Live data from Hacker News

Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

buzzfeednews.com

111–120 of 334 posts

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#111
post #80
post #52

In the past, Apple has lied about a severe security incident involving Super Micro hardware. In 2016 Super Micro Senior Vice President of Technology himself said Apple found "infected firmware." It was so bad that Apple "discontinued future business [with Super Micro] as a result of a compromised internal development environment". Strangely Apple at the time was denying the whole thing: https://appleinsider.com/artic…

In the past, these Bloomberg reporters have misreported on NSA exploiting Heartbleed. Here is the Washington Post giving them shit about it:[1] As for the 2016 incident, read Apple's denial more closely. They denied finding infected firmware on servers purchased from SuperMicro. What happened is someone in the design lab (not in production) downloaded infected firmware from SM's support site, where it was "still host…

[deleted]

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#112
post #80

Earlier quoted context omitted.

In the past, these Bloomberg reporters have misreported on NSA exploiting Heartbleed. Here is the Washington Post giving them shit about it:[1] As for the 2016 incident, read Apple's denial more closely. They denied finding infected firmware on servers purchased from SuperMicro. What happened is someone in the design lab (not in production) downloaded infected firmware from SM's support site, where it was "still host…

> someone in the design lab (not in production) downloaded infected firmware from SM's support site Other than the claim that the infected firmware is "still hosted there" (which beggars belief) that sounds more like an engineer was spearphished and fooled into downloading firmware from what he believed to be the SM support site.

This is why public statements need a high level of detail to set the record straight.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#113

Earlier quoted context omitted.

I concur. If it really is a chip being inserted on a board, then that's hard evidence that can be verified by cracking open the hardware and looking for said chip.

And Apple -- being, in part, a hardware company -- has extensive tools and expertise at their disposal to investigate any hardware abnormality. If they've concluded that everything is normal, I'm inclined to believe them.

Cook is claiming everything is normal, but that doesn't necessarily mean that's what Apple actually knows and believes.

It is also possible that they have investigated, did find tampering, and are still publicly denying it.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#114
post #80
post #52

In the past, Apple has lied about a severe security incident involving Super Micro hardware. In 2016 Super Micro Senior Vice President of Technology himself said Apple found "infected firmware." It was so bad that Apple "discontinued future business [with Super Micro] as a result of a compromised internal development environment". Strangely Apple at the time was denying the whole thing: https://appleinsider.com/artic…

In the past, these Bloomberg reporters have misreported on NSA exploiting Heartbleed. Here is the Washington Post giving them shit about it:[1] As for the 2016 incident, read Apple's denial more closely. They denied finding infected firmware on servers purchased from SuperMicro. What happened is someone in the design lab (not in production) downloaded infected firmware from SM's support site, where it was "still host…

Still waiting for WashPost to disclose their owner's deals with the CIA whenever it publishes a post about the CIA...

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#115
post #80

Earlier quoted context omitted.

In the past, these Bloomberg reporters have misreported on NSA exploiting Heartbleed. Here is the Washington Post giving them shit about it:[1] As for the 2016 incident, read Apple's denial more closely. They denied finding infected firmware on servers purchased from SuperMicro. What happened is someone in the design lab (not in production) downloaded infected firmware from SM's support site, where it was "still host…

> someone in the design lab (not in production) downloaded infected firmware from SM's support site Other than the claim that the infected firmware is "still hosted there" (which beggars belief) that sounds more like an engineer was spearphished and fooled into downloading firmware from what he believed to be the SM support site.

FYI "still" meant as of the time of the follow-up reporting in 2016, not today. I think it's believable that SuperMicro's support site got hacked. But I agree that was an incident on par with a sole developer installing malware on their system, not a supply chain compromise or major security incident with production systems.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#117

I think Bloomberg was probably irresponsible to publish the Chinese spy chip story, whether it was true or false! Here's why: * If the story is false , it's irresponsible because it causes severe monetary and reputational damage to companies that do not deserve it (e.g. Supermicro's stock is still down ~ 40% ). * If the story is true , it's a MAJOR breach of classified information from US intelligence operations; ope…

You have no idea what journalism represents if you think a report on something like that should be qualified as "irresponsible."

Daniel Ellsberg leaked such "major classified information" (the Pentagon Papers) about the Vietnam war, which ended-up stopping the war in Vietnam (mind you for the better...).

If the NSA has been using the Chinese' own spy chip against US citizens, it's the journalists' responsibility to report that to the public.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#118

If it turns out to be false, should the SEC look into it?

Possibly, but in all likelihood, no.

I know that some people here like to get hung up on literal interpretations and stated missions, but they really shouldn't. (Sorry, can't get into it here.)

For many reasons, there isn't a lot of good that would come from them making a big deal about this among the general public. Feel free to see my earlier post.[1]

[1] https://news.ycombinator.com/item?id=18141186

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#119
post #36

With all the strong denials so far, my guess is that heads are going to roll at Bloomberg and that there may be retractions. Worst case, Bloomberg gets caught as publishing fake news endangering entire countries and companies, and closes shop in shame. There’s too much at stake for Bloomberg here. Hopefully someone at the top at Bloomberg is taking this seriously and looking at some quick and decisive actions. These…

I'm fairly certain that both Bloomberg and the companies involved have a high degree of confidence that what they're saying is true and have sufficient facts to prove it. That confidence would seem to be misplaced on one side or the other. If anybody had any real doubt they'd let this story die.

never heard about fake news?

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#120

Earlier quoted context omitted.

> I would expect that if it's fabricated, Bloomberg will have to face a slew of defamation suits from the named companies. I'm not sure defamation is the right word here—"X was attacked by a foreign government" isn't defamation.

It could be. Particularly of the foreign government, but also of the supposed target especially if security of the kind that was claimed to be compromised is key to their business reputation.

> It could be.

That's not going to win huge legal battles.

Post reply on HN