The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?
I would've liked to hear this directly from the company doing the audit, without Super Micro's own "interpretation".
The second thing that bothers me about this story is that it was Supermicro that paid for the audit. Maybe there was no one else going to do it, or maybe they just thought to get ahead of anyone else trying to review their chips. I don't know, but it doesn't sit well with me.
Only recently we saw at least two major tech companies skirt FCC's privacy monitoring by paying themselves for the audits: Google and Facebook. Both had multiple major privacy scandals in the past couple of years, but somehow all of these privacy issues were completely missed by the companies auditing them.