Slashdot Mirror


The Messy Truth About Infiltrating Computer Supply Chains (theintercept.com)

In October last year, Bloomberg Businessweek published an alarming story: Operatives working for China's People's Liberation Army had secretly implanted microchips into motherboards made in China and sold by U.S.-based Supermicro. While Bloomberg's story -- which has been challenged by numerous players -- may well be completely (or partly) wrong, the danger of China compromising hardware supply chains is very real, judging from classified intelligence documents, reports The Intercept. From the report: U.S. spy agencies were warned about the threat in stark terms nearly a decade ago and even assessed that China was adept at corrupting the software bundled closest to a computer's hardware at the factory, threatening some of the U.S. government's most sensitive machines, according to documents provided by National Security Agency whistleblower Edward Snowden. The documents also detail how the U.S. and its allies have themselves systematically targeted and subverted tech supply chains, with the NSA conducting its own such operations, including in China, in partnership with the CIA and other intelligence agencies. The documents also disclose supply chain operations by German and French intelligence.

What's clear is that supply chain attacks are a well-established, if underappreciated, method of surveillance -- and much work remains to be done to secure computing devices from this type of compromise. "An increasing number of actors are seeking the capability to target ... supply chains and other components of the U.S. information infrastructure," the intelligence community stated in a secret 2009 report. "Intelligence reporting provides only limited information on efforts to compromise supply chains, in large part because we do not have the access or technology in place necessary for reliable detection of such operations."

29 of 69 comments (clear)

  1. Of course they do this. by Anonymous Coward · · Score: 2, Informative

    The NSA admits doing exactly this to target high-value individuals. Order a computer, they intercept the package, in a few hours it's opened and modified and packed back up with OEM stickers like new. You would never know.

    China is just much more broad and bold with their attempts to catch up using 3rd party companies that are actually 1st party ChiCom Party owned entities.

    Supermicro may or may not have been a real story - however, if it WAS REAL, the NSA and SECINT have no obligation to inform the public of that, only to mitigate it as they mitigate dozens of things we know nothing of.

    The problem isn't that there's no evidence, the problem is that we have no legal authority to demand evidence if it exists to know either way. Journalism has to catch them red-handed by itself for us to find things out.

    Hence Edward Snowden's revelations.

  2. Tariffs by Thelasko · · Score: 1

    This might actually be a legitimate case for a national security tariff.

    --
    One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
  3. Many parties are "guilty" here... by bogaboga · · Score: 1

    While Bloomberg's story -- which has been challenged by numerous players -- may well be completely (or partly) wrong, the danger of China compromising hardware supply chains is very real, judging from classified intelligence documents, reports The Intercept.

      While Bloomberg's story -- which has been challenged by numerous players -- may well be completely (or partly) wrong, which contributes to fake news, the danger of China compromising hardware supply chains is very real, judging from classified intelligence documents, reports The Intercept.

    (...bold mine...)

    The result of any compromising is the same as what the CIA/NSA have done to foreign entities, if I may add.

    1. Re:Many parties are "guilty" here... by Anne+Thwacks · · Score: 4, Insightful
      As a non-USian, I believe that the anti-China stories are mostly there because the NSA finds it harder to put its own Trojans in Chinese computers

      Think about it: if every computer on the planet is streaming private material to China, what the hell would China do with all that data? And why would I care? its not like the Chinese are going to send me for re-education. OTOH, we can see what happens when the NSA comes after you.

      --
      Sent from my ASR33 using ASCII
    2. Re:Many parties are "guilty" here... by PolygamousRanchKid+ · · Score: 1

      The result of any compromising is the same as what the CIA/NSA have done to foreign entities, if I may add.

      The result of any compromising is the same as what the CIA/NSA have done to domestic entities, if I may add.

      --
      Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
    3. Re:Many parties are "guilty" here... by mcswell · · Score: 1

      Ever hear of encryption?

  4. Yet another reason to diversify your supply chain by Marxist+Hacker+42 · · Score: 2

    Want to protect your supply chain from tariffs, spying, and other political crap? Diversify! Make components in as many countries as possible, and when one is compromised, shut it down and make it someplace else.

    --
    SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
  5. Anyone else find it creepy by rsilvergun · · Score: 2

    that China still calls their military the "China's People's Liberation Army". The people were "Liberated" a long time ago. It's just the army now.

    I don't think it matters that we've handed so much manufacturing over to the Chinese. The folks running the show, what we usually call the Ruling Class, are global now. They might have the occasional spat here and there over who's yacht's bigger or who's the richest this week but they're not really fighting (and by extension the countries they run aren't fighting).

    I suppose it's a good thing. A World War isn't the solution (though it's one way to kick your economy up a notch). But anything we're seeing here is at best a pissing match between billionaires.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:Anyone else find it creepy by AHuxley · · Score: 1

      South Korea, Vietnam, Tibet, Tiananmen Square all got lots of Communist liberation.
      Now its computer networks that will have to collect it all for a Communist government.

      --
      Domestic spying is now "Benign Information Gathering"
    2. Re:Anyone else find it creepy by AHuxley · · Score: 1

      Taiwan is still free AC. Re you "Communist in name only"? Ask the people from Tibet, Vietnam and Korea about that.

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:Anyone else find it creepy by mcswell · · Score: 1

      Not to mention the Uighurs, whose plight has gotten some attention recently from the BBC, among others.

    4. Re:Anyone else find it creepy by mcswell · · Score: 1

      Guess you totally missed AHuxley's point...

    5. Re: Anyone else find it creepy by Anonymous Coward · · Score: 1

      I find it creepy thar Americans called the destruction of Iraq "Operation Iraqi freedom" ...

  6. Re:Well, whom does it serve? by Anonymous Coward · · Score: 2, Insightful

    How does it "generate hate" to point out that China attacks the US constantly online and seeks to overthrow our superpower status technologically through subterfuge because they have a less capable military currently?

    Maybe you just don't understand hegemony? It's always going to be there until we have either world governance (UN is toothless by design..) or one power cements itself as the only power.

    Pretending China is an equal-opposite analogue of the US is where these analogies fail. They are not a country of actual laws. They are actually a cabal.

    Yes, the US is served by defending itself from China, and vice versa. To jump to an omni-beneficial relationship would require serious restructuring that won't happen without bloodshed in either case.

    So, detente instead. Pretending it's unwarranted or immoral is to not understand the point of it.

  7. intel management engine ? by Anonymous Coward · · Score: 1

    'nuff said

  8. Re:Well, whom does it serve? by Narcocide · · Score: 5, Interesting

    Maybe you didn't consider the possibility that from China's standpoint, the US started it, and the only reason the US citizens aren't outraged about this is because they've been outright lied to by their own intelligence agencies gone rogue.

  9. Cute propaganda piece by Anonymous Coward · · Score: 1

    Cute propaganda piece that builds upon the shaky claims of the original bloomberg story.

    1. Re: Cute propaganda piece by Anonymous Coward · · Score: 1

      Slashdot has been a constantly dripping spigot of US state propaganda for years now. This article seems like a patch over the last non-story about Chinese chip-trojaning injected into media which turned to to be pure bullshit.

  10. Greed by ickleberry · · Score: 2

    Greedy suit-wearing McMansion-dwelling fat-bellied US bosses couldn't resist the temptation of outsourcing to China for cheap and now the rest of us have to pay for it.

  11. Truth following Fiction? by McFortner · · Score: 3, Funny

    This makes me think of the backstory to The War Against the Chtorr series by David Gerrold. After losing several devastating conflicts, the US is forced into giving up it's military might and provide reparations to other countries. Instead of money, it provides food and high tech goods, such as computers and electronics, making the world dependent on US technology. All of the ICs have Trojan Horses hardwired into them that are undetected, which can were used as kill switches. That comes in real handy when some of those countries decide to invade the US in order to "liberate" resources that they want.

    Could something like this be used by China to cripple enemy economic and military might in a future conflict? We'd be fools not to consider this a very realistic possibility.

    --
    Beware of Sales Reps bearing gifts.
  12. The pot calling the kettle black by Anonymous Coward · · Score: 1

    The complete hypocrisy here is insane; the NSA is known to intercept supply chain of many countries, including US. On the other hand, the MSMs always have no issue with publishing articles with little to new evidences (or wrong as in the case of Bloomberg) to outright fabricating stories. And from some of the response here on / . at least a good portion of likely Americans are equally as ignorant and/or prejudiced.

  13. Wait - Wut? Vendors don't check their products? by Anonymous Coward · · Score: 1

    I worked in a company that created its own boards which were outsourced offshore. Every batch received in the plant where the devices were delivered had random inspections for quality. The company designed the boards and the offshore fabricators created the boards, populated them with chips (which contained company designed special purpose devices) and sent them to the plant. These custom boards were tested for QA and Government certification standards.

    So the article suggests that SuperMicro did not, does not, could not do a simple chip count on a random sample to see if anything was "added" to their motherboards? Really?
    So the Chinese are so f*u*king smart that they can alter the fundamental design of a mother board adding parts, signal paths, power consumption, etc. to a board designed in a foreign country and the original designer can not tell that the fundamental design has changed. Really?
    Oh, add into this fallacy that the mother board functions perfectly to the eyes of its designers and its customers. And the boards are contacting the Chinese from data centers outside of the Chinese mainland, but the data centers can not detect these signals leaving their facility and targeting "some collection point" in China. Really?

    1. Re:Wait - Wut? Vendors don't check their products? by AHuxley · · Score: 1

      Imagine if the NSA and GCHQ had production line over the decades AC ;)

      --
      Domestic spying is now "Benign Information Gathering"
  14. Intel Management Engine by Nocturrne · · Score: 4, Interesting

    Closed firmware... How is there not a class action lawsuit against Intel for this?

  15. Re:And keep the *local* trojan threat! by mcswell · · Score: 1

    Just the opposite.

  16. You're all fascists. by Anonymous Coward · · Score: 1

    All foreign IC is suspect. And we can't trust imported food. And definitely not their unsafe cars...

    In growth, the industry wants free trade. In a recession, they want protectionism. The form of government in which they have their way all the time is not democracy. It's fascism. And not one person living in an English speaking country and reading this post right now was born to a democratic regime.

  17. Iran knows not to buy from us by OrangeTide · · Score: 2

    Iran knows not to buy industrial controls from the U.S. (Stuxnet). And the U.S. should know not to buy computers and phones from China.

    --
    “Common sense is not so common.” — Voltaire
  18. Re:Yet another reason to diversify your supply cha by Marxist+Hacker+42 · · Score: 1

    Yes, in fact it is. Or to put it another way, don't keep your investment eggs all in one basket less the nuclear hammer smash them.

    --
    SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
  19. Re:To diversify, we need open platforms by Marxist+Hacker+42 · · Score: 1

    Even though I now work for a large chip manufacturer, I have a tendency to agree. That chip manufacturer missed it's earnings target by $1.8 billion due to the trade war with China and a disruption of a supply chain, a disruption that would simply not have happened with a diversified supply chain.

    --
    SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.