The tech giants, the US and the Chinese spy chips that never were; or were they?(theguardian.com)
theguardian.com
The tech giants, the US and the Chinese spy chips that never were; or were they?
https://www.theguardian.com/commentisfree/2018/oct/13/tech-giants-us-chinese-spy-chips-bloomberg-supermicro-amazon-apple
11 comments
Given the scarce technical details provided by Bloomberg and demonstrated Bloomberg reporter’s lack of understanding on how hardware works, it’s entirely possible someone fooled Bloomberg. Bloomberg said it has 17 sources, but perhaps one source intentionally gave a false story, another described an unrelated attack, and the third merely commented on the technical possibility of a chip hack instead of its existence. Without much technical expertise, the Bloomberg reporter could not determine which of the sources are credible and relevant, but he surely knew which buzzwords are good for a story. So he created a sensational narrative that could attract as much attention as possible, based on selected information that helps the narrative.
>...one source intentionally gave a false story, another described an unrelated attack, and the third merely commented on the technical possibility ...
Yep, that is very likely for 3 sources, but they (assertedly) had 17.
It is really hard to believe to the story, still, besides the journalists/authors there are editors and I cannot believe that - given the relevance of this story - it was not double/triple checked and approved for publishing only after a throroughful review.
Yep, that is very likely for 3 sources, but they (assertedly) had 17.
It is really hard to believe to the story, still, besides the journalists/authors there are editors and I cannot believe that - given the relevance of this story - it was not double/triple checked and approved for publishing only after a throroughful review.
This article is a summary of the current state of affairs; There is no new information, and does not answer the question in the headline.
Bloomberg says a spy chip was discovered and Apple and Amazon worked with the government to investigate. Apple and Amazon both deny the story is correct.
Bloomberg says a spy chip was discovered and Apple and Amazon worked with the government to investigate. Apple and Amazon both deny the story is correct.
With the government’s involvement in this international matter, especially considering it’s China, is it possible that there’s a gag order preventing them from saying anything?
Their strenuous, detailed denials, personally given by individual senior officers seem to go very far beyond what a gag order would require.
Given project/ biz structures at least with amazon and the gov cloud efforts, their response could be entirely true and false at the same time. Ie. amazon didn’t have modified hardware but the joint business venture did.
Whether or not there was a gag order they're still unlikely to want to admit to being hacked.
So detailed they sounded suspicious to some: https://tvtropes.org/pmwiki/pmwiki.php/Main/SuspiciouslySpec...
> There is no new information,
It links to the Cambridge university security team blog and they say Bloomberg's claim passes the sniff test.
https://www.lightbluetouchpaper.org/2018/10/05/making-sense-...
It links to the Cambridge university security team blog and they say Bloomberg's claim passes the sniff test.
https://www.lightbluetouchpaper.org/2018/10/05/making-sense-...
Which has been discussed before https://news.ycombinator.com/item?id=18148749
So whether that's new information or not depends on how much time you waste on HN ;)
So whether that's new information or not depends on how much time you waste on HN ;)
Im not familiar with this Cambridge researcher, but they seem very far off the mark and I do not think the original article passes the smell test.
Let's make multiple very serious and not reasonable assumptions and jump to the end: a compromised bmc on the network.
It is still non-trivial to get anything accomplished. Either you pass traffic through the likely sinkholed DNS (https://en.m.wikipedia.org/wiki/OpenDNS) or make hard coded calls likely to be flagged by ips/ids. Even if you don't get caught immediately, the number of firewalls with access rules to wan to lan traffic back to your ilo/idrac has got to be effectively 0. Even if the access rules are in place, I'd bet Nat isn't - even reverse ssh tunnels require Nat. There are file integrity solutions to check for OS compromises ( https://www.tripwire.com/solutions/file-integrity-and-change...)
The idea that these were shipped randomly globally to Enterprise environments and no one ever figured it out is basically impossible. Maybe there is some grey area and the CTOs and CISOs just never got told what the Frontline admins didn't think was a big deal.
Something else is going on. Maybe this is FUD with China in the title to fuel some political economic maneuvering. Maybe everything about the attack is real except Russia did it to hurt China.
Let's make multiple very serious and not reasonable assumptions and jump to the end: a compromised bmc on the network.
It is still non-trivial to get anything accomplished. Either you pass traffic through the likely sinkholed DNS (https://en.m.wikipedia.org/wiki/OpenDNS) or make hard coded calls likely to be flagged by ips/ids. Even if you don't get caught immediately, the number of firewalls with access rules to wan to lan traffic back to your ilo/idrac has got to be effectively 0. Even if the access rules are in place, I'd bet Nat isn't - even reverse ssh tunnels require Nat. There are file integrity solutions to check for OS compromises ( https://www.tripwire.com/solutions/file-integrity-and-change...)
The idea that these were shipped randomly globally to Enterprise environments and no one ever figured it out is basically impossible. Maybe there is some grey area and the CTOs and CISOs just never got told what the Frontline admins didn't think was a big deal.
Something else is going on. Maybe this is FUD with China in the title to fuel some political economic maneuvering. Maybe everything about the attack is real except Russia did it to hurt China.
Is there a problem with how much power some journalists have to move markets?
If this story turns out to be wrong, and it also wasn't fraud, it feels wildly unfair for a company to have half evaporated overnight.
Dangerous topic so I'll say that I'm not suggesting limits on journalism or freedom of speech.
If this story turns out to be wrong, and it also wasn't fraud, it feels wildly unfair for a company to have half evaporated overnight.
Dangerous topic so I'll say that I'm not suggesting limits on journalism or freedom of speech.
1) No doubt, the Bloomberg reporter was not technical enough to vet what he was being told
2) No doubt, newsmedia get lots of stuff wrong, and the more you know about the topic of the article, the more wrong you see, typically
3) But also no doubt, China has the means, motive, and opportunity to use their position in hardware the same way the U.S. uses its position in software, to enhance intelligence gathering. I have heard no credible reason why China wouldn't have, in one way or another, used that position to gather intelligence.
4) The longer that goes by without somebody finding a compromised board to show, the less I believe this particular avenue was used.
3)I doubt China would hack its hardware for intel purpose in the way bloomberg described, not because it doesn’t want to, but because it’s very cost inefficient. China needs to perform the hack on a massive scale to hack a target because it cannot reliably know which server is going to which company down the supply chain. Such a massive hack will almost certainly be caught and the economic consequece is huge. In addition, unlike software hack, its easy to trace the origin of a hardware attack back to china.
There's a large misconception in a lot of the conjecture I see publicly, and it's the idea that China would care if it could be traced back to them. A lot of governments commit a large number of intel actions knowing they'll be traced back to them but it's still worth it. If they got caught they'd just say "Oh it's a rogue factory" and go one with life. Maybe we would throw some bullshit sanctions their way.
A historic example of this is the recording devices we used for Operation Ivy Bells. There was no hiding who the recording devices belonged to because we spray painted "Property of the US Government" on them. Or the Iran nuclear manufacturing tampering that was pulled off for years. Everyone knows who did it because who else could have done it?
Regarding 'scale' - that's not all that important either. If you have someone at SMCI that can get shipping orders then you can easily figure out roughly what batches you need to tamper with in order to make sure your parts end up where they need to go. And it's worth it, even in a small scale, on the hopes of not getting found. No one comes up with one idea of compromising a target and then never waivers from it. You try them all until one works.
A historic example of this is the recording devices we used for Operation Ivy Bells. There was no hiding who the recording devices belonged to because we spray painted "Property of the US Government" on them. Or the Iran nuclear manufacturing tampering that was pulled off for years. Everyone knows who did it because who else could have done it?
Regarding 'scale' - that's not all that important either. If you have someone at SMCI that can get shipping orders then you can easily figure out roughly what batches you need to tamper with in order to make sure your parts end up where they need to go. And it's worth it, even in a small scale, on the hopes of not getting found. No one comes up with one idea of compromising a target and then never waivers from it. You try them all until one works.
I still believe though that China (and, in fact, the US itself) would have much more at stake if the US discovers that the supply chain has been compromised, given its enormous manufacturing interests and how this might be used to justify certain trading policies, whereas the US (and Israel) had, in comparison, almost nothing to worry about Stuxnet being traced back to them. This is the main reason I believe that if this was real it would have been incredibly rash from the Chinese, unbelievably so. Then again, it would also be extremely damaging to Bloomberg's reputation if it wasn't.
I have absolutely no doubt at all that China would do that sort of thing in a highly targeted way, but it seems wildly implausible that they would do it so irresponsibly. Their chip manufacturing industry is far too important for them to cripple it in that way.
Hmmm..."wildly implausible"? That's pretty strong wording. "They might not want to do it this way", I could believe. But that the individual(s) in the government concerned with a particular intelligence hack might not have thought through all the consequences for China's chip manufacturing industry, is not so far out there as to be "wildly implausible", I think. Which doesn't mean, of course, that it did in fact happen (this way).
Personally I wouldn't be surprised if there was a backdoor of some sort in the firmware or deniable known vulnerabilities to exploit but just a spy chip seems too Hollywood and symbolic given other approaches - adding a 'parasite' to corrupt it when they can just integrate it such that a very expensive and detailed analysis would be needed to find it.
Yeah - it does not look impressive when we have read about the possible backdoors inside processors: https://www.wired.com/2016/06/demonically-clever-backdoor-hi... But on the other hand maybe they were just testing the waters - it was in 2015 after all.
That's the holy grail so why not try it? They can plant 2-3 and milk them while they can. Maybe one is discovered, quite a few boards are never replaced and so on.
I wouldn't be surprised if this was some sort of PR campaign similar to Iraq's WMDs. It does make sense that Iraq still has weapons of mass destruction and could use them against civil populations; likewise, it does make sense that China could access the supply chain, and could use it to access government and corporate networks. The end goal is to change public perception and get support on the idea that the US should focus its efforts on that country (instead of the Mueller investigation or Russia for example). In Iraq's WMDs, the symbol was Colin Powell's vial of Anthrax, here it's a tiny chip that promises to unlock all servers. It's a symbol strong enough that goes well on TV or media.
True or not, what matters is that the seeds of distrust has been sowed. It's billions of $ lost for Supermicro shareholders, and potentially distrust of China.
True or not, what matters is that the seeds of distrust has been sowed. It's billions of $ lost for Supermicro shareholders, and potentially distrust of China.
Who knows? Bloomberg might have just ripped the image of thier chip from the mouser catalog and called it a day..
https://www.mouser.com/new/tdk/tdk-rf-components/
https://www.mouser.com/new/tdk/tdk-rf-components/
AFAIK the images used in the Bloomberg article were illustrations / stock images
I wish there was a ban on using stock imagery in news reporting. They should either put a real photo, or no photo at all. Putting stock photos almost always creates confusion.
What about a stock photo that is clearly labeled as a stock photo?
If "clearly" in the UX meaning of the word (e.g. same size or greater than that of surrounding text, but visibly emphasized) - sure. If "clearly" in the legal sense, let's be honest - who's going to notice that?
And ultimately, why risk confusing people just to make the article prettier? That media outlets do this is one of the many reasons proving that they don't really care about informing their audience.
And ultimately, why risk confusing people just to make the article prettier? That media outlets do this is one of the many reasons proving that they don't really care about informing their audience.
Where is the hardware? I call bullshit until someone produces compromised hardware.
The article is a pretty weak summary of events.
However, the across-the-board blanket denials seem suspect. Of course you'd deny that you gave a 3 letter agency access to your hardware.
Someone needs to procure one of these tainted boards soon though.
However, the across-the-board blanket denials seem suspect. Of course you'd deny that you gave a 3 letter agency access to your hardware.
Someone needs to procure one of these tainted boards soon though.
This isn't news. It's gossip and clickbait masquerading as news.
I wish there was a way to filter any headline with a "?".
"The pyramids were built by aliens... or were they?"
I wish there was a way to filter any headline with a "?".
"The pyramids were built by aliens... or were they?"
I agree with you about both the title and the content, it is a disappointing article. However, I decided to submit it anyway given that it's a sample of how this is being reported in the mainstream media, and that it has many comments, a few of which are quite interesting.