Sources: US investigators say hardware and firmware of Supermicro servers were tampered with as late as 2018, via chips with backdoors sending data to China
It has been two and a half years since … John Gruber / Daring Fireball : Bloomberg, at Long Last, Follows up on ‘The Big Hack’, and It's Nothing but a Pile of Sophistic Horseshit Thom Holwerda / OSnews : The long hack: how China exploited a US tech supplier Andrew Couts / Gizmodo : The Most Infamous Story in Tech Returns With New Details—but No Hard Evidence Jack Purcher / Patently Apple : Bloomberg Revisits their 2018 Story titled ‘The Big Hack’ in an updated report titled ‘The Long Hack: How China Exploited a U.S. Tech Supplier’ Sam Reynolds / Wccftech : Bloomberg Wants You To Believe in its Mythical Supermicro Spy Chips Msmash / Slashdot : The Long Hack: How China Exploited a U.S. Tech Supplier Mike Wuerthele / AppleInsider : SuperMicro server spy chip story returns, with no more proof than before Tweets: @pwnallthethings : tl;dr is a source misunderstood an FBI defensive briefing on China's supply chain activities, leaked it to the press, and bloomberg has *again* failed to do the work necessary to verify the sensational claims, because they mistake impressive credentials with domain expertise. @pwnallthethings : Oh man, guess we have to do supermicro chip saga again Costin Raiu / @craiu : This new Bloomberg story be like: “alright guys, listen, we weren't entirely correct about that supermicro bug, but we weren't entirely wrong either because, Lenovo, and, intel, and chips encrypted in motherboard and did you btw hear about the bios thing at pentagon?” @pwnallthethings : Ok lets do a thread breaking the article down into its constituent parts to see why it's BS. For reference, the article is here: https://www.bloomberg.com/... Rene Ritchie / @reneritchie : Has the NYTimes, WaPo, or anyone else has followed up and reported on any of this? If not, it is beyond perplexing that Bloomberg persists with this, not despite the denials, but despite the complete lack of corroborating reporting from any other outlet. https://twitter.com/... Glenn Fleishman / @glennf : @WilliamTurton @pwnallthethings @jamil_n_jaffer This is a tendentious supply. Extraordinary claims require specific evidence, even if the sourcing is anonymous and requires protection. There has never been anything specific to the very precise claims made. Companies that would be subject to severe SEC sanctions and lawsuits Catalin Cimpanu / @campuscodi : I'm not done with work today so I don't have the time to explain why that new Bloomberg piece is “ehh,” but Matt has done a great job here: https://twitter.com/... William Turton / @williamturton : This story is really impressive. The on the record quotes alone are jaw dropping. https://www.bloomberg.com/... Glenn Fleishman / @glennf : @WilliamTurton @pwnallthethings @jamil_n_jaffer for making definitive statements denying in detail nearly every aspect of the story have done so. No other reporters (and, yes, others have worked on this) from any other media organization have been able to confirm any of the specific, severe claims cited in the article. @baldingsworld : I have no specific knowledge of this case but we can say without any doubt that China does engage in this behavior inserting malicious code at the most fundamental level. It is not just Chinese firms but yes even US firms they seek to compromise https://www.bloomberg.com/... John Gruber / @gruber : @ambodnar What part of today's story confirms any of the disputed parts of the 2018 story? I didn't see anything. It's creating the illusion of confirmation but they still haven't found one compromised piece of kit, and today's story said nothing about Apple or Amazon. Sabotage / @sbtge : Since we're on this bullshit again I'm going to go through the article and point out everything that's either irrelevant or incorrect, with explanations. https://twitter.com/... Jesse Felder / @jessefelder : “Supermicro is the perfect illustration of how susceptible American companies are to potential nefarious tampering of any products they choose to have manufactured in China.” https://www.bloomberg.com/... Jason Syversen / @jsyversen : @Bloomberg has a second story on Supermicro Chinese penetration and exfiltrating data from US firms/DoD agencies. This time they actually get some people on the record and have even more unnamed sources. Still no hard evidence though. https://www.bloomberg.com/... https://twitter.com/... Scott Arciszewski / @ciphpercoder : Maybe Bloomberg should spend more time on publishing evidence than on graphic designs for their news articles? https://twitter.com/... David S. Joachim / @davidjoachim : 🇨🇳 EXCLUSIVE: U.S. investigators found evidence that China was repeatedly manipulating Supermicro products used by the U.S. military + big corporations Supermicro says it was never told Neither was the public By @jordanr1000 @MichaelRileyDC https://www.bloomberg.com/... @business https://twitter.com/... @pwnallthethings : This story is too big, and the refutations too blunt and too numerous to support on this level of third- and fourth-hand sourcing. If they have documents: go for it. Make fools of Apple, Amazon, FBI, NSA, DHS and ODNI by publishing them. Otherwise, this story should not have run. @pwnallthethings : Apple's counter-statement very directly said Bloomberg's report was just wrong, and that their “best guess” was Bloomberg had got confused with an incident in 2016 that Apple concluded was accidental and not a targeted attack, and in any case, not about tiny chips. https://twitter.com/... Kevin Beaumont / @gossithedog : this is one of the problems many infosec reporters face btw, there's basically lots of stakeholders in the field who, frankly, aren't very close to the coalface - i.e. Chinese whispers (pun not intended) end up in media. https://twitter.com/... Thomas Rid / @ridt : This started like a nice crisp Friday morning and then I had to wade through another Bloomberg chip tale. If you did too, don't miss this razor-sharp thread > https://twitter.com/... Lesley Carhart / @hacks4pancakes : @bettersafetynet @business They lost credibility with the entire cybersecurity community last time by refusing to provide evidence, most of us don't even talk to their journalists anymore and now, this... unbelievable. Mick Douglas / @bettersafetynet : @business If this is true, WE NEED TO KNOW. Show us some proof! Anything! PLEASE!! You have no idea how bad this goes each time you dig this corpse up and defile it again. Thomas Brewster / @iblametom : So the Bloomberg follow up to the 2018 China hacks Supermicro story is interesting. It has named sources and some unnamed ones that I'd guess are credible. Am I wrong to start believing? https://www.bloomberg.com/... @jkylebass : How China Hacks Supermicro Servers that supply the majority of the tech titans and the US Defense Department. Robertson and Riley spent 3 years reporting an enormous counterintelligence investigation. MUST READ! @ABlinken @AmbCuiTiankai https://www.bloomberg.com/... Tim Culpan / @tculpan : An important follow up to the 2018 “spy chip” story. It's worth reading all the way to the end. https://twitter.com/... Alex Webb / @atbwebb : The Twitter commentariat will inevitably start weighing in on whether they believe the story or not. I would urge them to get sources of their own before they do so. An opinion, as I know too well, is not the same as a reported fact, particularly when it's on the record. https://twitter.com/... Akshat Rathi / @akshatrathi : The sheer amount of work that has gone into this story is head-spinning. Kudos to @jordanr1000 & @MichaelRileyDC https://www.bloomberg.com/... Gerry Shih / @gerryshih : *Pushes chips all in* https://www.bloomberg.com/... https://twitter.com/... Ashadi Hopper / @ashadihopper : Good to see @Bloomberg sticking to its original reporting, despite criticisms from non-entities on the fringes of journalism like @daringfireball https://www.bloomberg.com/... Fidel Ernesto / @checastro728 : And in 2015, the Federal Bureau of Investigation warned multiple companies that Chinese operatives had concealed an extra chip loaded with backdoor code in one manufacturer's servers. https://www.bloomberg.com/... Alex Webb / @atbwebb : Colossal props to @jordanr1000 and @MichaelRileyDC for this one. So much detail on how this came about. https://www.bloomberg.com/... Alex Hern / @alexhern : Almost three years later, Bloomberg is doubling down on its 2018 story alleging a massive hardware-based supply-chain attack that affected Apple, Amazon and others. The initial story was flatly and explicitly denied by almost every organisation named https://www.bloomberg.com/... Alex Hern / @alexhern : This story feels like it sits alongside the first, rather than proving, or retracting, any of the claims in that. It provides more testimony supporting the idea that Supermicro was involved in a series of supply-chain attacks on American companies.