Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

151–160 of 183 posts

Re: What Businessweek got wrong about Apple

#151

Earlier quoted context omitted.

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…

I think the Command and Control traffic will be much harder to spot. In fact it might be dormant until an operative is on the same network and wakes it up.

Re: What Businessweek got wrong about Apple

#152

Earlier quoted context omitted.

That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…

I'd appreciate a detailed explanation of the steps needed to get from putting this chip on a motherboard to actionable intelligence useful to a hostile nation state. If we're talking about being able to make changes at the OS level, surely those should be relatively easy to spot? If we're talking about copying packets, wouldn't that be useless under most circumstances? If we're talking about doing whatever on a mass…

Something like triggering a memory-read of a specific address the moment you see a TLS diffie helman exchange on the wire? The idea being that you can recover the session key, and thus break the encryption retroactively.

That requires more than just access to the network, but it is rather simple.

With just access to the network, perhaps one could do spoofed DNS responses that are never seen on the network? A very simple '1% of the time, set the gmail.com A record to the chinese gmail IP' might be enough.

One could create mayhem by sending false ARP or DHCP responses, but that is only mayhem. Perhaps if it is externally triggerable it is useful offensively as DoS.

Re: What Businessweek got wrong about Apple

#153

Earlier quoted context omitted.

This isn't how gag orders (or, in the case of online services, NSLs) work. A gag order can compel you not to share data, but they cannot compel you to lie, let alone lie elaborately, as Apple and Amazon at this point would have to be for their denials to be false. If Apple is lying here, they're lying because they want to, not because something is forcing them to. I believe them.

"Did you receive an NSL?" You have been compel to lie, by the government, to answer "NO" if you've received one. If you can be compelled to lie that you have received an NSL then I do not see why you can't be forced to lie more. We already compelled speech, why not more?

I thought that you could simply not answer the NSL question (hence warrant canaries)

Re: What Businessweek got wrong about Apple

#154
post #115

Earlier quoted context omitted.

That's the interesting bit. Having done so much to hide the exploit your most important aim is to hide it's presence. Anything that would just "connect to a Chinese server" would be discovered immediately. If the Bloomberg story is true, the network traffic scheme must have been extremely sophisticated to fool so many network security specialists at top companies for such a long time. This, or the story is false, pur…

Most places I know of isolate their OOB management network, requiring a vpn or jumpbox to access it. However, if someone did let their OOB network full outbound access, I could see this slipping through. I could imagine that simply going to a CDN or cloud provider like AWS/Cloudfront/cloudflare/akamai with a dns lookup along the lines of updates.supermicro.cdn-front.com wouldn't be too suspicious. At that point, you'…

> However, if someone did let their OOB network full outbound access, I could see this slipping through.

Quite, especially in small networks and inline ilos, entirely possible that people plug the ilo (ipmi etc) to a more open network. Sure, nothing in, but no block on stuff going out.

Re: What Businessweek got wrong about Apple

#155

Stupid legal question, could this end up becoming a defamation lawsuit?

Similar question, but should BW turn out to be correct and Apple was for lack of a better word, lying, aren't they on the hook as a public company?

Not if the US government has instructed or allowed Apple/Amazon/etc to do so on national security grounds.

Re: What Businessweek got wrong about Apple

#156
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

> Bloomberg is exquisitely specific and detailed about the chip, including photos and placement (on the baseboard management bridge, disguised as a shielding element.)

They are very specific, yes. They show pictures of the alleged chips that are allegedly disguised, yes. They describe placement, yes.

However, photographic or video evidence of these chips on SuperMicro boards is conspicuously absent. The only visual of placement is an illustration, not a photo. I’m not suggesting Bloomberg is wrong. I find this story fascinating and incredible (if true). But I noticed there were no photos/video of the chips on boards.

Re: What Businessweek got wrong about Apple

#157
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

It's certainly beginning to look like Bloomberg got played. I don't know what the motivation would be for Bloomberg to deliberately deceive readers, but I can't help notice that the article came out at roughly the same time as Mike Pence was giving a speech whose central premise was that China is meddling in american politics, and all the attention currently focused on Russian hacking should be focused on Chinese hac…

But go read the Chinese response. It certainly looks like a non-denial to me. Pretty much says, "yeah, it was us, but US is doing the same to us".

The full statement can be found at the link below, but the take-away is pretty much this quote from the statement: "Supply chain safety in cyberspace is an issue of common concern, and China is also a victim."

https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

Re: What Businessweek got wrong about Apple

#158
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

My general response whenever there is something like this: Look at the past stories by the reporter. Bloomberg handily lists them for you. https://www.bloomberg.com/authors/AQrv1y2ieI0/jordan-roberts... Take a look at those stories in the strong light of being able to see them in retrospect and decide for yourself if this reporter is prone to going to press without a full understanding of the situation. I have my opi…

In this case, there's relatively little ground for misunderstanding or exaggeration. There's either a malicious chip or there's not. I suppose in the "worst case" scenario, there could be a malicious chip, but some other government than the Chinese put it there.

However, reading the statement from the Chinese government in response to this story, which never actually denies the incident and instead complains about being victim to such hardware hacking themselves, that's not the impression I get: https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

Re: What Businessweek got wrong about Apple

#159

Earlier quoted context omitted.

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets. The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards…

That is a good question, did the Chinese target specific customers, identifying the relevant sub-contractors and modify these boards? Or are these boards commercial-of-the-shelf things that are mass produced? In the latter case these boards can just end up anywhere, in the first case not so much. As a result using commodity boards would provide some degree of protection against such an attack as slipping a manipulate…

> That is a good question, did the Chinese target specific customers, identifying the relevant sub-contractors and modify these boards?

Why not go read the story? It addresses this question and many others HNers are asking now. It's actually a fairly detailed story, although annoyingly short on technical detail (which could have been because their sources refused to go into much detail).

Re: What Businessweek got wrong about Apple

#160

Earlier quoted context omitted.

"Did you receive an NSL?" You have been compel to lie, by the government, to answer "NO" if you've received one. If you can be compelled to lie that you have received an NSL then I do not see why you can't be forced to lie more. We already compelled speech, why not more?

I thought that you could simply not answer the NSL question (hence warrant canaries)

Iirc that's only in theory. I don't think there has been any precedent set. But I always see people say that a warrant canary is a false sense of security.
Post reply on HN