Live data from Hacker News

Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

buzzfeednews.com

281–290 of 334 posts

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#281
I don't understand why China would do such a thing, when they have a pretty effective dragnet on US cell towers and routing equipment (alleged to me by a security expert). Hardware seems like such a fragile and expensive hack. That said, even if the story is a complete fiction it does help shine light the surveillance state that has emerged in China, and its global ambitions.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#282

Earlier quoted context omitted.

There is no reason to believe than Tim Cook or any executive would be aware of anything. In large companies with a hundred thousand employees and contractors, barely anyone is aware of anything. Ask a thousand people about project something and they will assert in good faith that they have never heard of it. It doesn't mean that it doesn't exist, just that you didn't find the handful of people who knows about it.

Yeah, that is typically the case, sure. But you are comparing business-as-usual operations to an incident investigation. Sure, Tim Cook likely new nothing or very little about the organization's business dealings with Super Micro before the story broke, but not now. If this story is true, the implications for Apple are huge. It makes them look inept and creates a large problem that must be solved. Tim Cook would be v…

This. Apple is a large enough, and competent enough, organization to investigate this internally.

Some will say "but the people involved have a gag order, and nobody investigating, including tim cook or legal knows". This doesn't make any sense.

People without a clearance are not obligated to keep it a secret, and can investigate for themselves. So either everyone competent to investigate this has a clearance and/or is gagged (i.e., many thousands of people) and if that were the case it'd almost certainly make to Tim Cook's radar.

Or not that many people are gagged, and Apple has thousands of engineers that could be looking into this, and they found nothing. I find that much more plausible.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#283
post #53

Earlier quoted context omitted.

Bloomberg listed a lot of entities in that article and every single one that wasn't anonymous has all but called Bloomberg outright frauds over it. They have all sorts of anonymous sources telling them anything and everything about this supposed plot yet none of them provided any shred of evidence to back up their claims. Where's the smoking gun here? Why don't we have die shots of this thing? Why hasn't anyone on th…

Enough people have access to Supermicro boards that this should have been found by now. Adding a part seems unnecessary just to add a back door. Intel CPU chips already have built-in back doors; you just have to enable them.

Exactly, why can't any of their sources just swipe one of the unpopulated PCBs? Even just having a physical circuit board with 6 extra pads added onto it would at least give a hint of truth to their claims.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#284

Earlier quoted context omitted.

Long story short, this is really wanting me to obtain the gerbers for the motherboards I use, and verify the parts on the board are the parts listed. This the basis of open source hardware. The next step is to obtain firmware for each chip, and compile and load it on all programmable chips. Again, but open source firmware. Then moving up, we need an open source OS, which we have. The last area is having open source s…

I wonder if you could solve the fab issue with some sort of xray based checksum that is reproducible by third parties (maybe universities?)

An xray or optical inspection would never be able to detect the doping of the silicon so it's possible to alter the behavior of the chip in such a way as to allow an attacker to cripple something like Intel's random number generator RdRand yet have this be basically undetectable in software.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#285
post #260

Earlier quoted context omitted.

Is he under the same burden to tell the truth, legally speaking, as the current chief counsel?

Feudatory obligation is feudatory obligation, senior execs almost always have feudatory obligations.

Do you perhaps mean fiduciary?

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#286
post #135

Is it precedented for a news organization to double down like this in the case where a reporter just makes stuff up Stephen Glass style? Because barring a Stephen Glass scenario, what's fascinating here is that no matter which side is right, this is evidence of some sort of mysterious power play. Either Apple was hacked, they know, and are denying, which is evidence of them being under the thumb of U.S. national secu…

Tim Cook would have to know. If there is something like a NSL involved, Apple's legal team would have already reviewed it. That same legal team would also be advising Cook on what he publicly says since he is an officer in the company. He could lose his job or be fined for saying false information in the press (think about what happened to Musk) so its in his and his legal team's best interest to only say true things…

> An NSL compels you to say nothing.

Is that true in this case? My understanding is that NSLs are a subpoena with an accompanying gag order _about the subpoena_. I haven't heard of a case where an NSL was used to restrict speech in the manner you're suggesting. In other words, I believe an NSL could be used to hide government interest in such a breach, but not to hide the fact of the breach.

This is one of the main differences between the US and UK approach to classified information; there's no official secrets act in the US.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#287

Earlier quoted context omitted.

How exactly do canaries work, then? Isn't the point there that you have a canary that you remove later?

Canaries don’t work. National secrecy laws treat a canary exactly as outright violating the gag order.

Do you have a citation for this? Ideally one written by a lawyer.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#288
post #242

Earlier quoted context omitted.

It could simply be classified

That's not how the classification system works.

Nobody here knows how these cases truly work. There's some precedent where you can find gag orders, which make people think that Cook would simply go the "No Comment" route, but to assume those are a blanket procedure for everything is incredibly narrow-minded.

When it comes to National Security, combined with the most valuable company in the US, all assumptions should be off the table. Apple has many reasons to publicly dismiss the claims: their business in China, their marketing as a security-conscious company, etc. They also operate under immense secrecy. Apple has unmarked buildings, top secret projects, a culture of secrecy within the company. They are the type of company that would have innovative approaches when dealing with national security matters.

It would be odd for Tim Cook to knowingly lie about this situation. If definitive proof came out that the chips were bugged and he had knowledge of it, then he could be punished. But, at the same time, if he were able to prove that he lied in the name of National Security, it could be instantly excusable.

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#289

Earlier quoted context omitted.

How exactly do canaries work, then? Isn't the point there that you have a canary that you remove later?

Canaries don’t work. National secrecy laws treat a canary exactly as outright violating the gag order.

Reference ?

Re: Apple CEO Tim Cook Calling for Bloomberg to Retract Its Chinese Spy Chip Story

#290
post #130

Earlier quoted context omitted.

I think it's in the best interest of the US not to turn this case into international relations nightmare. > I mean, this is just intense now. On record statements from four different huge players in this field, clearly and forcefully stating there was no hardware-based backdoor inserted by PLA with regard to Apple and Amazon. https://twitter.com/hatr/status/1048859348489916417

Long story short, this is really wanting me to obtain the gerbers for the motherboards I use, and verify the parts on the board are the parts listed. This the basis of open source hardware. The next step is to obtain firmware for each chip, and compile and load it on all programmable chips. Again, but open source firmware. Then moving up, we need an open source OS, which we have. The last area is having open source s…

>Although, FPGAs could supplant some hardware.

But wouldn't you want the FPGAs to be open source, too?

Post reply on HN