Live data from Hacker News

The Big Hack: The Software Side of China’s Supply Chain Attack

bloomberg.com

21–30 of 31 posts

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#21

AWS Reply: https://aws.amazon.com/blogs/security/setting-the-record-str...

> We further strengthen our security posture by implementing our own hardware designs for critical components such as processors, (...)

Do they? I haven't heard about this before.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#22
post #5

That secret "Chinese weapon" you hold on your finger tip is a very common electronic component called the signal conditioning balun, worth $0.29 and sold here https://www.mouser.com/ProductDetail/TDK/HHM1932A2?qs=6JAMGB... . The Bloomberg report can really win the Ignorance and Stupidity Award of this year.

My word... You have quite the narrow comment history...

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#23
post #4

The Norwegian national security agency has confirmed that they were aware of the allegations against SuperMicro since June, but they won't confirm if it's true (nor are they denying it) and they noted that they are also aware that Amazon/Apple are denying it. As for why Apple/Amazon are denying it I wonder if it's because they don't want to burn bridges. If they confirm the allegations, how would that play out in the…

My guess is Gag order for the US govt.

A gag order cannot force you to say something. That would be government compelled speech, which is generally frowned upon by courts, to put it mildly.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#24
This has been posted several times and there are tons of comments:

[1]: https://news.ycombinator.com/item?id=18146438 [2]: https://news.ycombinator.com/item?id=18138328 [3]: https://news.ycombinator.com/item?id=18145645 [4]: https://news.ycombinator.com/item?id=18138990 [5]: https://news.ycombinator.com/item?id=18141328

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#25

This has been posted several times and there are tons of comments: [1]: https://news.ycombinator.com/item?id=18146438 [2]: https://news.ycombinator.com/item?id=18138328 [3]: https://news.ycombinator.com/item?id=18145645 [4]: https://news.ycombinator.com/item?id=18138990 [5]: https://news.ycombinator.com/item?id=18141328

[deleted]

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#27
post #19
post #17

Earlier quoted context omitted.

But they don't, they explicitly mentioned they are not under a gag order, which is the first thing you are forbidden to mention when you are gagged. That is the reason why "warrant canaries" exist. https://en.wikipedia.org/wiki/Warrant_canary

I think what GP was suggesting is that lower level employees might be under individual gag order, keeping them from ever reporting the incident to their higher ups (including those responsible for the warrant canary).

[deleted]

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#28
post #23

Earlier quoted context omitted.

My guess is Gag order for the US govt.

A gag order cannot force you to say something. That would be government compelled speech, which is generally frowned upon by courts, to put it mildly.

No, but a gag order can prohibit you from saying something specifically with regard to national security issues.

So downvote away, but these documents do exist and these circumstances can and will happen.

In fact, everyone impacted by Aurora, were strictly under gag orders during the onset of that investigation too.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#29

AWS Reply: https://aws.amazon.com/blogs/security/setting-the-record-str...

> We further strengthen our security posture by implementing our own hardware designs for critical components such as processors, (...) Do they? I haven't heard about this before.

Yes, AWS rolls its own hardware in some cases.

Re: The Big Hack: The Software Side of China’s Supply Chain Attack

#30
> “In 2015, we were made aware of malicious manipulation of software related to Supermicro hardware from industry partners through our threat intelligence industry sharing programs,” Facebook said in an emailed statement. “While Facebook has purchased a limited number of Supermicro hardware for testing purposes confined to our labs, our investigations reveal that it has not been used in production, and we are in the process of removing them.”

Facebook confirmed this happened. But looks like Apple and Amazon are denying it.

Post reply on HN