Earlier quoted context omitted.
The Bloomberg article specifically claimed that Apple themselves discovered the chip in a random spot check. If an Apple employee discovered it, it would have been communicated all the way up to the executive level prior to notifying anyone outside the company (such as the FBI), which means you can't just chalk this up to a handful of lower-level Apple employees being covered by a gag order and the executives not kno…
It also claimed Apple removed 7000 SuperMicro servers in a few weeks. That seems especially unlikely to happen without at least some explanations to upper management. Sure, they could lie to management about why but either way management can’t then claim no servers were removed without lying themselves.
New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
361–370 of 379 posts
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#362Earlier quoted context omitted.
Yeah - when I add to it that, as a non-American, I can (annectodaly) observe a rise in different kinds of news that involve China in a negative context for the last 6m especially, it's hard to form an opinion. In terms of security concerns also - come on, we know by now to which lengths the US goes in this area, and they're surely doing worse stuff than this, I'd expect no one would doubt it any more. So, either they…
Still doesn’t mean you shouldn’t be concerned by China’s super position in the global supply chain...
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#363Bloomberg really has it out for Supermicro.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#364Earlier quoted context omitted.
Still doesn’t mean you shouldn’t be concerned by China’s super position in the global supply chain...
You should, but China rarely cares about people beyond its own boarders. They don't have the power of the U.S. to reach for anyone across the globe, so I think NSA doing this is a tad more worrisome.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#365Earlier quoted context omitted.
No comment.
If I was a high value target (and knew about it) I would definitely not let you know, if I was a high value target and did not know about it I would not be able to tell if I was or if I wasn't. So any high value target and anybody else would not be able to tell you they were a high value target.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#366Earlier quoted context omitted.
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…
Yeah - when I add to it that, as a non-American, I can (annectodaly) observe a rise in different kinds of news that involve China in a negative context for the last 6m especially, it's hard to form an opinion. In terms of security concerns also - come on, we know by now to which lengths the US goes in this area, and they're surely doing worse stuff than this, I'd expect no one would doubt it any more. So, either they…
At least China won't be as dangerous as the US or the Soviet Union in that it has absolutely no interest in enforcing its political ideals on other places or becoming a world police. I see no real reason why people should be worried about the rise of China as if this will turn the whole world Orweillian. China has its own way of organizing the vast and complex country and it's hard to come up with better practical solutions. Still if one doesn't like it they can just live somewhere else, and the authorities don't care, as long as it doesn't hurt Chinese business.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#367Earlier quoted context omitted.
You should, but China rarely cares about people beyond its own boarders. They don't have the power of the U.S. to reach for anyone across the globe, so I think NSA doing this is a tad more worrisome.
I think the main difference between the US and China, the Chinese have no mission to convert every country to their thinking. Not that they influence countries through their investments, see Greece as an example.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#368Earlier quoted context omitted.
Is there any way to solve this problem without needing a "trusted manufacturer"? I know it won't probably won't apply to general purpose motherboards or devices, but is there a way to design or build some components or devices in a way that you can verify that they can perform their purpose and nothing more? If we start with that concept, and slowly build up "verifiably secure" components, they can be the islands of…
What happens when your attacker knows how your safeguards work and can route around your door though the windows? For a motivated and well funded attacker who has an ability to manufacture a replacement chip with an additional coprocessor that can siphon or modify data from the main processors, network cards, and baseband modems, short of decapping every chip and component that comes through your assembly line your r…
A way to verify a chip is working as expected in a way that it can't be gamed without breaking multiple fundamental proofs, so that you won't need to worry as much about who makes it, just that it "passes the tests". (and you'd probably need a system to validate the validators, but splitting up the people involved means it is significantly harder to hack multiple products to all have them falsely verify each other)
Obviously I have no idea what I'm talking about and am just kind of musing at the idea, but trying to secure the whole supply chain from digging materials out of the ground all the way until it is in the hands of the consumer seems like an exercise in futility. You'll never be able to secure it in all cases, and like you said a truly motivated attacker is going to be able to break the chain (even if it means threatening a handful of people with death so you can get 5 minutes alone with a board).
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#369Earlier quoted context omitted.
Yeah - when I add to it that, as a non-American, I can (annectodaly) observe a rise in different kinds of news that involve China in a negative context for the last 6m especially, it's hard to form an opinion. In terms of security concerns also - come on, we know by now to which lengths the US goes in this area, and they're surely doing worse stuff than this, I'd expect no one would doubt it any more. So, either they…
> I don't think we (the world outside China) shouldn't be a bit worried given in what position _we've_ put China and how strong they are now At least China won't be as dangerous as the US or the Soviet Union in that it has absolutely no interest in enforcing its political ideals on other places or becoming a world police. I see no real reason why people should be worried about the rise of China as if this will turn t…
Not yet. But becoming a banker for whole third-world is almost done. And when your debts are big, you lose sovereignty.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#370Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
Mr. Appleboum has made a tactical mistake here and let the kitty out of the bag.
This [edit: read: the original Bloomberg article] disinformation campaign appears to have 2 strategic goals.
1 - Penetrate Apple's data centers via a legislative attack vector. We all know that our congress is owned lock stock and barrel by AIPAC. They will pass legislation that will require companies like Apple to permit 3rd parties to audit their facilities. Enter Yossi and company.
1a - As an aside, this confirms for me that for the time being Apple products and facilities are in fact secure and have presented a serious obstacle to the Israeli intelligence services. Bravo to Apple's security teams.
2 - This same nation state actor is poised to pick up the "supply chain" missing links when China is removed from the equation.
http://economy.gov.il/English/InternationalAffairs/InvestInI...
(related in this thread: https://news.ycombinator.com/item?id=18178028)