Live data from Hacker News

Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

buzzfeednews.com

71–80 of 334 posts

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#71

Earlier quoted context omitted.

Given the hack involves hardware I'm quite inclined to believe Apple and all the strong denials.

I concur. If it really is a chip being inserted on a board, then that's hard evidence that can be verified by cracking open the hardware and looking for said chip.

And Apple -- being, in part, a hardware company -- has extensive tools and expertise at their disposal to investigate any hardware abnormality. If they've concluded that everything is normal, I'm inclined to believe them.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#72
post #59

Earlier quoted context omitted.

It's not irresponsible at all if the story is true. Bloomberg has no responsibility to Supermicro's stock (or anyone else's). They also aren't responsible for protecting classified information. But the story probably isn't true.

I'm not trying to argue that Bloomberg did anything illegal, so lets stay away from that red herring. I'm talking about whether their action was morally right; granted, morality and civic duty is a much more ambiguous topic, and I'm open to the possibility that my position is incorrect here. To make an analogy: What if a newspaper was given sensitive personal information about someone that was legal to publish, but c…

Private people can have secrets, the government shouldn't.

I don't think they did anything immoral by publishing (unless they believed what they wrote to be false).

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#73
post #59

Earlier quoted context omitted.

It's not irresponsible at all if the story is true. Bloomberg has no responsibility to Supermicro's stock (or anyone else's). They also aren't responsible for protecting classified information. But the story probably isn't true.

I'm not trying to argue that Bloomberg did anything illegal, so lets stay away from that red herring. I'm talking about whether their action was morally right; granted, morality and civic duty is a much more ambiguous topic, and I'm open to the possibility that my position is incorrect here. To make an analogy: What if a newspaper was given sensitive personal information about someone that was legal to publish, but c…

It's not immoral if what's being reported is in the public interest. It's questionable when it's something like "Brad and Angelina are breaking up", but obviously not illegal.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#74

It’s fascinating to see this story unfold. On one end you have Bloomberg doubling down on their claims, and here you have Apple making a move that shows their confidence in their claims. For a while I was buying the subpoena theory, but this action clearly doesn’t fall under that, and they would be setting themselves up for serious liability / damage claims if it were true. Either there is some gross miscommunication…

There is no reason to believe than Tim Cook or any executive would be aware of anything. In large companies with a hundred thousand employees and contractors, barely anyone is aware of anything. Ask a thousand people about project something and they will assert in good faith that they have never heard of it. It doesn't mean that it doesn't exist, just that you didn't find the handful of people who knows about it.

>There is no reason to believe than Tim Cook or any executive would be aware of anything.

The minute this story hit publication you can bet internal security teams at Apple would have validated it and submitted findings to Tim Cook. At this point Tim Cook, along with his legal team, has all the facts as they pertain to Apple and Apple suppliers and every component inside Apple devices. You don't come out without a strong denial like that unless you are sure you can back it up.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#75
> “We turned the company upside down,” Cook said. “Email searches, data center records, financial records, shipment records. We really forensically whipped through the company to dig very deep and each time we came back to the same conclusion: This did not happen. There’s no truth to this.”

Wow, ok then..

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#76
post #9

Man, I am now 90% convinced that someone intentionally misled Bloomberg. It looks like this may end up being an extremely embarrassing episode for them.

If someone misled them, Tim Cook should be aware of it considering they claim to have multiple sources at Apple. It would have to a pretty big conspiracy for those sources alone to be tied to some outside attempt at disinformation.

Either that or Bloomberg is lying.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#77

Is it precedented for a news organization to double down like this in the case where a reporter just makes stuff up Stephen Glass style? Because barring a Stephen Glass scenario, what's fascinating here is that no matter which side is right, this is evidence of some sort of mysterious power play. Either Apple was hacked, they know, and are denying, which is evidence of them being under the thumb of U.S. national secu…

I don't agree with the "journalistic process being hacked" as being the only line there, as it implies some deliberate power play by bad actors which would omit said integrity.

It seems plausible that it's more along the lines of "journalistic process being broken" for this type of article, that all parties might be acting in good faith and that there is some level of misunderstanding.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#78
post #65

I think Bloomberg was probably irresponsible to publish the Chinese spy chip story, whether it was true or false! Here's why: * If the story is false , it's irresponsible because it causes severe monetary and reputational damage to companies that do not deserve it (e.g. Supermicro's stock is still down ~ 40% ). * If the story is true , it's a MAJOR breach of classified information from US intelligence operations; ope…

Hold on. If a reporter is uncovers hostile, state-sponsored corporate espionage in extant, US hardware, it's "shockingly irresponsible" to report that? The putative fact that our supply chain is so totally compromised is immediately relevant to everyone. I'm sorry-not-sorry if that's inconvenient for the FBI and Tim Cook. In a context where the geopolitical and commercial forces would all strongly prefer that such th…

It's not that the information is irrelevant, it's that knee-jerk responses to leaked information may be worse than coordinated and planned responses to national security threats.

Shining a light on this too early (assuming this wasn't an intentional "leak") could be akin to applying antibiotics to an infection prior to actually knowing what exactly the infection consists of, and discontinuing the treatment too soon (we all know how short the attention span of our news cycles are).

It doesn't seem unreasonable to analogize fighting spy networks to fighting an evasive infection: If you attack the infection with a half-baked or inconsistent treatment, you risk just breeding stronger infections that are even better at evading you.

Maybe I trust the US intelligence agencies too much, but it seems likely that they know what they're doing here. And so far, I've seen no evidence contrary to my default assumption that they're operating in best faith for the interests of the US and its citizens in this case.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#79
post #52

In the past, Apple has lied about a severe security incident involving Super Micro hardware. In 2016 Super Micro Senior Vice President of Technology himself said Apple found "infected firmware." It was so bad that Apple "discontinued future business [with Super Micro] as a result of a compromised internal development environment". Strangely Apple at the time was denying the whole thing: https://appleinsider.com/artic…

What they denied was that the servers were used in production. They also said they didn't find the firmware on the server as shipped from Supermicro, it was downloaded from their website [1].

>Update: A source familiar with the case at Apple told Ars that the compromised firmware affected servers in Apple's design lab, and not active Siri servers. The firmware, according to the source, was downloaded directly from Supermicro's support site—and that firmware is still hosted there.

Apple issued the following official comment:

Apple is deeply committed to protecting the privacy and security of our customers and the data we store. We are constantly monitoring for any attacks on our systems, working closely with vendors and regularly checking equipment for malware. We’re not aware of any data being transmitted to an unauthorized party nor was any infected firmware found on the servers purchased from this vendor.

>I also find it very interesting that the FBI, the one organization at the center of this saga who is allegedly investigating the spy chip, has remained completely silent, neither confirming nor denying the story.

That's not true. Christopher Wray, in a congressional hearing, said "be careful what you read" in a response to a question about the story [2].

[1] https://arstechnica.com/information-technology/2017/02/apple...

[2] https://www.cnbc.com/2018/10/10/fbi-director-wray-on-super-m...

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#80
post #52

In the past, Apple has lied about a severe security incident involving Super Micro hardware. In 2016 Super Micro Senior Vice President of Technology himself said Apple found "infected firmware." It was so bad that Apple "discontinued future business [with Super Micro] as a result of a compromised internal development environment". Strangely Apple at the time was denying the whole thing: https://appleinsider.com/artic…

In the past, these Bloomberg reporters have misreported on NSA exploiting Heartbleed. Here is the Washington Post giving them shit about it:[1]

As for the 2016 incident, read Apple's denial more closely. They denied finding infected firmware on servers purchased from SuperMicro. What happened is someone in the design lab (not in production) downloaded infected firmware from SM's support site, where it was "still hosted".[2] While you might say Apple could have been clearer at the time, that is nothing like the very strong, clear, detailed denials at hand here.

[1] https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/...

[2] https://arstechnica.com/information-technology/2017/02/apple...

Post reply on HN