UK cyber security agency backs Apple, Amazon China hack denials
41–50 of 99 posts
Re: UK cyber security agency backs Apple, Amazon China hack denials
#42Re: UK cyber security agency backs Apple, Amazon China hack denials
#43It could also be possible that these companies are legally bound by some sort of investigation-related order to maintain ignorance to the presence of the chips and that Bloomberg have just sunk an ongoing investigation/counter-espionage operation, potentially putting an associated intelligence network at risk.
They're not "maintaining ignorance"; they're categorically denying it, and in significant detail. Both Apple and Amazon produced essentially bulleted refutations of the story. That's not what you do when you're trying to brush something off.
What makes you think the people denying it know about it though? E.g. if the head of Apple security got served an NSL, wouldn't that potentially prevent them from telling the company lawyers or the executive team?
Re: UK cyber security agency backs Apple, Amazon China hack denials
#44Re: UK cyber security agency backs Apple, Amazon China hack denials
#45Earlier quoted context omitted.
APPLE: > Finally, in response to questions we have received from other news organizations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations. https://daringfireball.net/linked/2018/10/04/what-businesswe...
FWIW, NSLs prevent you from talking about being under a NSL. I don't think they can be forced to lie, though
Re: UK cyber security agency backs Apple, Amazon China hack denials
#46It could also be possible that these companies are legally bound by some sort of investigation-related order to maintain ignorance to the presence of the chips and that Bloomberg have just sunk an ongoing investigation/counter-espionage operation, potentially putting an associated intelligence network at risk.
They're not "maintaining ignorance"; they're categorically denying it, and in significant detail. Both Apple and Amazon produced essentially bulleted refutations of the story. That's not what you do when you're trying to brush something off.
Re: UK cyber security agency backs Apple, Amazon China hack denials
#47Earlier quoted context omitted.
They're not "maintaining ignorance"; they're categorically denying it, and in significant detail. Both Apple and Amazon produced essentially bulleted refutations of the story. That's not what you do when you're trying to brush something off.
How is "we have found no evidence of..." categorically denying? They're doing exactly what parent says, turning a blind eye to it, and "truthfully" saying they haven't seen anything amiss.
Re: UK cyber security agency backs Apple, Amazon China hack denials
#48“We are aware of the media reports but at this stage have no reason to doubt the detailed assessments made by AWS and Apple,” This is a pretty mild statement, would not say it backs Apple and Amazon.
Re: UK cyber security agency backs Apple, Amazon China hack denials
#49Earlier quoted context omitted.
SuperMicro shareholders might.
Indeed. SuperMicro is the victim so far. If trustworthiness amounted for anything in today's world, all major news agencies would be out of business.
Re: UK cyber security agency backs Apple, Amazon China hack denials
#50It could also be possible that these companies are legally bound by some sort of investigation-related order to maintain ignorance to the presence of the chips and that Bloomberg have just sunk an ongoing investigation/counter-espionage operation, potentially putting an associated intelligence network at risk.
They're not "maintaining ignorance"; they're categorically denying it, and in significant detail. Both Apple and Amazon produced essentially bulleted refutations of the story. That's not what you do when you're trying to brush something off.
> That's not what you do when you're trying to brush something off.
It /could/ be what you do if good relations with the Chinese government are crucial to your business (true for both Apple and Amazon).
As for the UK NCSC, it's bizarre that they would comment at all. One possible motivation: eagerness to discover how to use such a backdoor themselves
> “The NCSC engages confidentially with security researchers and urges anybody with credible intelligence about these reports to contact us”