Live data from Hacker News

Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

buzzfeednews.com

141–150 of 334 posts

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#141
post #94
post #77

Earlier quoted context omitted.

I don't agree with the "journalistic process being hacked" as being the only line there, as it implies some deliberate power play by bad actors which would omit said integrity. It seems plausible that it's more along the lines of "journalistic process being broken" for this type of article, that all parties might be acting in good faith and that there is some level of misunderstanding.

There's also the possibility of the malicious part being the journalist himself.

Shouldn't part of the journalistic process include making sure one guy isn't going off the rails and making stuff up? I guess that could be part that's broken.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#142

Earlier quoted context omitted.

And Apple -- being, in part, a hardware company -- has extensive tools and expertise at their disposal to investigate any hardware abnormality. If they've concluded that everything is normal, I'm inclined to believe them.

Cook is claiming everything is normal, but that doesn't necessarily mean that's what Apple actually knows and believes. It is also possible that they have investigated, did find tampering, and are still publicly denying it.

Cook has made this claim in a way that exposes the company, and probably himself, to a lot of legal grief if it later becomes evident that he's not being truthful.

What does Bloomberg have at stake, in comparison? Nothing, apparently, since they don't seem to value their reputation enough to back up their reporting with evidence.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#143
post #97

Earlier quoted context omitted.

I'm all for globalism but that's one area where the best strategy is probably to keep production inside the borders. Not that I'd condone misleading the press to create a case for the legislation.

Yes, manufacture the high security chips on one of the many 7nm fabs in the US. I suppose it also follows that the fab and design should be staffed only as NOFORN? That rules out the lead on the Apple silicon team. I don’t think you understand how this works. This isn’t a nationalism vs globalism thing.

You're the one that jumped from no foreign production to no "foreign" employees. Of course there's a difference between a factory operating under the supervision of the People's Liberation Army and an immigrant working in a lead role at a company.

My comment is basically a pre-reaction to nationalists who would want to use this situation as an excuse to bring as much manufacturing work home as possible, even if it doesn't make sense (and if this were all a ruse, it would be a good way to get the White House on board.) Granted, it would also be pretty dumb to trust your adversary (from a national defence perspective) to build your weapons for you. Which is what the US is doing to a certain degree. Of course this is about globalism, because it's what lead to this situation in the first place. But nationalism, importantly, is not the solution. That's what I hope people take away from this.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#144
post #130

Earlier quoted context omitted.

For the lazy: https://twitter.com/nicoleperlroth/status/104901890298483507...

I think it's in the best interest of the US not to turn this case into international relations nightmare. > I mean, this is just intense now. On record statements from four different huge players in this field, clearly and forcefully stating there was no hardware-based backdoor inserted by PLA with regard to Apple and Amazon. https://twitter.com/hatr/status/1048859348489916417

Long story short, this is really wanting me to obtain the gerbers for the motherboards I use, and verify the parts on the board are the parts listed. This the basis of open source hardware.

The next step is to obtain firmware for each chip, and compile and load it on all programmable chips. Again, but open source firmware.

Then moving up, we need an open source OS, which we have.

The last area is having open source silicon... but given that it's $10m minimum for a basic fab, this isn't happening anytime soon. Although, FPGAs could supplant some hardware. Then we'd need the synthesis code for the design.

Long story short, is there a way to make a trustworthy OS if you don't trust the underlying hardware? Is that even possible?

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#145
post #36

Earlier quoted context omitted.

I'm fairly certain that both Bloomberg and the companies involved have a high degree of confidence that what they're saying is true and have sufficient facts to prove it. That confidence would seem to be misplaced on one side or the other. If anybody had any real doubt they'd let this story die.

never heard about fake news?

>never heard about fake news?

I love that "fake news" is now a license to disbelieve any story that doesn't fit with your personal beliefs. There was fake news one time, now everything is under suspicion.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#146

Earlier quoted context omitted.

It could be. Particularly of the foreign government, but also of the supposed target especially if security of the kind that was claimed to be compromised is key to their business reputation.

Just think of the repercussions if that was proven to be true. Any company could sue any reporter for reporting that they had a exploit, true or not.

Well, yes, you can sue for anything. The barrier here isn't that publishing that a firm is subject to an exploit is specially categorically immune from defamation liability, but the regular standards for defamation, which in the US include falsity, a certain measure of responsibility for the falsity (which carries based on whether public figure or a matter of public interest are involved), and actually damaging publication.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#147

Is it precedented for a news organization to double down like this in the case where a reporter just makes stuff up Stephen Glass style? Because barring a Stephen Glass scenario, what's fascinating here is that no matter which side is right, this is evidence of some sort of mysterious power play. Either Apple was hacked, they know, and are denying, which is evidence of them being under the thumb of U.S. national secu…

Gruber made a good point: They aren't quite doubling down as hard as they could.[1] They said their reporters spoke with a lot of people and spent a long time on the story. They checked the boxes in the journalistic process, so to speak.

But they didn't detail, like, that there was substantial corroboration of specific details like Apple working with the FBI. That leaves open possibilities that it came from just one source or that the reporters mixed up some details. Whereas the company/govt denials are very detailed and clear to rule out any possibility of misinterpretation. Bloomberg's "double down" is nowhere near that level.

[1] https://daringfireball.net/linked/2018/10/19/cook-calls-for-...

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#148
post #135

Is it precedented for a news organization to double down like this in the case where a reporter just makes stuff up Stephen Glass style? Because barring a Stephen Glass scenario, what's fascinating here is that no matter which side is right, this is evidence of some sort of mysterious power play. Either Apple was hacked, they know, and are denying, which is evidence of them being under the thumb of U.S. national secu…

Tim Cook would have to know. If there is something like a NSL involved, Apple's legal team would have already reviewed it. That same legal team would also be advising Cook on what he publicly says since he is an officer in the company. He could lose his job or be fined for saying false information in the press (think about what happened to Musk) so its in his and his legal team's best interest to only say true things…

> An NSL compels you to say nothing. You can neither confirm nor deny anything

Ordinarily, yes. But what if this was double secret NSL?

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#149

Earlier quoted context omitted.

There is no reason to believe than Tim Cook or any executive would be aware of anything. In large companies with a hundred thousand employees and contractors, barely anyone is aware of anything. Ask a thousand people about project something and they will assert in good faith that they have never heard of it. It doesn't mean that it doesn't exist, just that you didn't find the handful of people who knows about it.

Let's drift into some wild speculation here. Suppose this was a malicious attack, and PRC intelligence within SuperMicro and perhaps even Apple are responsible for these machines getting shipped and installed by Apple. Let's further suppose that the plot was uncovered by US counterintelligence. Why the heck would US counterintelligence operate inside of Apple, discover security vulnerabilities that affect Apple in pa…

>>> Apple personnel who are in the business of receiving and installing server hardware...

Contractors who worked in some datacenters 5 years ago and have long left?

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#150
post #80
post #52

In the past, Apple has lied about a severe security incident involving Super Micro hardware. In 2016 Super Micro Senior Vice President of Technology himself said Apple found "infected firmware." It was so bad that Apple "discontinued future business [with Super Micro] as a result of a compromised internal development environment". Strangely Apple at the time was denying the whole thing: https://appleinsider.com/artic…

In the past, these Bloomberg reporters have misreported on NSA exploiting Heartbleed. Here is the Washington Post giving them shit about it:[1] As for the 2016 incident, read Apple's denial more closely. They denied finding infected firmware on servers purchased from SuperMicro. What happened is someone in the design lab (not in production) downloaded infected firmware from SM's support site, where it was "still host…

Not even infected firmware, an infected Windows driver package. Which, although embarrassing for Supermicro, is a lot less sophisticated or unusual an attack than anything being claimed.
Post reply on HN