Slashdot Mirror


FBI Director on Whether Apple and Amazon Servers Had Chinese Spy Chips: 'Be Careful What You Read' (cnbc.com)

During a hearing in front of the Senate Homeland Security Committee on Wednesday, FBI Director Christopher Wray told senators to "be careful what you read," when asked about a recent story involving spy chips from China being secretly embedded into servers owned by Apple, Amazon and other big companies. From a report: Senator Ron Johnson, R-Wis., chairman of the committee, asked Wray when his agency found out about the chips that server manufacturer Super Micro implanted into server hardware, as reported last week by Bloomberg Businessweek. "I would say to the newspaper article or, I mean, the magazine article, I would say be careful what you read," Wray replied. "Especially in this context." Johnson called on Wray to speak to the accuracy of the story, telling the FBI director that, "We don't want false information out there." Wray said he couldn't offer much detail because the agency has a policy of not confirming or denying that an investigation is underway. "I do want to be careful that my comment not be construed as inferring or implying, I should say, that there is an investigation," Wray said. "We take very seriously our obligation to notify victims when they've been targeted."

124 comments

  1. Well; thanks for clearing that up!! by Anonymous Coward · · Score: 0

    Now I know something did or did not happen and someone did or did not know about it

    1. Re:Well; thanks for clearing that up!! by Darinbob · · Score: 3, Informative

      I remember seeing a news article from a sensationalistic source that had a picture of a chip. I immediately though that we had one of those chips, and it was just just an RF filter with only 2 pins. Of course, no one ever had a picture of the actual alleged chip but it was funny enough that they picked some random chip in order to scare their readers while everyone in the know would have known the picture was bogus.

    2. Re:Well; thanks for clearing that up!! by Anonymous Coward · · Score: 0

      Because actual alleged chip has ominous aura clearly visible on photo?

      This complain makes no sense, public doesn't know nor care how "real" chip looks. One chip doesn't look scarier than other, "stock photo" usage is reasonable. This is not what "investigative journalism" and "reliable sources" are about.

    3. Re:Well; thanks for clearing that up!! by infolation · · Score: 2
      Even better than the fight club disclaimer...

      I'm not disclosed to bespeak any such information to you, nor would I, even if I had said information you want, at this juncture be able.

    4. Re:Well; thanks for clearing that up!! by Anonymous Coward · · Score: 0

      The picture was of a coupler that had five pins and based on their description on what the part was supposed to do, the number of pins made sense. You could definitely mess around with eeprom with a chip that lives on a SPI bus (supply voltage, ground, SPI clock, SPI data, SPI enable, that makes 5)

  2. false by kwoff · · Score: 1

    "We don't want false information out there." - he had a mouse in his pocket?

    1. Re:false by lgw · · Score: 0

      "We don't want false information out there." - he had a mouse in his pocket?

      More like, he's in the NSA's pocket. He meant "the NSA is trying to subvert these chips to spy on all Americans. If they fail, we'll be sure to notify everyone affected so they can replace these servers. In the meantime, forget we ever mentioned it."

      --
      Socialism: a lie told by totalitarians and believed by fools.
    2. Re:false by mujadaddy · · Score: 1

      A *sting* -- hadn't considered that; nice theory fitting many facts.

      --
      Populus vult decipi, ergo decipiatur...
      "Force shits upon Reason's back." - Poor Richard's Almanac
    3. Re:false by xxxJonBoyxxx · · Score: 1

      "We couldn't recover any data from the servers."

    4. Re:false by gtall · · Score: 1

      NSA wouldn't want Ron Johnson in NSA's pocket. They know he's as stupid as he says. Once in a committee hearing on stock pricing on Wall Street he explained that he used to pay gobs to trade but can now do so for $19.99 per trade, so what's the problem. The fact that money was being skimmed due to timing issues on trades wasn't something he could understand as a law enforcement issue.

      Of course the skimming wasn't tied to Hillary or to those naughty Benghazis so he probably thought it was okay.

    5. Re:false by Megol · · Score: 0

      And you will never amount to anything. Losing. :(

    6. Re:false by Anonymous Coward · · Score: 0

      Translation because if people loook hard enough they will find where we tampered first!

    7. Re:false by Anonymous Coward · · Score: 0

      So a secure delete process leaves traces?
      So a secure delete process will go out and hit backups?

      So you have no idea what you are talking about -- priceless.

    8. Re:false by Anonymous Coward · · Score: 0

      he mean they will the chips you americans have altered \ added - moron.

    9. Re:false by Anonymous Coward · · Score: 0

      And even so, Hillary Clinton will never be president of the United States. She will never appoint a judge. She can no longer sell out the US to the highest bidder. Winning

    10. Re:false by Anonymous Coward · · Score: 0

      It was also said Trump would never be president. He has appointed judges. Has already sold out the US. Losing

  3. So what you are saying is... by Anonymous Coward · · Score: 0

    That we can neither confirm or deny whether or not we will not deny the confirmation that there could be an investigation into whether or not we should be considering, pre-emptively, confirming the denial as to whether or not we should be investigating the confirmation.

    Crystal clear.

  4. FBI is shit by Anonymous Coward · · Score: 0

    They should all be fired. They almost never answer direct questions, and when they do it turns out to be a lie later on.

    They have lied so frequently in the last couple of years, just fire the bunch of them and hire random people in place. It would be a guaranteed improvement.

    1. Re:FBI is shit by Narcocide · · Score: 1

      It would probably be an overall improvement but there would still be problems unless you could somehow find a way to filter 5th columnists from the random selection process ahead of time.

    2. Re:FBI is shit by Anonymous Coward · · Score: 0

      MAGA!

  5. 'Be Careful What You Read' by The+Original+CDR · · Score: 1, Flamebait

    I always read the White House press statements with a 5lb bag of salt.

    1. Re:'Be Careful What You Read' by Anonymous Coward · · Score: 0

      Salt production really is at an all time high since Trump won the election.

    2. Re:'Be Careful What You Read' by gtall · · Score: 1

      Nah, the trick is not read them. They are like the odor of a public restroom that no one cleans. Best to cover your eyes and not let the misinformation in.

    3. Re:'Be Careful What You Read' by Anonymous Coward · · Score: 0

      correct, who the fuck living by himself in a studio as creimer does buys 5lb of salt? We buy 2lb and it lasts us a year at least and we do our own home cooking.

    4. Re:'Be Careful What You Read' by The+Original+CDR · · Score: 1

      Nope. I'm not creimer. Now bugger off.

    5. Re:'Be Careful What You Read' by The+Original+CDR · · Score: 1

      English must not be your first language if you can't understand a joke.

    6. Re:'Be Careful What You Read' by Anonymous Coward · · Score: 0

      English must not be your first language if you can't make a joke.

      Hint: Jokes are funny. You weren't.

    7. Re:'Be Careful What You Read' by Anonymous Coward · · Score: 0

      Right, this coming from the guy who wrote "As the end user of this firehorse". Ah yes, the magnificent English fire horse!

    8. Re:'Be Careful What You Read' by The+Original+CDR · · Score: 1

      English must not be your first language if you can't make a joke.

      Hint: Jokes are funny. You weren't.

      Two other people picked up on the joke. Seriously, I expected more false outrage from Trump supporters. Your butt hurt anal fixation with creimer is pathetic.

    9. Re:'Be Careful What You Read' by Anonymous Coward · · Score: 0

      What joke, Chris? Your YouTube subscriber count? Your Slashdot psychosis?

  6. What's the big deal? by Anonymous Coward · · Score: 1

    This same guy and guys just like him (and worse) have been able to do the same thing with the legal authority of the US federal government behind them for over a decade and a half with legal immunity. Who cares what the Chinese know. The US government knows it too and they've proven they're ready to use it against you.

    You're going to get fucked if you don't fall in line with big brother. The two part illusion is only a facade to keep the most dimwitted in line. That would be the Democrat and Republican voting base.

    1. Re:What's the big deal? by Anonymous Coward · · Score: 0

      That would be the Democrat and Republican voting base.

      But not Libertarians! We're the SMART ones.

    2. Re: What's the big deal? by Anonymous Coward · · Score: 0

      Agreed, but what if the purported modifications were a kill switch? That would be an enormous deal and I doubt we would ever hear a thing about it.

      I guess I naturally distrust the government.

    3. Re:What's the big deal? by Anonymous Coward · · Score: 0

      That may or may not be true. Regardless, Libertarians just seem to be a pesky fly to the other two parties.

  7. Non-Story by mentil · · Score: 1

    Wray made a non-statement, that he's unable to make a statement. Nothing to see here, move along.
    'Be careful what you read' is ambiguous enough it doesn't necessarily imply anything one way or the other; I don't think it's supposed to be a subtle hint that we're supposed to read between the lines of. It's like the phrase "so it has come to this", it can be used in any context without adding anything of value.

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
    1. Re: Non-Story by illiac_1962 · · Score: 1

      Except for making a statement directed at the old and gullible, disparaging Bloomberg and making other weasle non-statements to downplay everything without addressing the question. Good politician.

    2. Re:Non-Story by Tablizer · · Score: 1

      They might as well say, "We can tell you, but we'd have to kill you right after."

    3. Re:Non-Story by Anonymous Coward · · Score: 0

      What do you expect from a Trumptard?

    4. Re:Non-Story by Anonymous Coward · · Score: 0

      Hmm... so I read the comment "be careful what you read"...

      Should I now discount everything he said because it was written down, or should I discount the original story as it was written down. Should I discount both? If so, then the chips are fake, but the hack is real.

      Now I'm confused...

  8. Be Careful by Anonymous Coward · · Score: 0

    Anonymous Coward on Whether Apple and Amazon Servers Had Chinese Spy Chips: 'Be Careful What You Believe Coming from the FBI'

    1. Re:Be Careful by DCFusor · · Score: 1

      "Be careful what you read" is promoting censorship. Be careful what you believe is more to the point - as well as WHO you believe.

      --
      Why guess when you can know? Measure!
    2. Re:Be Careful by Anonymous Coward · · Score: 0

      "Be careful what you read" is promoting censorship.

      No it’s not. It’s like saying be careful what you drive, and likewise, angry basement dwellers show up to protest whatever it was they were wished to be careful at. In the news later: five young men injured in hover board / motorcycle collision at a protest against safety messages. Que the slow clap.

  9. The FBI seems to be part of the problem by gweihir · · Score: 4, Funny

    At least this statement may or may not indicate that. Maybe.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    1. Re:The FBI seems to be part of the problem by Narcocide · · Score: 1

      It's clear as daylight to me that they can't clean their own house. It's not clear whether they're aware of that and trying to fix it, or aware of that and trying to cover it up, though. In either case they're failing.

    2. Re:The FBI seems to be part of the problem by HornWumpus · · Score: 0

      Peter principle corollary: The older the organization the more of it's staff will be operating at their level of incompetence.

      Sometimes the right move is just to let the old one run (in quarantine), while building a new one. Then shut down the old one and set all their employees to 'no rehire'.

      The FBI is past saving, only the political operatives/appointees are not at their level of incompetence. Only a few though, thank dog, or we'd be truly screwed.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    3. Re:The FBI seems to be part of the problem by gtall · · Score: 3, Insightful

      What the fuck are you talking about? There's no credible information the Chinese did squat with those boards the way it's been reported. They may be up to other things but that's not what is being claimed.

    4. Re:The FBI seems to be part of the problem by smooth+wombat · · Score: 1

      Peter principle corollary: The older the organization the more of it's staff will be operating at their level of incompetence.

      That explains Microsoft and Apple.

      --
      We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
    5. Re: The FBI seems to be part of the problem by illiac_1962 · · Score: 0

      Microsoft is by far one of the best tech companies around. WTF you neckbeard 50 yr old junior high student.

    6. Re: The FBI seems to be part of the problem by illiac_1962 · · Score: 1

      Credible journalist is enough for now.

    7. Re: The FBI seems to be part of the problem by TechyImmigrant · · Score: 1, Flamebait

      >Credible journalist

      A what? Never heard of such a thing.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    8. Re: The FBI seems to be part of the problem by Anonymous Coward · · Score: 0

      Credible journalist is enough for now.

      Given the credibility of most journalism these days that makes me feel a lot better.

    9. Re:The FBI seems to be part of the problem by Anonymous Coward · · Score: 0

      It's amazing how gullible Slashdot has gotten this last couple of years.

      But hey, keep your head in the sand and just place your trust in the FBI.

    10. Re: The FBI seems to be part of the problem by thegarbz · · Score: 1

      Credible journalist is enough for now.

      You're easily swayed.

    11. Re: The FBI seems to be part of the problem by Harinezumi · · Score: 1

      Credible, or credulous?

    12. Re:The FBI seems to be part of the problem by squiggleslash · · Score: 3, Insightful

      Prince Charming: You! You can't lie! So tell me puppet... where... is... Shrek?

      Pinocchio: Uh. Hmm, well, uh, I don't know where he's not

      Prince Charming: You're telling me you don't know where Shrek is?

      Pinocchio: It wouldn't be inaccurate to assume that I couldn't exactly not say that it is or isn't almost partially incorrect.

      Prince Charming: So you do know where he is!

      Pinocchio: On the contrary. I'm possibly more or less not definitely rejecting the idea that in no way with any amount of uncertainty that I undeniably

      Prince Charming: Stop it!

      Pinocchio: ...do or do not know where he shouldn't probably be, if that indeed wasn't where he isn't. Even if he wasn't at where I knew he was

      [Pigs and Gingerbread Man begin singing]

      --
      You are not alone. This is not normal. None of this is normal.
    13. Re: The FBI seems to be part of the problem by TigerPlish · · Score: 2

      Microsoft is by far one of the best tech companies around. WTF you neckbeard 50 yr old junior high student.

      Pfft. Microsoft. Best? Totally dysfunctional. No QA. Bug city. Updates to Windows that break shit and delete shit. At random. One machine fine, the next a pile of ashes.

      Dream on. The older the company the more cruft sets in. One day you'll find that out too.

      --
      The "Civilized World" jumped the shark ca. 1973.
    14. Re:The FBI seems to be part of the problem by Narcocide · · Score: 1

      It may be the first you've heard about it but it is not the first time mistrust about specific ports on SuperMicro server boards has been expressed to me by mutual customers. And, at the time, no mention was made of the Chineese or any specific attacker, but my response was otherwise very similar to yours. Derision, disdain, arrogant contempt. Stupid naivety.

    15. Re:The FBI seems to be part of the problem by Anonymous Coward · · Score: 0

      Not a denial of course just a motherhood comment.

    16. Re:The FBI seems to be part of the problem by Anonymous Coward · · Score: 0

      Looks like these old fools on Slashdot really don't know what's up anymore.

    17. Re:The FBI seems to be part of the problem by Anonymous Coward · · Score: 0

      It's amazing how Slashdot's become inundated with trolls trying to make us believe that everything sucks, nothing is to be believed in, and we shouldn't even bother getting out of bed in the mornings.

      Fuck you, and fuck your Big Daddy Vladdy, too, motherfucker.

    18. Re: The FBI seems to be part of the problem by Anonymous Coward · · Score: 0

      Credible journalist is enough for now.

      You're easily swayed.

      The story is plausible enough to warant further investigation. No more, no less. Exactly where on the motherboards would this spy chip be located? Can people who own these motherboards verify that it's there? What network traffic do these chips generate, and how can you activate them? If it's true I expect confirmations and details in the coming weeks.

  10. Can't confirm or deny an investigation by Anonymous Coward · · Score: 0

    But they could confirm or deny the chips exist. Show us the chips!

    1. Re:Can't confirm or deny an investigation by PPH · · Score: 4, Funny

      The Chinese chips are right next to the NSA chips, which are immediately below the Russian vacuum tubes.

      --
      Have gnu, will travel.
    2. Re: Can't confirm or deny an investigation by Anonymous Coward · · Score: 0

      I seriously doubt there are any vacume tubes. Voltage is too high to work well with other IC'S, but the microphones they use to dangle out of the vents to listen to the chips may still be there...

    3. Re: Can't confirm or deny an investigation by PPH · · Score: 1
      --
      Have gnu, will travel.
  11. Pay no attention! by PopeRatzo · · Score: 0

    Dolt 45 said it best:

    "What you are seeing and what you are reading is not what's happening"

    https://www.bbc.com/news/av/wo...

    https://www.newsday.com/long-i...

    --
    You are welcome on my lawn.
    1. Re:Pay no attention! by Anonymous Coward · · Score: 0, Interesting

      Dolt 45 said it best:

      "What you are seeing and what you are reading is not what's happening"

      https://www.bbc.com/news/av/wo...

      https://www.newsday.com/long-i...

      The press told you Hillary was going to win. The press told you that Mitt Romney was a buffoon for thinking Russia was still a credible threat.

      Tump said, "Wrong."

      Was he wrong PopeRatzo? Are you in a bad dream or was "Dolt 45" telling the truth you refused to believe?

  12. "These are not the chips you are looking for!" by gweihir · · Score: 3, Insightful

    At least it does sound like that to me. Maybe everything we read is correct, except that the attack actually was done by the NSA?

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    1. Re:"These are not the chips you are looking for!" by evanh · · Score: 1

      I've been thinking the same thing. Maybe Bloomberg has been misdirected about who is doing the spying.

    2. Re:"These are not the chips you are looking for!" by gweihir · · Score: 1

      Would explain some things...

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    3. Re:"These are not the chips you are looking for!" by Anonymous Coward · · Score: 0

      How much are you getting paid for this propaganda?

    4. Re:"These are not the chips you are looking for!" by drinkypoo · · Score: 1

      Maybe everything we read is correct, except that the attack actually was done by the NSA?

      Maybe an agreement was made between multiple nations' intelligence agencies to make these systems vulnerable in general, for all their benefit?

      In any case, show me the components.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    5. Re:"These are not the chips you are looking for!" by gweihir · · Score: 1

      In any case, show me the components.

      Indeed. And with an independent analysis on top, please.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  13. Re:Did he also say they don't mass collect data? by Narcocide · · Score: 1

    Using the term "brain faggots" doesn't really help your argument any.

  14. I'll read any gods-be-damned thing I want, asshole by Rick+Schumann · · Score: 3, Insightful

    Don't tell me or anyone else what we should and should not read.
    Now, that being said, if you want to tell people to think carefully about the validity of what they read, then that's something else entirely.

  15. Be careful what you believe by Anonymous Coward · · Score: 0

    Read whatever you want

  16. Our Most Likely Options by painandgreed · · Score: 5, Insightful

    What could be going on?

    1) Everything is exactly as Bloomberg states and the Chinese have performed a supply line hack on American industry. - The strong denials from all public sources that might confirm this, including to the public and stockholders, would seem to indicates that a serious investigation is going on and the government is ordering everybody to deny hard if not out lie to preserve it. However, why keep it secret it the cat's out of the bag? China, and anybody involved, would already know and be taking steps to cover their tracks. Seems the proper response by law enforcement to break the news and step up public investigation ASAP.

    2) Bloomberg's editors and writers are just misinterpreting whatever happened to Apple that they say was a compromised driver caught in the lab coming from a variety of sources who don't really have that good of info. - Bad stain on Bloomberg's reputation and failure of their editors to preserve the brand. Will no doubt hurt their operation when things come to light as their business is acting as a reliable source of business news.

    3) The authors of the article are fabricating the article either from a collection of unrelated sources, or whole of cloth and selling it to Bloomberg, perhaps not expecting the attention it's getting. - A worse stain on Bloomberg as their editors still fell for it, but pretty much ruin for the author's careers as journalists in the future.

    4) Bloomberg and the authors are in cahoots to create a fictitious story that can't be confirmed or denied in order to manipulate the markets, push international policy, and/or create fear of China. - This might actually spell doom for Bloomberg, or might not. There are plenty of "news sources" that could get away with such things and nobody would even blink if it was proved to be true. Perhaps Bloomberg thinks they can get sales and get away with it at the same time. I'm sure some people have played harder and faster with more on the line and the end result would depend on how trustworthy the public actually takes Bloomberg to be to begin with. It would also probably be straying into legal territory it it turned out toe be manufactured, cause the people involved to lose their jobs, and maybe do jail time.

    4)Somebody has manufactured the story and fed it to Bloomberg's authors in order to manipulate the markets, push international policy, create fear of China, hurt Bloomberg's reputation, or any combination of these. - Now we're practically back into spook territory. There are certainly people who would like to do any number of things, but to have the scale to do beyond simply option #2 would take resources and also probably venture into legal territory for acting against Bloomberg, the companies involved, China, etc.

    1. Re:Our Most Likely Options by Anonymous Coward · · Score: 0

      Well, in fairness, Bloomberg is a 0.01%er who makes tons of money while pushing public policy from his wallet. I think what's going on stinks like shit but follow the money, Bloomberg is an enemy of the common man.

    2. Re:Our Most Likely Options by Anonymous Coward · · Score: 1

      How about option 1.1 (quite similar to your #1): The Chinese have done what Bloomberg claims they have done. But the FBI's (or some other 3-let federal agency) done the same, so exposing the China hack could mean exposing the hacks the US have already done or are continuing to do against China or other other countries, including presumably US allies.

    3. Re:Our Most Likely Options by Junta · · Score: 1

      I think it's some weird blend of 2 and 3. Note:
      https://9to5mac.com/2018/10/09...

      One of the sources gave a view of what it was like to be a source for the story. The writers came with some vague 'maybes' that probably had accumulated over several previous hypotheticals and then published as absolute fact, rather than 'this is how this could go down', then doubling down on the story when it's controversial.

      I don't know if they had any maliciousness or were just caught up in thinking they were unwinding people being evasive about some secret and overplayed what their sources were giving them, but that seems to be the answer that makes the most sense, since this magical no-more-than-six-pin chip is hard to imagine how it could do what is claimed.

      The follow up about an instrumented network port at least sounds credible as the technology to pull that off is a bit more plain, but there we have a single source, no evidence, and non-trivial chances that he didn't understand some legitimate part of the equipment or is trying to take advantage of the situation to get himself into the press.

      Basically, if Supermicro is in the clear, they need to pursue a defamation suit and then perhaps we can stop having to engage in hypothetical debate over hypothetical things and actually evaluate the available evidence.

      --
      XML is like violence. If it doesn't solve the problem, use more.
    4. Re:Our Most Likely Options by Falos · · Score: 1

      You suggest many possible factors at many tiers. A nice visual aid, that the Real Truth is not likely to be "It's exactly as they said" / "Every word is a total fabrication"

      Even though simple minds only want to think binary. Good. Bad. Us. Them. True. False.

    5. Re:Our Most Likely Options by jittles · · Score: 1

      2) Bloomberg's editors and writers are just misinterpreting whatever happened to Apple that they say was a compromised driver caught in the lab coming from a variety of sources who don't really have that good of info

      Why did Apple drop them as a supplier in that case? Did Apple go directly to the ODM and use open compute designs? I am not sure. But I don't think that it is normal to drop a supplier for a reason like an infected driver.

    6. Re:Our Most Likely Options by Anonymous Coward · · Score: 0

      5) A Mossad kike fabricated the entire thing to further strain ties with China.

    7. Re:Our Most Likely Options by Anonymous Coward · · Score: 0

      I like this option. Fits with 'Never ascribe malice when incompetence is an adequate explanation'

  17. Re:I'll read any gods-be-damned thing I want, assh by Anonymous Coward · · Score: 0

    Well said.

  18. No secrets among the community by rickb928 · · Score: 1

    We can be sure that Chinese, if they did indeed sponsor implanting chips as described, already know if we know.

    And we can be certain that the truth of this has been known for a while, by the agencies interested, globally. And for a while, possibly months. Keeping the knowledge quiet is important to fully understanding the problem, since the target servers would likely be reconfigured to obscure their true purposes, then quietly killed. And the data being sent would need to be evaluated with live examples to understand the capabilities and guess at the intentions.

    Of course this could all be an elaborate ruse, to either prevent an effort - describing the possible exploit methods, and so rendering them fairly useless, or at least being able to put the opposition on notice that 'we are watching'. But I doubt this.

    This news is most likely an unexpected and unwanted disclosure. We should have heard about this through indictments, plentiful evidence, and the already-launched mitigation, most likely black holing the destinations and then writing specific rules to block the outbound traffic. That's done a lot for lesser threats, Cisco in particular would be working on that, and core transport would be involved. At least everywhere but the perpetrator states.

    So this is known to be true or not, and I expect the authorities to delay confirming this for a variety of reasons, some not mentioned above. Certainly to get as much information as possible about the sponsors.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  19. HA HA HA by Anonymous Coward · · Score: 0

    When you thought shit couldn't get more funny.

  20. We know, and the Chinese know we know by Anonymous Coward · · Score: 0

    The rest of the monkey dance is to not upset the business community or the populous under the usual government assumption that it's OK to lie to the voters.

    1. Re:We know, and the Chinese know we know by Anonymous Coward · · Score: 0

      That's "populace", friend. "Populous" is an adjective meaning, "having lots of people".

      BTW, thanks to that error, I'm now pretty sure I know who you are.

  21. Re:I'll read any gods-be-damned thing I want, assh by Anonymous Coward · · Score: 0

    Don't tell me or anyone else what we should and should not read.

    Now, that being said, if you want to tell people to think carefully about the validity of what they read, then that's something else entirely.

    Be careful what you read, child.

  22. I'm not saying he's wrong by rsilvergun · · Score: 1

    to say we shouldn't be attentive of our sources, but "Be careful what you read" isn't a good way to say it. What he should have said was "Be critical of what you read".

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:I'm not saying he's wrong by gweihir · · Score: 1

      I think he meant exactly "be careful what you read" with an implied "we may come after you if you read heretical texts". It is how a totalitarian state works, after all.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  23. Where is the SEC when you need them? by Anonymous Coward · · Score: 0

    It's clear that the various articles published by Bloomberg have had an impact on the share price of Supermicro and other listed companies.

    If Bloomberg has actual evidence to back their claims, they should be required to produce it. If not, this has to be grounds for an investigation by the SEC. If you consider the response to Elon Musk's stupid comments on Twitter this has to be worse.

    1. Re:Where is the SEC when you need them? by DCFusor · · Score: 1

      The SEC is busy with Elon Musk, which already takes too much time away from their midget porn fetish.

      --
      Why guess when you can know? Measure!
  24. Re:I'll read any gods-be-damned thing I want, assh by gweihir · · Score: 1

    I am pretty sure he meant the former, not the latter.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  25. Re:I'll read any gods-be-damned thing I want, assh by Anonymous Coward · · Score: 0

    Don't tell me or anyone else what we should and should not read.

    Now, that being said, if you want to tell people to think carefully about the validity of what they read, then that's something else entirely.

    #incel

  26. Re:I'll read any gods-be-damned thing I want, assh by mentil · · Score: 1

    A government rep promoting critical thinking and independent thought? He'd be disappeared to a black site faster than a Saudi journalist.

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
  27. So is there a smoking gun? by Anonymous Coward · · Score: 0

    Has anyone pried open a metal Ethernet connector shell and pulled out a mystery chip that has no business being there?

    1. Re: So is there a smoking gun? by Anonymous Coward · · Score: 0

      I did just that today with a spare Supermicro server board we have. All I found inside were inductor cores. Nothing nefarious about that. Appleboum is an idiot.

  28. Re:I'll read any gods-be-damned thing I want, assh by Rick+Schumann · · Score: 1

    I chuckle at this, but sardonically.

  29. Re:I'll read any gods-be-damned thing I want, assh by Rick+Schumann · · Score: 0

    Fuck the police, I do what I want. xD

  30. Just BECAUSE they're already doing it. by Ungrounded+Lightning · · Score: 3, Insightful

    This same guy and [others in the US "intelligence community"] have been able to do the same thing w... for over a decade and a half

    Quite. They can, and do, do everything this alleged hardware hack is alleged to enable, and more. Since Snowden that's solidly on the public record, manuals and all. Since the Shadow Brokers, lots of others have been able to do some of it and/or see how it works.

    Seems to me they are trying to tone down the outrage - because if it really gets going, it might (finally) be turned on them.

    What's the big deal if the Chinese came up with the capability, but had to put a chip on the boards to make it happen, rather than get Intel and AMD build it into their own chip sets?

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  31. False flag maybe? by Anonymous Coward · · Score: 0

    Maybe it's actually the US who infiltrated the Chinese manufacturing. Who get to get the intel if they don't get found out, and can blame the Chinese if they do. Win win!

  32. Chinese hax by Anonymous Coward · · Score: 0

    I get the feeling these servers were compromised on behalf of one of our tla's, not the Chinese govt.

  33. Breadcrumbs by GrBear · · Score: 4, Insightful

    I don't know if these "magic" chips are installed or not.. buuut..

    If they were, you'd think that someone would have noticed the extra traffic on their network going through, or trying to get through, their firewalls. Unless these chips are packed with every known vulnerability of bypassing corporate firewalls, they would leave a very suspicious trail of evidence to their use.

    1. Re:Breadcrumbs by Anonymous Coward · · Score: 0

      Considering the amount of routers made in China and possibly knowing precisely what routers are being used at different places, it's not unthinkable they preemptively backdoored the routers in a way that would silently hide any special knocked messages and allow bypassing any firewall rules. There's also the issue that a ton of Cisco routers have been shown to have hardcoded default passwords, so again they'd just need to know ahead of time what routers are being used.

      That's the real problem with the whole situation. There's literally streams of vulnerabilities announced on a near daily basis, and a lot aren't patched because "critical services" can't be rebooted or there's simply not enough effort put into plugging every possible hole over the whole infrastructure of an organization. This doesn't even get into the spooky steganography stuff that could be pulled by embedding information in reencoded images--so literally going to the front page of every major website with the right program/password could potentially give you all the passwords you need to enter.

      I wouldn't put it past a State actor, be in China or Israel--they've shown themselves quite capable--, to do as much or more. Having said that, it does seem like a bit of incompetence if true because they were caught. *shrug*

    2. Re:Breadcrumbs by Anonymous Coward · · Score: 2, Informative

      If they were, you'd think that someone would have noticed the extra traffic on their network going through, or trying to get through, their firewalls.

      Having attended the DEFCON and Blackhat conferences, I'm not so sure I agree with you. The level of publicly known ways to disguise malicious traffic to look like innocent traffic is quite scary.

    3. Re:Breadcrumbs by DCFusor · · Score: 3, Insightful

      Some assets are meant to be hidden until use. Instant gratification often gets you less than waiting for the best setup.

      --
      Why guess when you can know? Measure!
    4. Re:Breadcrumbs by strikethree · · Score: 1

      IIRC, that is exactly how they were discovered; through anomalous traffic.

      This whole thing screams that there is a Top Secret investigation going on and that someone who knew about the compromise but not about the investigation revealed to Bloomberg.

      I kind of don't care about any of this. I assume all hardware is compromised, it is merely a question of who compromised it this time. Nobody respects the rights of the average person.

      --
      "Someone needs to talk to the tree of liberty about its ghoulish drinking problem." by ohnocitizen
  34. Agreed by ArchieBunker · · Score: 1, Interesting

    They were warned of the school shooter in Florida before it happened and did nothing. They were told exactly who it was and what he was planning. A two minute follow up call to the school to ask if this kid was a threat or not was all it would have taken. The running joke at the school was he was going to shoot the place up. One teacher specifically asked that he be notified if the student ever showed up with a backpack.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
  35. PRISM talk? by AHuxley · · Score: 2

    Its the decades of before PRISM talk?

    Did the intelligence community find a way back to China?
    Sending back altered data?
    Did the USA have spies in China that warned the USA and the US just watched on to protect its spies?
    Did one part of the US gov use methods for decryption and does not want methods talked about?

    --
    Domestic spying is now "Benign Information Gathering"
  36. Re:I'll read any gods-be-damned thing I want, assh by Anonymous Coward · · Score: 0

    if you want to tell people to think carefully about the validity of what they read, then that's something else entirely.

    That's literally exactly what he said. Your TDS is causing hallucinations again.

    If you're worried about people controlling what you're *allowed* to read, please find the latest Google thread.

  37. If compromised motherboards exist, so should pics by Reeses · · Score: 3, Insightful

    The part that got me about the article was that there were no pictures of actual compromised motherboards.

    Supposedly they were sold by the thousand, and the IT crews pulled them all out and replaced them. No one thought to keep one?

    Or there isn't one still lying on some shelf somewhere?

    --
    Reeses
  38. Re:If compromised motherboards exist, so should pi by Spamalope · · Score: 1

    When you can sell them all on Ebay? :p

  39. What are they about then? by Anonymous Coward · · Score: 1

    This is not what "investigative journalism" and "reliable sources" are about.

    Pray tell, what are those things about then? Because I certainly see no investigative anything, journalistic anything, reliable anything, or sources anything in this whole rigmarole.

    You might as well say "chinese replace russians as big bad boojum, with hardware instead of network messages" and and you would have the gist of the thing nailed.

    Which doesn't mean our computers are safe. They're not, and we do know this whether we admit it or not.

  40. Nothingburger by Anonymous Coward · · Score: 0

    Translation: No Comment (TM).

  41. Probably this: by Sqreater · · Score: 1

    Our intelligence organs have hacked the hackers and are using it against them. Blanket denial would support this.

    --
    E Proelio Veritas.