China Infiltrated Apple, Amazon and Other US Companies Using Spy Chips on Servers, According To Bloomberg; Apple, and Amazon, Among Others Refute the Report (bloomberg.com)
Data center equipment run by Amazon Web Services and Apple were subject to surveillance from the Chinese government via a tiny microchip inserted during the equipment manufacturing process, Bloomberg BusinessWeek reported Thursday, citing 17 people at Apple, Amazon, and U.S. government security officials, among others. The compromised chips in question came from a server company called Supermicro that assembled machines used in the centers, the report added. The scrutiny of these chips, which were used for gathering intellectual property and trade secrets from American companies, have also been the subject of an ongoing top secret U.S. government investigation, which started in 2015, the news outlet reported. Amazon, which runs AWS, Apple, and Supermicro have disputed summaries of Bloomberg BusinessWeek's reporting.
The report states that Amazon became aware of a Supermicro's tiny microchip nested on the server motherboards of Elemental Technologies, a Portland, Oregon based company, as part of a due diligence ahead of acquiring the company in 2015. Amazon acquired Elemental as it prepared to use its technologies for what is now known as Prime Video, its video streaming service. The report adds that Amazon informed the FBI of its findings. From the report: One official says investigators found that it eventually affected almost 30 companies, including a major bank, government contractors, and the world's most valuable company, Apple. Apple was an important Supermicro customer and had planned to order more than 30,000 of its servers in two years for a new global network of data centers. Three senior insiders at Apple say that in the summer of 2015, it, too, found malicious chips on Supermicro motherboards. Apple severed ties with Supermicro the following year, for what it described as unrelated reasons. [...] [Update: Some counterpoint: According to an earlier report by The Information, security concerns were indeed a reason why Apple and Supermicro parted ways.] A U.S. official says the government's probe is still examining whether spies were planted inside Supermicro or other American companies to aid the attack. Some background on Supermicro, courtesy of Bloomberg: Today, Supermicro sells more server motherboards than almost anyone else. It also dominates the $1 billion market for boards used in special-purpose computers, from MRI machines to weapons systems. Its motherboards can be found in made-to-order server setups at banks, hedge funds, cloud computing providers, and web-hosting services, among other places. Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards -- its core product -- are nearly all manufactured by contractors in China. The company's pitch to customers hinges on unmatched customization, made possible by hundreds of full-time engineers and a catalog encompassing more than 600 designs. Further reading: Amazon Offloaded Its Chinese Server Business Because it Was Compromised, Report Says.
The report states that Amazon became aware of a Supermicro's tiny microchip nested on the server motherboards of Elemental Technologies, a Portland, Oregon based company, as part of a due diligence ahead of acquiring the company in 2015. Amazon acquired Elemental as it prepared to use its technologies for what is now known as Prime Video, its video streaming service. The report adds that Amazon informed the FBI of its findings. From the report: One official says investigators found that it eventually affected almost 30 companies, including a major bank, government contractors, and the world's most valuable company, Apple. Apple was an important Supermicro customer and had planned to order more than 30,000 of its servers in two years for a new global network of data centers. Three senior insiders at Apple say that in the summer of 2015, it, too, found malicious chips on Supermicro motherboards. Apple severed ties with Supermicro the following year, for what it described as unrelated reasons. [...] [Update: Some counterpoint: According to an earlier report by The Information, security concerns were indeed a reason why Apple and Supermicro parted ways.] A U.S. official says the government's probe is still examining whether spies were planted inside Supermicro or other American companies to aid the attack. Some background on Supermicro, courtesy of Bloomberg: Today, Supermicro sells more server motherboards than almost anyone else. It also dominates the $1 billion market for boards used in special-purpose computers, from MRI machines to weapons systems. Its motherboards can be found in made-to-order server setups at banks, hedge funds, cloud computing providers, and web-hosting services, among other places. Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards -- its core product -- are nearly all manufactured by contractors in China. The company's pitch to customers hinges on unmatched customization, made possible by hundreds of full-time engineers and a catalog encompassing more than 600 designs. Further reading: Amazon Offloaded Its Chinese Server Business Because it Was Compromised, Report Says.
Chinese market poison as baby food. Nobody should be doing business with them.
China been doing this for years and it's only just coming out.
Everyone involved on both sides has come out publicly to say Bloomberg is wrong. Why are we still talking about it?
All parties involved have it in their vested interest to deny this.
"That's the way to do it" - Punch
Where'd the chips come from? They are physical things that exist. Do you think Bloomberg faked the paper trail all the way up the supply chain (..)
Bloomberg says A, Apple, Amazon etc say B. That's where you need to back up your claim.
If Bloomberg did its job, it should have some expert(s) on call that can tell you what motherboard, what chip / where on the board, what pinout, what it does, and how they arrived at those findings. That's the core of their story after all.
If Bloomberg does, just publish those technical details & call it a day. If Bloomberg doesn't, then yes they are talking out of their nose and Apple, Amazon & co have every right to criticize them.
Sure, I bet it was strongly worded. With all of Apple's production in China, the Chinese could stop every iDevice from being made until Apple restaged manufacturing outside of China. While Apple has the cash reserves to weather the lack of product for over a year while that happens, the decline in market share during that interregnum would be near-fatal, if not fatal.
...let's hear more from people whinging about Trump's 'trade war' with China.
China's been a shitty actor on the world stage since they bred themselves out of irrelevancy.
Foreign companies have to establish a Chinese business, owned 51% by Chinese who almost always end up being a front for the PLA. ...and yet we should curry their favor so we can keep buying $9 folding chairs?
Draconian censorship laws. No free speech. No freedom of religion.
Currency manipulation and disregard for norms of international economic (and other) reporting.
Military occupation and absorption of neighbors it deems "were *actually* China anyway".
Sorry Hong Kongers, I guess you don't get to keep democracy and nobody cares...
An arbitrary, dangerously confrontational foreign policy including sweeping territorial claims.
Environmental destruction with impunity.
I don't like Donald Trump for a number of reasons, but the US confrontation with China is LONG past due; waiting any longer would likely make it military when China finally gets brazen enough to try to grab Taiwan.
-Styopa
I don't know to what degree "China" (it's government, it's people, or it's corporations, state owned or otherwise) are spying, but I do know it's not 0, not even close to 0. I have been close to accusations and convictions, they are absolutely spying using any available means. That's not surprising. If it made any sense to do it, adding stray hardware/software to a PC is definitely a viable approach to compromising it.
The real issue is technical. How do we create a secure compute environment? Apple has taken the route on its phones of building a very effective and secure trust chain. It is pretty hard for an unauthorized user to slip in stray firmware on their phones, I don't want to say impossible because there are some known and pretty exotic exploits. But very hard. Their design is such that even their MFGs cannot sneak in stray code to spy on you. The weakest point is still the single authorized user, and their ability to protect their passwords and biometrics. Apple's route also makes you, the owner, a perpetual customer rather than an owner. If they choose to lock you out, there's nothing you can do about it, your $1k phone is a paperweight.
PCs (I'm including desktops, servers and laptops) on the other hand are pretty much a free for all. The MFG can sneak on just about anything in their BIOS/EFI implementation, and anyone up and down the chain can do so without much oversight. It's a pretty open and competitive market, with many small players of little to no account, all trying to make the sale. Each of them provides their own hardware, and some EFI implementation they probably bought and then tailored to their implementation. Someone could also have added backdoors. That in turn hands off to my choice of OSes, which themselves could easily be compromised and I wouldn't know better until something happened. I am unquestionably the owner of this system, and can do anything I would like, but I also cannot rely on anything up and down the system. I'm the owner of a very leaky boat.
What we need is a system that can both be trustworthy and robust to middle-man attackers who may, at times, have direct hardware access, but still allows me to be the absolute owner of my hardware. I may make bad choices, those bad choices may compromise my system, but I need a foolproof way of knowing when I'm making a bad choice. It's not that easy of a problem in the current ecosystem, and we're waiting for someone to get caught doing something bad that forces our hand.
Why? You live in the US, Te US has a lot more options on ways to misuse your data in ways that could have far more impact on your life. What exactly could China do to you, an American citizen?
Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
Meanwhile, here's a complete list of Bloomberg's sources who were willing to speak on the record:
*crickets*
Were Woodward and Bernstein's Watergate source(s), e.g., Deepthroat, willing to have their names published?
How exactly does "slow, negotiated processes" fit with the military occupation of the South China Sea or Tibet?
Those cards turn up on eBay for peanuts, and TFA identifies the location of the chip. It should be possible to get one.
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
If you want to take credit, you have to take blame. I give 2 shits about Hilllary. What does her being a completely worthless piece of shit have to do with the current President and others in charge of the country doing everything they can to undermine American democracy and the livelihood of the American citizenry?
And if there is no lawsuit, what does that tell you?
(That was the rhetorical, but here's the answer: Somebody would prefer to keep the details out of a courtroom.)
Buying chips offshore is a national security risk and always has been. If you're stupid enough to think that the Chinese military won't exploit chips/software/tech products bound for the USA for their own benefit, I have a bridge I can sell you.
Of course, as always, profits before country. Can't restrict Northrop Grumman, ya know. And you can bet the current crop of republican technopeasants don't have this on their radar.
Please do not read this sig. Thank you.
Everyone involved on both sides has come out publicly to say Bloomberg is wrong. Why are we still talking about it?
All parties involved have it in their vested interest to deny this.
All parties are required by law to deny this. It's a classified investigation which Bloomberg says is still open. According to Bloomberg's reporting, they don't just want to deny it—they have to deny it. With the Supermicro boards in question in use by the DOD and the CIA, it's quite literally a matter of national security.