect a rogue chip.
Post reply on HN