Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
China Communications Network Privacy Security Apple

Apple Insiders Say Nobody Internally Knows What's Going On With Bloomberg's China Hack Story (buzzfeednews.com) 176

An anonymous reader quotes a report from BuzzFeed News: Multiple senior Apple executives, speaking with BuzzFeed News on the condition of anonymity so that they could speak freely all denied and expressed confusion with a report earlier this week that the company's servers had been compromised by a Chinese intelligence operation. On Thursday morning, Bloomberg Businessweek published a bombshell investigation. The report -- the result of more than a year of reporting and over 100 interviews with intelligence and company sources -- alleged that Chinese spies compromised and infiltrated almost 30 U.S. companies including Apple and Amazon by embedding a tiny microchip inside company servers. Both Amazon and Apple issued uncharacteristically strong and detailed denials of Bloomberg's claims.

Reached by BuzzFeed News multiple Apple sources -- three of them very senior executives who work on the security and legal teams -- said that they are at a loss as to how to explain the allegations. These people described a massive, granular, and siloed investigation into not just the claims made in the story, but into unrelated incidents that might have inspired them. A senior security engineer directly involved in Apple's internal investigation described it as "endoscopic," noting they had never seen a chip like the one described in the story, let alone found one. "I don't know if something like this even exists," this person said, noting that Apple was not provided with a malicious chip or motherboard to examine. "We were given nothing. No hardware. No chips. No emails." Equally puzzling to Apple execs is the assertion that it was party to an FBI investigation -- Bloomberg wrote that Apple "reported the incident to the FBI." A senior Apple legal official told BuzzFeed News the company had not contacted the FBI, nor had it been contacted by the FBI, the CIA, the NSA or any government agency in regards to the incidents described in the Bloomberg report. This person's purview and responsibilities are of such a high level that it's unlikely they would not have been aware of government outreach.

This discussion has been archived. No new comments can be posted.

Apple Insiders Say Nobody Internally Knows What's Going On With Bloomberg's China Hack Story

Comments Filter:
  • by hjf ( 703092 ) on Saturday October 06, 2018 @08:14AM (#57437102) Homepage

    Remember when people used to answer "I cannot confirm on deny that such action has taken place"?
    Nowadays they just flat out deny it. And then months later the truth comes up, heads roll, stock prices drop, investors buy the stock for pennies. Then people forget about it, stock prices go up, investors sell the stock, and make a lot of money.
    Everyone's happy. The head that rolled? Got his golden parachute. The investors? They got a lot of money. Everyone else? Don't remember a thing.

    • Everything else is a Lie. :)

      Like they Could tell you.

    • by AmiMoJo ( 196126 ) on Saturday October 06, 2018 @11:13AM (#57437726) Homepage Journal

      It's more like the opposite; the myths never die. Remember that famous slide that Snowden leaked showing the timeline of when the NSA infiltrated Apple, Google, Microsoft and various other tech companies? All denied they were helping the NSA but many people still believe that they are, even long after further slides showed that they were actually attacked and later took steps to prevent data collection based on the leaked info.

    • Re: (Score:1, Insightful)

      by turkeyfish ( 950384 )

      Who needs truth now that we have Kavanaugh?

    • Remember when people used to answer "I cannot confirm on deny that such action has taken place"?

      Sometimes there are stories that are just false or faked. So what else is Apple supposed to say? Now tell me, is it true that you are raping your children? Remember that any denial will prove that you are guilty. Refusing to comment will also prove that you are guilty. You might try admitting it, but I think that also proves you are guilty.

  • It's the US government.

  • ..."we can neither confirm nor deny the story".
  • by crow ( 16139 ) on Saturday October 06, 2018 @08:41AM (#57437176) Homepage Journal

    I'm not sure what to believe here.

    In support of the story, China does have a long history of industrial espionage and other spying. Many believe that their economic rise was boosted by stolen IP.

    On the other hand, the current administration is clearly using allegations against China to balance the revelations that continue to come out about Russian interference. Many of the allegations from this administration towards China appear to be completely fabricated.

    But this allegation is much more detailed than anything the administration has been imagining, but the sources are all anonymous.

    • Re: (Score:1, Insightful)

      There is no way in the world that the NSA and the rest of the intelligence community are on Trump's side. In fact, they are his sworn enemies. The media, including Bloomberg, would never be on Trump's side. The media are Trump's sworn enemies. Both of them have been pushing Russia, hard, in an attempt to overthrow him. None of this makes sense.
      • It's more like the intelligence community and the media are on America's side, and guess who isn't.

        • by Anonymous Coward
          The media are on their own side, and the intelligence community is, as far as I can tell, insane. You can pile as many insults on Trump as you like, and most of them will probably be fair - but the guy isn't anti-American in any sense I can see.
        • LOL no. The intelligence community utterly despises the American people (this includes you). The media utterly despises us as well (guess who this includes?) If you're not a member of their tiny community, you're one of us. They number no more than the population of a small town. All of them put together would fit comfortably inside Waco, Texas. The Jacksonians are on the side of the American people, as they always have ever been.
        • This intelligence community and media were the same ones who lied us into Iraq, remember? You seriously think they're on your side? How was your interest served by invading Iraq? If you didn't make a mint on military procurement, you're not in their ingroup and it is folly to identify with their interests. You are in their outgroup, along with the rest of us Americans.
    • by AmiMoJo ( 196126 )

      What makes me doubt it is how blatant it would have been. The Chinese government would have had to develop and manufacture this chip, and then get it installed on Supermicro boards which means either getting Supermicro in on it or getting the factory in on it, because I can't see them being able to alter the PCB CAD files and get a part added to the bill of materials without anyone noticing. I mean everything on the BOM has to be paid for, someone has to check the manufactured boards meet the layout and tha

      • by sphealey ( 2855 )

        = = = What makes me doubt it is how blatant it would have been. The Chinese government would have had to develop and manufacture this chip, and then get it installed on Supermicro boards which means either getting Supermicro in on it or getting the factory in on it, because I can't see them being able to alter the PCB CAD files and get a part added to the bill of materials without anyone noticing. = = =

        There are a lot of difference factions in the government of the PRC and in the military of the PRC and

  • by mykepredko ( 40154 ) on Saturday October 06, 2018 @08:45AM (#57437188) Homepage

    Engineers are not intimately involved in the design, support and software maintenance of their products.

    I've worked with Apple, Dell and HP server design teams in a past life and it would be highly unlikely that anything could be added to the products by board stuffers without being discovered.

    Typically for most vendors, the first failed products go straight to development to understand what the problem is to see if there are any design issues. One of the first thing that is done in the process is a review (usually by a junior engineer/technician) to make sure there haven't been any unapproved part substitutions - anything added at this point would be found. It should also be pointed out that Apple products have WiFi/BT built in which means FCC testing and that requires Apple to verify that the product is identical to what will be going down the line - if the PCB gets changed to add a chip without Apple's prior approval and validation by repeating the FCC testing then, based on the contracts I've seen and been a part of, Apple would be demanding huge amounts of compensation as well as making the vendor pay to roll the field.

    This doesn't mean that Apple hasn't added the chips for US/other governmental snooping just that it's highly unlikely that the manufacturing partners added something without Apple's approval.

    • The PCB layout would not be changed to include a rogue chip. An additional module would simply be added at the right place in some glue logic on the current board. The FCC would not be notified, because obviously Apple was not notified that the 'new' glue logic chip is being placed instead of the original.

    • You've raised an interesting point. Have you reviewed the article? There is a difference between "not on the manufacturer's component list" and "not part of the original design". That distinction could leave an opportunity for engineers at the subcontractor SuperMicro was using to insert the component into the circuit board design and component list, so that it would not show up as an unexpected part for a typical hardware evaluation. It would require a much deeper knowledge of the design to say "what is t

      • by mykepredko ( 40154 ) on Saturday October 06, 2018 @11:12AM (#57437722) Homepage

        Two comments back.

        1. The servers in question aren't Apple hardware (that isn't set out in the article) as an AC pointed out. Doing a bit of research, the servers in question are Teradata "Extreme Data Appliances".

        2. When I was at Celestica, I was part of the team responsible for building Apple products - as a sub, you don't mess with the BoMs, much less the schematic/PCB layout without Apple review and approval without facing HUGE penalties (the least of which is losing the business). This is true for any Tier 1 vendor.

        • That is an interesting point. But I'd assume that, as engineers at a subcontractor business, they probably don't care much about penalties form Apple. People will do astounding things for very small bribes or startlingly weak blackmail at the right moment form the right person. They might not have even known they were doing, they might merely have left their workstations insecure by accident.

          • Engineers might not care but their bosses do.

            Contract manufacturers in China have amazing networks. If, as an engineer, you do something that loses your company business or causes them fines you'll find yourself shitcanned with absolutely no chance at work.

            • > you'll find yourself shitcanned with absolutely no chance at work.

              That's interesting. In the USA, employees caught with even criminal offenses in the workplace are often dismissed, quietly, to avoid scandal and legal backlash. The "blackballing" is often ineffective.

              Even if the "shitcanning" is true, rationally handling consequences is not something we can completely rely on to prevent criminal or foolish behavior. I'd expect lower level CAD engineer to require only a modest bribe. It can be very tempt

  • Option A: The Chinese have compromised Supermicro, and have spy chips embedded in every major datacenter and product from companies such as Apple, Amazon, Dell, etc. These publicly traded companies are now involved in the wholesale denial of this event taking place

    Or, as someone who remembers the media blitz in the lead up to the Iraq war:

    Option B: The Trump "administration" (slogan: "Not Nazis Only Because We're Too Incompetent) desperately wants a media disinformation campaign to sway nation
    • So the guy with the new 2,700,000th Slashdot account is going to pipe up to attack Anonymous Cowards and their coordinated fascist campaign.

      You've been rather loud in the last several days, dude.

    • by Anonymous Coward

      Option B:

      With their current relationships, the Trump administration couldn't get the media to print that the sun will rise tomorrow. They'd print eternal night was coming just to flare him up to send a few tweets and drum up clicks.

      Option C is far more likely: Military-Industrial complex in Neocon Washington wants to march to war, irrespective of administration, and is getting their propaganda arm in the MSM to pose tech bullshit stories at all cost. As you say, the play is too obvious after you've seen to

  • by aglider ( 2435074 ) on Saturday October 06, 2018 @08:54AM (#57437216) Homepage

    Please, take a sample of those servers, open them and let a bunch of experts to investigate.
    Is it that difficult?

    • by JBMcB ( 73720 )

      That won't happen. At least it won't get reported on. Never let the facts get in the way of a good story.

    • Other than the fact that that is exactly what was done, Apple has NEVER given straight talk about flaws in its consumer products, much less internal security issues.
    • by AmiMoJo ( 196126 )

      Used boards are on eBay right now. Anyone with a few hundred bucks could investigate.

    • One side alleges the servers were removed back in 2015. The other side says the malicious servers never existed, but that the Super Micro servers that did exist were decommissioned in 2016 for unrelated reasons. Either way, there aren’t any servers around to open up and check.

  • by aaarrrgggh ( 9205 ) on Saturday October 06, 2018 @09:02AM (#57437242)

    Midterm elections, or quarterly reports... so complicated!

  • by timholman ( 71886 ) on Saturday October 06, 2018 @09:06AM (#57437254)

    "I don't know if something like this even exists," this person said, noting that Apple was not provided with a malicious chip or motherboard to examine.

    My colleagues and I were discussing this story last week. My research group has done some work in secure computing, and we were frankly surprised that someone would bother to add a compromised piece of hardware to a motherboard.

    Software intrusions always provide plausible deniability to the attacker, which is critical to state-sponsored espionage. But a hardware hack, where someone succeeds in adding a component to a motherboard without the knowledge of the designer, is far more difficult and far more dangerous. A device in hand can be reverse-engineered, and forensics performed to determine exactly when and how it was inserted into the manufacturing chain. Experts can even determine the exact IC fab in which the chip was manufactured.

    On top of that, a company that allows its manufacturing process to be compromised has essentially ruined itself. What customer would trust it again? Sure, it is possible that the Chinese government would be willing to spend the money to create a company that could be sacrificed to a state espionage effort, but the problem remains that if the espionage is uncovered, no one will trust any installed hardware purchased from them.

    Software intrusions remain extremely successful. The Chinese purportedly breached the OPM and copied all of the personnel files for every U.S. citizen with a security clearance back in 2014, but to this day no one can be entirely sure who was behind it. Likewise, Russia constantly denies its own state-sponsored hacks. For that matter, so does the U.S.A., and everyone else. Why give up such a successful exploit vector in favor of one that provides an undeniable trail back to the perpetrator?

    So exactly what is the story behind this Bloomberg article, and where is the proof that the hack actually happened? Someone needs to produce some hardware as proof. This story is definitely becoming even more interesting.

    • by Jahoda ( 2715225 )
      So exactly what is the story behind this Bloomberg article, and where is the proof that the hack actually happened? Someone needs to produce some hardware as proof. This story is definitely becoming even more interesting.

      Cui bono?
    • This has happened a lot lately, don't discount it. Just about when Trump was going to end the Syrian war, Assad attacked with chemical weapons, just about the worst possible timing. When Russia should have been laying low, it did that chemical weapons poisoning in Britain, again the Russian government's timing was horrible. Iran just got caught red-handed planning a terrorist attack in France, just at the time they were about to get out of the US sanctions by bypassing them through the EU. So don't underes
      • Just about when Trump was going to end the Syrian war...

        That's a mighty long-winded way to say "Never".

        • Oh, he was. Then the next week Assad attacked with chemical weapons, killing that idea entirely. Even though it was probably the worst thing he could have done. Trump launched missiles at Syrian airfields - earning unprecedented praise from the US media. Just goes to show you governments make terrible decisions at the worst times.
          • ...earning unprecedented praise from the US media.

            That's a massive overstatement, and you seem to be making a better case for the possibility that Trump and Assad's fight over Syria was a coordinated public staging of aggression.

            • It was notable because the press NEVER praises Trump, and yet when he attacked a country that's not at war with us, suddenly they were full of approval. Weird, eh?
      • Iran just got caught red-handed planning a terrorist attack in France
        Pretty unlikely. Why would Iran attack one of its biggest (if not THE BIGGEST) trade partners?

        • by mentil ( 1748130 )

          France tends to piss off Muslims (remember the Charlie Hebdo attack?) and Iran holds the reins of Hezbollah and other terrorist groups. There have been several Islamic terrorist attacks in France in the past few years, I haven't done research but it wouldn't surprise me if some of the attackers had ties to Iran. I suspect it's less "Iran sicced its dogs" so much as "didn't keep their dogs on a short enough leash." Also, countries go after their biggest trade partners *cough* China and USA *cough* all the ti

          • I read up a bit on it.

            An iranian group, and some traveling iranian politician was involved, probably planned to assassinate another iranian living in France ... so: no terrorist attack.

    • ;)
      Or maybe the carriers are in on it. ;);)

    • by AHuxley ( 892839 )
      Re "where is the proof that the hack actually happened?"

      The part about "Since the implanted chips were designed to ping anonymous computers on the internet for further instructions, operatives could hack those computers to identify others who’d been affected."?

      Really smart people with investigative skills in the USA followed the "internet" use back from the chips?
  • Bloomberg got pwn3d (Score:5, Interesting)

    by mveloso ( 325617 ) on Saturday October 06, 2018 @09:13AM (#57437268)

    Quite frankly, Bloomberg got fooled by a bunch of people who, for whatever reason, gave them this story.

    Why would people do this? I can think of a bunch of reasons off the top of my head:

    * someone wanted SuperMicro to play ball, and they refused. This is payback.
    * someone wanted SuperMicro's stock to fall, and fall a lot.
    * someone wanted to demonstrate they could get the press to print anything, no matter how ridiculous.
    * someone wanted to teach Bloomberg a lesson
    * someone wanted to throw doubt on the Chinese supply chain. The one that supplies like all the electronics to the US.
    * someone wanted China to share some of the attention

    It could be all of the above. But really, the story is bullshit. The superchip is a story cooked up to fool reporters, reporters who are smart enough fool themselves into thinking they understand how computers work.

    What I'm surprised at is that they didn't ask anyone in the industry about the details. You can always theoretically wire something into a mobo and hide it. You can't practically get something that small to do everything they said it could do. Even James Patterson could tell the difference.

    • What I'm surprised at is that they didn't ask anyone in the industry about the details. You can always theoretically wire something into a mobo and hide it. You can't practically get something that small to do everything they said it could do. Even James Patterson could tell the difference.

      Bloomberg had several sources inside the industry about the details, including Apple themselves.
      • Bloomberg had several fake sources inside the industry about the details, including Apple themselves.

        There, fixed that for you.

    • Don't think so - Bloomberg says they have 17 independent sources for this story.
      • by mentil ( 1748130 )

        Or the journalist's phone line was rerouted and he talked to 17 different spooks. No matter how it shakes out, there's way more to this story.

    • by Anonymous Coward

      The story is quite plausible though. It would be entirely possible to hook in to the BMC with a small chip and cause it to do "other" stuff than it's suppose to. The BMC (Baseboard Management Controller) exists on a motherboard as it's own fully functional standalone computer. It has its own hardware, processor, embedded operating system, network controller, etc. It's a very simple system and that simplicity makes it easy to modify it. It runs all the time and can not be turned off. Although its network con

    • Exactly! This reminds us the Iraqi Weapon of Mass Destruction saga. At the end, it was the Americans who supplied Iraq the few remaining chemical bombs used in Iraq-Iran war to kill Iranian civilians. Of course, we Americans don't really care if the U.S. is a hypocritical terrorist country and we just promptly showed our patriotism and paid our money.

      The American media and political institutions need to portray China as an evil empire in order to garner readership and supports from its populace; the America

    • * all of the above?

    • Slightly offtopic, but item #3:

      * someone wanted to demonstrate they could get the press to print anything, no matter how ridiculous.

      Here's an article about a series of academic-journal hoaxes which were trying to get printed in the "the best journals in the relevant fields." --- Is Huge Publishing Hoax 'Hilarious and Delightful' or an Ugly Example of Dishonesty and Bad Faith? [chronicle.com]

      Of the 20, seven papers were accepted, four were published online, and three were in process when the authors [stopped.]

      "It could be all of the above. But really, the story is bullshit." -- I complete agree with you here.

  • Deep State Disinfio (Score:3, Interesting)

    by bill_mcgonigle ( 4333 ) * on Saturday October 06, 2018 @09:14AM (#57437274) Homepage Journal

    If there's one thing i like about Apple it's their intense hatred for either doing the government's bidding or funding their attempts to do so.

    If there's one thing I like about the Feds it's ... ok, there's nothing I like about the Feds but one can at least recognize that the powerful interests scratch each other's backs and Michael "Disarm the Jews" Bloomberg would be happy to help the FBI, et. al. build their case that Apple /must/ be /compelled/ to make iOS spy on its users for them, because "Apple can't even be trusted with its own security."

    Look for natural alliances and opportunities to harm their common enemy. Apple isn't making me buy their walled-garden shit so on this one they're an ally of the people who want privacy and personal freedom.

  • Assuming for argument that the substitution described in the Bloomberg article occurred, the group within Apple working on it may (a) have higher security clearances than Tim Cook and the VP of Communications (b) be under national security letter gag orders to say nothing to anyone including their bosses. In which case the executive levels of Apple management may sincerely believe that the situation did not happen when it actually did.

    • by ezdiy ( 2717051 )
      This. Possible need-to-know basis, and whoever got wind of it is gagged. Then, complete fabrication is also plausible, bloomberg isn't what it used to be when it comes to due diligence and impartiality in recent years.
    • by mentil ( 1748130 )

      So they contacted the FBI without going through Legal first? Or are you saying the anonymous source in the Legal department isn't talking because of the National Security Order (an NSL is only a request for information). Furthermore, Apple and other tech companies now have permission to give annual reports of how many NSO's they've received in the past year, so they all should've received one in 2015/16, that's easy to check.

    • The US government could produce gag orders, but the original story is that Apple employees went to the FBI. I would also like to know on which grounds there would be a gag order from the government. It doesn't make sense.
  • by Anonymous Coward

    China doesn't need to add any chips, the Intel PC architecture is such a bloody mess that all China would need to do is make changes to the firmware in order to get a permanent infection that is neither detectable not reversible without additional hardware tools.

  • The device in question would have to either be fed a refclock or derive it's own clock, a PLL to either multiply the refclock or to derive it from the differential signal, have a small processor core, RAM, ROM, and some way to communicate with it, as well as being fed by one of the power rails, probably a 1.00V or 1.05V rail. In a 10nm or 14nm bare die you might be able to make it small enough and thin enough to hide between layers of the many-layer PCBs that are current technology -- or for that matter you
    • It'd also need connections to the PCIe bus. That's easy enough to get, but it means a lot of traces going into a single chip that oughtn't have that many incoming traces. I'm thinking it'd be easier to modify the EFI firmware and hide a small extra processor in the southbridge chip.

    • by ezdiy ( 2717051 )
      I too tend to think this would be super over-engineered and the story sounds BS. But passive, 2 terminal SMT is a place where nobody would look, whereas a huge mux chip actually "does" something and would be more "intuitive" subject of scrutiny if something is taken apart to find out where the signal comes from - and would be much cheaper to manufacture a trojanized one.

      The thing reported might be viable though, possibly as a pull resistor for data line and nothing more. Power source is not really an iss
  • Someone stumbled across an NSA project and are laying all the blame on China.

    Everyone is denying everything in the hope that it goes away because if it turns out that it IS a three letter agency project, the pitchforks are going to come back out.

    • by sphealey ( 2855 )

      Yeah. Once you have gone down the rabbit hole once - and the document leaks of the last 5 years have taken anyone who is technically inclined there at least once - you will have a hard time NOT thinking something like this is what happened.

  • Who has the better track record for reporting factually-based truths: Bloomberg or those tech companies?

    Sadly, Bloomberg. Don't know what's going on as I haven't seen one opened --- so until that time I am withholding judgment as the hardware hacks have grown increasingly more sophisticated over the many years and have attended too many users forums in the past when technoid users discovered much of what the hardware was capable of, completely unknown to the designers.

    I remember the naysayers abou
  • I had shares of SMCI back in 2017 and sold them not long over these reports came out, that Apple dropped a large contract with Supermico over security concerns.

    https://www.marketwatch.com/st... [marketwatch.com]

    For Apple too say there were not aware of security issues with Supermico is BS.

  • This story is getting really weird. One possibility could that the thing was invented by US agencies to support the trade war with China. After all they alredy invented Sadam Hussein's WMD to support a real war.
  • The main question is what prompted Bloomberg to publish this story in the first place.
    They are well aware that the Chinese government carries grudges and will exact a large penalty from anyone harming China's interests.
    So why would Bloomberg, a firm that historically has tried hard to avoid offending China, publish a story designed to damage the reputation of the Chinese subcontractor base? Given the importance of China in the world financial framework, they are not an entity Bloomberg would casually offend

"The vast majority of successful major crimes against property are perpetrated by individuals abusing positions of trust." -- Lawrence Dalzell

Working...