Slashdot Mirror


The Messy Truth About Infiltrating Computer Supply Chains (theintercept.com)

In October last year, Bloomberg Businessweek published an alarming story: Operatives working for China's People's Liberation Army had secretly implanted microchips into motherboards made in China and sold by U.S.-based Supermicro. While Bloomberg's story -- which has been challenged by numerous players -- may well be completely (or partly) wrong, the danger of China compromising hardware supply chains is very real, judging from classified intelligence documents, reports The Intercept. From the report: U.S. spy agencies were warned about the threat in stark terms nearly a decade ago and even assessed that China was adept at corrupting the software bundled closest to a computer's hardware at the factory, threatening some of the U.S. government's most sensitive machines, according to documents provided by National Security Agency whistleblower Edward Snowden. The documents also detail how the U.S. and its allies have themselves systematically targeted and subverted tech supply chains, with the NSA conducting its own such operations, including in China, in partnership with the CIA and other intelligence agencies. The documents also disclose supply chain operations by German and French intelligence.

What's clear is that supply chain attacks are a well-established, if underappreciated, method of surveillance -- and much work remains to be done to secure computing devices from this type of compromise. "An increasing number of actors are seeking the capability to target ... supply chains and other components of the U.S. information infrastructure," the intelligence community stated in a secret 2009 report. "Intelligence reporting provides only limited information on efforts to compromise supply chains, in large part because we do not have the access or technology in place necessary for reliable detection of such operations."

3 of 69 comments (clear)

  1. Re:Many parties are "guilty" here... by Anne+Thwacks · · Score: 4, Insightful
    As a non-USian, I believe that the anti-China stories are mostly there because the NSA finds it harder to put its own Trojans in Chinese computers

    Think about it: if every computer on the planet is streaming private material to China, what the hell would China do with all that data? And why would I care? its not like the Chinese are going to send me for re-education. OTOH, we can see what happens when the NSA comes after you.

    --
    Sent from my ASR33 using ASCII
  2. Re:Well, whom does it serve? by Narcocide · · Score: 5, Interesting

    Maybe you didn't consider the possibility that from China's standpoint, the US started it, and the only reason the US citizens aren't outraged about this is because they've been outright lied to by their own intelligence agencies gone rogue.

  3. Intel Management Engine by Nocturrne · · Score: 4, Interesting

    Closed firmware... How is there not a class action lawsuit against Intel for this?