TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

What Businessweek got wrong about Apple

267 pointsby rakkhiover 6 years ago

26 comments

Jerry2over 6 years ago
Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It&#x27;s also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild.<p>So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC (&quot;intelligence community&quot;) as a way to scare technology companies from doing business in China?<p>Someone at the SEC should scrutinize SMCI shorts at the very least.
评论 #18146383 未加载
评论 #18146486 未加载
评论 #18146281 未加载
评论 #18146220 未加载
评论 #18146332 未加载
评论 #18147450 未加载
评论 #18146313 未加载
评论 #18146380 未加载
评论 #18148238 未加载
评论 #18146336 未加载
评论 #18147604 未加载
评论 #18146348 未加载
评论 #18146215 未加载
评论 #18146434 未加载
baxtrover 6 years ago
<i>In an appearance this morning on Bloomberg Television, reporter Jordan Robertson made further claims about the supposed discovery of malicious chips, saying, “In Apple’s case, our understanding is it was a random spot check of some problematic servers that led to this detection.” As we have previously informed Bloomberg, this is completely untrue. Apple has never found malicious chips in our servers. Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.</i><p>It can’t get much clearer than that. The whole story is quite weird. I don’t know who should be believed but I’ve never read any such vehement denial. If Apple is lying they risk quite a bit of credibility here
评论 #18148121 未加载
IOT_Apprenticeover 6 years ago
From 2016: Report: Apple designing its own servers to avoid snooping Apple suspects that servers are intercepted and modified during shipping.<p>&quot;Apple has long suspected that servers it ordered from the traditional supply chain were intercepted during shipping, with additional chips and firmware added to them by unknown third parties in order to make them vulnerable to infiltration, according to a person familiar with the matter,&quot; the report said. &quot;At one point, Apple even assigned people to take photographs of motherboards and annotate the function of each chip, explaining why it was supposed to be there. Building its own servers with motherboards it designed would be the most surefire way for Apple to prevent unauthorized snooping via extra chips.&quot; <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2016&#x2F;03&#x2F;report-apple-designing-its-own-servers-to-avoid-snooping&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2016&#x2F;03&#x2F;repor...</a>
评论 #18146602 未加载
chillaxover 6 years ago
The Norwegian National Security Authority (<a href="https:&#x2F;&#x2F;nsm.stat.no&#x2F;english&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nsm.stat.no&#x2F;english&#x2F;</a>) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. <a href="https:&#x2F;&#x2F;www.vg.no&#x2F;nyheter&#x2F;i&#x2F;xRkLep&#x2F;storavis-hevder-kina-installerte-spionverktoey-i-maskinvare" rel="nofollow">https:&#x2F;&#x2F;www.vg.no&#x2F;nyheter&#x2F;i&#x2F;xRkLep&#x2F;storavis-hevder-kina-inst...</a>
评论 #18146280 未加载
评论 #18147412 未加载
评论 #18146277 未加载
评论 #18146312 未加载
whatever1over 6 years ago
I mean what was the alternative? To admit that your supply chain is compromised and blame directly the government of the country where you produce (and sell to a level) all of your hardware?<p>That would be a huge blow in the credibility of the company and would raise serious questions on why they did not move the manufacturing elsewhere.
评论 #18146304 未加载
Bryan_Tiernanover 6 years ago
It&#x27;s hard to say what the truth is here, but what I will say is if that Bloomberg reporter doesn&#x27;t have substantial evidence to prove that claim he could be in serious trouble. SuperMicro&#x27;s stock was down 50% straight after that articles release, and it&#x27;s not looking so hot right now either. He could be looking down the barrel of an SEC investigation very soon.
_pmf_over 6 years ago
&gt; &quot;As a matter of practice, before servers are put into production at Apple they are inspected for security vulnerabilities and we update all firmware and software with the latest protections.&quot;<p>They do not have equipment to detect this kind of attack, period. It&#x27;s not viable for each device, and it&#x27;s not even viable for sampling a subset of devices from a given production batch. Some components are physically inaccessible and would require desoldering of other components to even access them in any way.<p>These kinds of attacks cannot be generically detected in any economically feasible way; it must be prevented by drastically clamping down the supply chain and the logistics chain.
charlyslover 6 years ago
Regardless of whether this particular case is true or not, given the crucial role of computer systems in so many key institutions, it seems to me extremely risky to trust Chinese suppliers not to try to compromise critical infrastructure.<p>Then again, I understand that it could be argued that, if this is confirmed, to me it would seem quite rash from the Chinese, given that they would have known all along that such a scheme would be discovered sooner or later. It is one thing to plant a device as part of a spy operation, quite another to consistently compromise a whole supply chain.<p>Whichever is the case, the national interest and commercial interests seem to be seriously incompatible with one another when it comes to outsourcing such critical infrastructure to China, this seems obvious to me, regardless of the China policy of who is in government in US.
RepAgentover 6 years ago
&gt; Despite numerous discussions across multiple teams and organisations, no one at Apple has ever heard of this investigation.<p>If this is some kind of ongoing national security issue with nondisclosure requirement authorized by the Director of the FBI, like this big breach could be, people involved are not allowed to talk about it even inside their company.<p>Of course it would be advisable to inform higher ups in the Apple so that they would not issue a denial.
jdorfmanover 6 years ago
Stupid legal question, could this end up becoming a defamation lawsuit?
评论 #18146185 未加载
评论 #18148288 未加载
评论 #18146379 未加载
doe88over 6 years ago
I would say one specific detail (I haven&#x27;t looked at it though) would challenge the truth of the rebuttal of both Amazon and Apple is that if it is confirmed that both have severed ties with Supermicro around the same time, the coincidence would really seem odd then.
mcqueenjordanover 6 years ago
AWS Reply: <a href="https:&#x2F;&#x2F;aws.amazon.com&#x2F;blogs&#x2F;security&#x2F;setting-the-record-straight-on-bloomberg-businessweeks-erroneous-article&#x2F;" rel="nofollow">https:&#x2F;&#x2F;aws.amazon.com&#x2F;blogs&#x2F;security&#x2F;setting-the-record-str...</a>
partiallyproover 6 years ago
DoD contracts for the military require the hardware to be sourced and made in the US to prevent compromise. I wonder if one day we will see the DoD require any Cloud contractor that has DoD datacenters to source from the US or NAFTA countries...and what impact that would have. I&#x27;ve heard ramblings about a lot of companies moving their manufacturing and sourcing from China to Vietnam already.
hacknatover 6 years ago
Companies don’t give vehement denials like this unless they’re telling the truth. People claiming gag orders are crazy, mostly for thinking that Apple, or anyone else for that matter, would ever sign a document forcing them to lie to their customers (I’m not saying they wouldn’t lie, just that they wouldn’t sign anything that would force them to do so).
评论 #18146663 未加载
评论 #18149864 未加载
onetimemanytimeover 6 years ago
Very strong denial. Frankly, if true and Apple is saying this kind of a &quot;no&quot; shareholders will sue.<p>Two possibilities: Left hand doesn&#x27;t know (or can&#x27;t know) what the right hand is doing at Apple. Top secret?<p>Bloomberg was a victim of a hoax, some nation state (huh huhm!) wants to target China for something so they need a story.<p>Based on what I&#x27;ve read here these past days, I&#x27;m leaning towards the second one. Apple can hire the best or all Infosec companies in the world if security was compromised. In other words, they&#x27;d know by now, even if they missed it originally. Cat and mouse and all...
评论 #18146205 未加载
评论 #18160558 未加载
评论 #18149897 未加载
评论 #18146183 未加载
评论 #18146916 未加载
writepubover 6 years ago
Bloomberg needs to make a statement about all of this, either doubling down or issuing an apology. Either ways, we need a follow up and conclusion. Can we HN-ers tweet-request them (politely) to follow up?
aylmaoover 6 years ago
This article sounded a bit weird to me from the technical level, but I just assumed it could be lack of clear understanding on the nitty-gritty from the journalist, or just me not knowing about hardware enough to know what&#x27;s possible and how.<p>Given this is all getting a little fishy I&#x27;ll share what had me thinking:<p>1. The article mentions &quot;they were capable of doing two very important things: telling the device to communicate with one of several anonymous computers elsewhere on the internet...&quot;<p>Servers tend to run on VPNs. This being a dormant backdoor is believable, but then the article mentions:<p>&gt; &quot;American investigators eventually figured out who else had been hit. Since the implanted chips were designed to ping anonymous computers on the internet for further instructions, operatives could hack those computers to identify others who’d been affected.&quot;<p>Which makes me believe the devices were active and somehow circumvented corporate VPNs. I&#x27;m unsure how undetectable this could be using the system&#x27;s network stack (or if it would be possible at all)-- would the claim then be that this tiny device shipped with a whole TCP&#x2F;IP layer and some sort of very powerful wireless capability?<p>2. It continues with: &quot;and preparing the device’s operating system to accept this new code&quot;<p>Is this possible? Where would a device like this need to be wired to be able to write to memory with some arbitrary payload to do this? From the pictures it looks like it has 6 pins maximum-- could this do? If so, wouldn&#x27;t this mean this device would need to do some next-level signal processing that would probably require advanced computation? Could said computation be done by a processing unit that fits the size of this chip?<p>Moreover, assuming it takes control of the OS independently would imply there&#x27;s some decent amounts of memory in here, to hold the payload, etc. no? But if it&#x27;s just a backdoor that doesn&#x27;t take control of the OS, then how is it communicating over the internet with other machines like the article claims?<p>Again, I might be wrong and things that I don&#x27;t think possible might. I&#x27;m mostly just curious to know if my intuition is too naive. Please comment below if you know more about these things than I do.<p>EDIT: I was really disappointed that the article itself didn&#x27;t go into these technicalities, because IMO this would be an impressive feat and newsworthy by itself. The lack of alternative coverage in sources more close to technical expertise was weird to me.
评论 #18146678 未加载
评论 #18146656 未加载
okketover 6 years ago
FYI: &quot;Britain’s national cyber security agency said on Friday it had no reason to doubt the assessments made by Apple and Amazon that refuted a Bloomberg story that their systems contained malicious computer chips inserted by Chinese intelligence. [...]&quot;<p><a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-china-cyber-britain&#x2F;uk-cyber-security-agency-backs-apple-amazon-china-hack-denials-idUSKCN1MF1DN" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-china-cyber-britain&#x2F;uk-cy...</a>
chasd00over 6 years ago
Incredibly interesting story and discussion, this is why i come to this site.<p>Isn&#x27;t this practice known, if not common, in the infosec&#x2F;intelligence communities at the nation level? There&#x27;s lots of stories of hardware exploits in copy machines, faxes, etc that took place during the Cold War.
评论 #18152916 未加载
xmlyover 6 years ago
The rice is indeed small, but it is not small on an IC chip. When people check the chip, they usually use a tool called microscope, like this <a href="https:&#x2F;&#x2F;goo.gl&#x2F;1XK4YK" rel="nofollow">https:&#x2F;&#x2F;goo.gl&#x2F;1XK4YK</a>.
评论 #18146431 未加载
评论 #18147044 未加载
GordonSover 6 years ago
The cynic in me wonders about the plausibility of all this.<p>Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable.<p>Secondly, why Bloomberg? It&#x27;s an odd organisation to get a scoop on something like this.<p>Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the bottom. I imagine that would be very difficult to keep secret.<p>Finally, the timing is very suspicious - it comes with midterms approaching, and Trump and China arguing over trade tarrifs; it would serve the political narrative well for China to be painted as the &#x27;bugbear de jour&#x27;, and this also plays to the MAGA crowd.
评论 #18146566 未加载
评论 #18146204 未加载
评论 #18146821 未加载
评论 #18146198 未加载
评论 #18146672 未加载
avryhofover 6 years ago
Political mind games.<p>Right now, most of the tech industry, and a good portion of the news media are at odds with the executive branch of the government.<p>This article puts at least one popular news outlet against several tech industry giants. Divide.<p>What comes after divide? ...and who has the most to gain? I doubt it&#x27;s <i>actually</i> our executive branch. I think they could be getting played just as much as Bloomberg and the Tech industry.
yAnonymousover 6 years ago
Consider that Apple also stated this a few years back:<p>&gt;&quot;We have never heard of PRISM. We do not provide any government agency direct access to our servers, and any government agency requesting customer data must get a court order.&quot;<p>Their whole business is built around lying to customers.
deftover 6 years ago
My personal theory is this is a ploy to get people to believe Trump&#x27;s anti-china narrative meant to distract from the Russia narrative.
评论 #18146447 未加载
评论 #18146161 未加载
kerngover 6 years ago
This will be interesting to follow, it&#x27;s very unlikely there is not some truth to this. The fact that Apple and others are pushing so strongly against the story (very defensive) which makes me believe they are hiding something for sure.
ElBartoover 6 years ago
They complain too much...<p>Apple apparently entirely dropped Supermicro as a supplier over a few weeks when they were planning a large order(source: theregister.co.uk).<p>The ones who should strongly deny such a story, if it is indeed incorrect, are Supermicro. Is there a statement from them?<p>Edit: yes, there is. They are &quot;not aware of any investigation&quot;. That tells me all I need to know...
评论 #18146128 未加载