Live data from Hacker News

UK cyber security agency backs Apple, Amazon China hack denials

reuters.com

71–80 of 99 posts

Re: UK cyber security agency backs Apple, Amazon China hack denials

#71
post #69
post #27

Earlier quoted context omitted.

They're not "maintaining ignorance"; they're categorically denying it, and in significant detail. Both Apple and Amazon produced essentially bulleted refutations of the story. That's not what you do when you're trying to brush something off.

Right. Wouldn't the inside sources also know if Apple/Amazon were somehow gagged? If you're going to leak the whole story, why not leak that part too?

I have reason to believe that Apple and Amazon (and intelligence agencies) silo some data internally on a need-to-know basis wherever possible. A leaker shouldn’t be capable of leaking everything.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#72
post #55

Earlier quoted context omitted.

It's a curious forum we're on where on one day there are jiggabytes spilled over how journalists get technical things wrong and on another, they're so reliably accurate, technology organizations making the case reporting on them is inaccurate must have been infiltrated by men in black and have had hapless employees flashed with a neuralyzer.

Apart from that not being remotely what's being said, HN is not one person, it's a lot of different people with different opinions, commenting on different articles.

I'm not sure what is 'remotely not being said' and I have some vague understanding of the idea HN is not one person.

But there are definitely two (among many) strong tribes of HN-popular belief - let's call them the Gell-Mannicheans and the National Security Epistoleros. It's weird (to me) that they rarely meet in threads on stories concerning both! That could be because they live in different timezones or have different interests. It could be that the Epistoleros are just that much more numerous or that for some people epistolerism trumps gell-mannicheism. Or something else altogether. I find it a curious thing to observe and think about - it's not some underhanded 'zomg lolz, I have caught you in logic error' comment.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#73
post #34

Earlier quoted context omitted.

APPLE: > Finally, in response to questions we have received from other news organizations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations. https://daringfireball.net/linked/2018/10/04/what-businesswe...

FWIW, NSLs prevent you from talking about being under a NSL. I don't think they can be forced to lie, though

That is a commonly accepted position. As any prosecutions under an NSL would presumably be kept secret in order to keep the NSL itself secret, I strongly suspect that governments in general will take a dim view of such loopholes. The aforementioned secrecy means you are unlikely to find out.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#74
post #71
post #69

Earlier quoted context omitted.

Right. Wouldn't the inside sources also know if Apple/Amazon were somehow gagged? If you're going to leak the whole story, why not leak that part too?

I have reason to believe that Apple and Amazon (and intelligence agencies) silo some data internally on a need-to-know basis wherever possible. A leaker shouldn’t be capable of leaking everything.

So not one of the fifteen Bloomberg sources knew about any kind of gag order or reason for Apple/Amazon to deny these claims? Just saying that seems unlikely.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#75
post #71
post #69

Earlier quoted context omitted.

Right. Wouldn't the inside sources also know if Apple/Amazon were somehow gagged? If you're going to leak the whole story, why not leak that part too?

I have reason to believe that Apple and Amazon (and intelligence agencies) silo some data internally on a need-to-know basis wherever possible. A leaker shouldn’t be capable of leaking everything.

Sure, but it wouldn't make sense to only relay the gag order to a subset of people who were aware of an incident - that would add risk and defeat the purpose of the risk-mitigating silos that you're suggesting.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#76
It seems unlikely that Amazon would not detect attempts to reach unauthorized IP addresses. If you’ve used AWS security groups, you know that you can specify what IP ranges your machines can access. While many customers aren’t locking this access down, I’m fairly certain Amazon knows exactly what they are doing on the AWS systems they use.

Detecting such attempts on a brand new system would spur them to identify the source. They’d have found that chip, most likely.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#78

It seems unlikely that Amazon would not detect attempts to reach unauthorized IP addresses. If you’ve used AWS security groups, you know that you can specify what IP ranges your machines can access. While many customers aren’t locking this access down, I’m fairly certain Amazon knows exactly what they are doing on the AWS systems they use. Detecting such attempts on a brand new system would spur them to identify the…

Virtually any halfway competent enterprise would catch this as well. This is network security 101.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#79
I am pretty sure some security issues did happened else supermicro would have definitely sued the reporters by now. But then the mild response by US government and the FBI in general means that the so called attack wasn't as sophisticated as claimed by Bloomberg.

Re: UK cyber security agency backs Apple, Amazon China hack denials

#80

I heard this on NPR [1] and thought it was interesting and hadn't seen it in these articles on HN: > When [Bloomberg] asked China's foreign ministry for a response, a lot of times they'll say things like, you're crazy; we know nothing about this. Their response was a little more nuanced and contextual in the environment we're in now. Basically they said, we are a victim of these kinds of attacks, too. And, you know,…

Are you saying the NSA bribed manufacturers in China to add these to boards - so Americans would discover then and accuse the Chinese government of espionage? Is this the stick to the tariff's carrot?

Remember, astronauts couldn't have met aliens on the moon, if the moon landings were faked.

Post reply on HN