Slashdot Mirror


Apple Insiders Say Nobody Internally Knows What's Going On With Bloomberg's China Hack Story (buzzfeednews.com)

An anonymous reader quotes a report from BuzzFeed News: Multiple senior Apple executives, speaking with BuzzFeed News on the condition of anonymity so that they could speak freely all denied and expressed confusion with a report earlier this week that the company's servers had been compromised by a Chinese intelligence operation. On Thursday morning, Bloomberg Businessweek published a bombshell investigation. The report -- the result of more than a year of reporting and over 100 interviews with intelligence and company sources -- alleged that Chinese spies compromised and infiltrated almost 30 U.S. companies including Apple and Amazon by embedding a tiny microchip inside company servers. Both Amazon and Apple issued uncharacteristically strong and detailed denials of Bloomberg's claims.

Reached by BuzzFeed News multiple Apple sources -- three of them very senior executives who work on the security and legal teams -- said that they are at a loss as to how to explain the allegations. These people described a massive, granular, and siloed investigation into not just the claims made in the story, but into unrelated incidents that might have inspired them. A senior security engineer directly involved in Apple's internal investigation described it as "endoscopic," noting they had never seen a chip like the one described in the story, let alone found one. "I don't know if something like this even exists," this person said, noting that Apple was not provided with a malicious chip or motherboard to examine. "We were given nothing. No hardware. No chips. No emails." Equally puzzling to Apple execs is the assertion that it was party to an FBI investigation -- Bloomberg wrote that Apple "reported the incident to the FBI." A senior Apple legal official told BuzzFeed News the company had not contacted the FBI, nor had it been contacted by the FBI, the CIA, the NSA or any government agency in regards to the incidents described in the Bloomberg report. This person's purview and responsibilities are of such a high level that it's unlikely they would not have been aware of government outreach.

3 of 176 comments (clear)

  1. This story has the presumption that Apple by mykepredko · · Score: 4, Informative

    Engineers are not intimately involved in the design, support and software maintenance of their products.

    I've worked with Apple, Dell and HP server design teams in a past life and it would be highly unlikely that anything could be added to the products by board stuffers without being discovered.

    Typically for most vendors, the first failed products go straight to development to understand what the problem is to see if there are any design issues. One of the first thing that is done in the process is a review (usually by a junior engineer/technician) to make sure there haven't been any unapproved part substitutions - anything added at this point would be found. It should also be pointed out that Apple products have WiFi/BT built in which means FCC testing and that requires Apple to verify that the product is identical to what will be going down the line - if the PCB gets changed to add a chip without Apple's prior approval and validation by repeating the FCC testing then, based on the contracts I've seen and been a part of, Apple would be demanding huge amounts of compensation as well as making the vendor pay to roll the field.

    This doesn't mean that Apple hasn't added the chips for US/other governmental snooping just that it's highly unlikely that the manufacturing partners added something without Apple's approval.

  2. Re:ah, the good old times by AmiMoJo · · Score: 5, Informative

    It's more like the opposite; the myths never die. Remember that famous slide that Snowden leaked showing the timeline of when the NSA infiltrated Apple, Google, Microsoft and various other tech companies? All denied they were helping the NSA but many people still believe that they are, even long after further slides showed that they were actually attacked and later took steps to prevent data collection based on the leaked info.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  3. Re:Not Sure What to Believe by Zontar+The+Mindless · · Score: 3, Informative

    This intelligence community and media were the same ones who lied us into Iraq, remember?

    *I* remember certain parties within the Bush Administration ignoring their intelligence agencies (and not just their own) and feeding a bunch of crap to the media that was later shown in the media to be just that—crap.

    --
    Il n'y a pas de Planet B.