However, the across-the-board blanket denials seem suspect. Of course you'd deny that you gave a 3 letter agency access to your hardware.
Someone needs to procure one of these tainted boards soon though.
11–20 of 38 posts
However, the across-the-board blanket denials seem suspect. Of course you'd deny that you gave a 3 letter agency access to your hardware.
Someone needs to procure one of these tainted boards soon though.
This article is a summary of the current state of affairs; There is no new information, and does not answer the question in the headline. Bloomberg says a spy chip was discovered and Apple and Amazon worked with the government to investigate. Apple and Amazon both deny the story is correct.
> There is no new information, It links to the Cambridge university security team blog and they say Bloomberg's claim passes the sniff test. https://www.lightbluetouchpaper.org/2018/10/05/making-sense-...
So whether that's new information or not depends on how much time you waste on HN ;)
If this story turns out to be wrong, and it also wasn't fraud, it feels wildly unfair for a company to have half evaporated overnight.
Dangerous topic so I'll say that I'm not suggesting limits on journalism or freedom of speech.
This article is a summary of the current state of affairs; There is no new information, and does not answer the question in the headline. Bloomberg says a spy chip was discovered and Apple and Amazon worked with the government to investigate. Apple and Amazon both deny the story is correct.
> There is no new information, It links to the Cambridge university security team blog and they say Bloomberg's claim passes the sniff test. https://www.lightbluetouchpaper.org/2018/10/05/making-sense-...
Let's make multiple very serious and not reasonable assumptions and jump to the end: a compromised bmc on the network.
It is still non-trivial to get anything accomplished. Either you pass traffic through the likely sinkholed DNS (https://en.m.wikipedia.org/wiki/OpenDNS) or make hard coded calls likely to be flagged by ips/ids. Even if you don't get caught immediately, the number of firewalls with access rules to wan to lan traffic back to your ilo/idrac has got to be effectively 0. Even if the access rules are in place, I'd bet Nat isn't - even reverse ssh tunnels require Nat. There are file integrity solutions to check for OS compromises ( https://www.tripwire.com/solutions/file-integrity-and-change...)
The idea that these were shipped randomly globally to Enterprise environments and no one ever figured it out is basically impossible. Maybe there is some grey area and the CTOs and CISOs just never got told what the Frontline admins didn't think was a big deal.
Something else is going on. Maybe this is FUD with China in the title to fuel some political economic maneuvering. Maybe everything about the attack is real except Russia did it to hurt China.
Who knows? Bloomberg might have just ripped the image of thier chip from the mouser catalog and called it a day.. https://www.mouser.com/new/tdk/tdk-rf-components/
The article is a pretty weak summary of events. However, the across-the-board blanket denials seem suspect. Of course you'd deny that you gave a 3 letter agency access to your hardware. Someone needs to procure one of these tainted boards soon though.
Who knows? Bloomberg might have just ripped the image of thier chip from the mouser catalog and called it a day.. https://www.mouser.com/new/tdk/tdk-rf-components/
AFAIK the images used in the Bloomberg article were illustrations / stock images
True or not, what matters is that the seeds of distrust has been sowed. It's billions of $ lost for Supermicro shareholders, and potentially distrust of China.