Super Micro reviewing its hardware in search for alleged Chinese spy chips

Posted:
in General Discussion
Super Micro will be reviewing its products for any signs of chips or other malicious hardware added during its production, in a bid to clear itself following a report claiming Chinese spies had implanted the components to perform espionage on Apple and other western companies.




"Despite the lack of proof that a malicious hardware chip exists, we are undertaking a complicated and time-consuming review to further address the article," Super Micro advised to its customers in a letter. Included as part of a U.S. Securities and Exchange Commission filing, the letter claims "We are confident that a recent article, alleging a malicious hardware chip was implanted during the manufacturing process of our motherboards, is wrong."

"We trust you appreciate the difficulty of proving that something did not happen, even though the reporters have produced no affected motherboard or any such malicious hardware chip," asserts Super Micro. "As we have said firmly, no one has shown us a mtherboard containing any unauthorized hardware chip, we are not aware of any such unauthorized chip, and no government agency has alerted us to the existence of any unauthorized chip."

It is claimed to be "virtually impossible" for a third-party to install such a component capable of communicating with a baseboard management controller during the manufacturing process, as they would lack the "pin-to-pin knowledge" of the design. Super Micro also notes the system is designed "so that no single Super Micro employee, single team, or contractor has unrestricted access to the complete motherboard design," including hardware, software, and firmware.

On October 4, a Bloomberg report based on a multi-year investigation claimed that Apple, Amazon, and 30 other companies had been the victim of an espionage campaign in which rice-sized chips had been planted on motherboards made by Super Micro. Once delivered, the motherboards supposedly created a backdoor into infrastructure like Apple's iCloud.

Apple was quick to deny allegations, insisting that it had conducted a "massive, granular, and siloed investigation."

Amazon's denial of the attack was a bit more outspoken.

"There are so many inaccuracies in this article as it relates to Amazon that they're hard to count," Amazon said in its statement, refuting several specific claims, and specifically citing that there was no modified hardware found.

Several subsequent accounts have cast further doubt, such as one from the senior advisor for Cybersecurity Strategy to the director of the U.S. National Security Agency. Additionally, The U.S. Department of Homeland Security commented that it had "no reason to doubt" the positions of Apple and Amazon.

On Friday, Tim Cook also spoke candidly about the attack, putting his own name on very specific denials, and also talking about how Bloomberg interacted with Apple during the investigation.

"There is no truth in their story about Apple," Cook said on Friday. "They need to do that right thing and retract it."

"I was involved in our response to this story from the beginning," said Cook. "I personally talked to the Bloomberg reporters along with Bruce Sewell who was then our general counsel. We were very clear with them that this did not happen, and answered all their questions. Each time they brought this up to us, the story changed and each time we investigated we found nothing."

"We turned the company upside down. Email searches, datacenter records, financial records, shipment records," Cook added. "We really forensically whipped through the company to dig very deep and each time we came back to the same conclusion: This did not happen. There's no truth to this."

Bloomberg hasn't backed down from its claims, and U.S. senators have asked Super Micro for answers.

Comments

  • Reply 1 of 14
    Rayz2016Rayz2016 Posts: 6,957member
    And still Bloomberg stays silent.

    With their credibility on the line, surely now is the time to produce the evidence. National security is at stake here. Just holding back the evidence like this is criminal. 
    jbdragonhubbaxradarthekatchasmwatto_cobrajony0
  • Reply 2 of 14
    So the case wasn't so clearcut after all? 
    With the stark denials, this should have been up and settled already, yeah?
    radarthekatwatto_cobra
  • Reply 3 of 14
    felix01felix01 Posts: 294member
    At one time, Bloomberg was a respected media outlet. Now I’m viewing them as a rag.
    radarthekatchasmwatto_cobrajony0
  • Reply 4 of 14
    maestro64maestro64 Posts: 5,043member
    SM does nots not have find the part on any boards, all there need to do is go get the CAD and Gerber files for the PCB manufacturer that were used to build their products during the so call time period and do a hash compare on the files in their own archives and if the hash do not match then they know files were modified. There is no way to put a ship on a board without modifying the PCB drawing and file. If they tried adding the part after the fact that means there would be wires and such which any one would have easily know.
    watto_cobra
  • Reply 5 of 14
    maestro64maestro64 Posts: 5,043member

    Bloomberg hasn't backed down from its claims, and U.S. senators have asked Super Micro for answers.
    The bigger question is will the Senate also require the same of Bloomberg once SM establish it never happen. Bloomberg should be held responsible for the stock well issue that SM is dealing as well as the fact they may be loosing business if Companies think SM was hack in some regards and their systems can not be trusted. Until A media companies is held financial responsible for their actions we will not see a change in how things are reports. Look what was done to Elon for basically saying he wants to take him company private. He believed he wanted to do this, but could not back it up with money and they fined his ass and the stock in in the hole ever since.

    chasmchristophbjony0
  • Reply 6 of 14
    SoliSoli Posts: 10,035member
    Journalists can and will make mistakes. Sources can lie and people can be duped, especially when it's backed by a foreign agency disseminating a false narrative. We accept this and (for everyone that is rational) we accept this will occur from time-to-time. The difference is that real journalists and the media outlets who employ them will admit when they are wrong or duped. These bad actors hurt all of journalism, so at this point I am boycotting Bloomberg just as I do Fox News for purposely choosing to push a false narrative.
    chasmradarthekatwatto_cobramuthuk_vanalingam
  • Reply 7 of 14
    boltsfan17boltsfan17 Posts: 2,294member
    Soli said:
    Journalists can and will make mistakes. Sources can lie and people can be duped, especially when it's backed by a foreign agency disseminating a false narrative. We accept this and (for everyone that is rational) we accept this will occur from time-to-time. The difference is that real journalists and the media outlets who employ them will admit when they are wrong or duped. These bad actors hurt all of journalism, so at this point I am boycotting Bloomberg just as I do Fox News for purposely choosing to push a false narrative.
    I'm actually really surprised Bloomberg won't retract the story. You can say the same about CNN, MSNBC, etc. They push a false narrative as well. The only news sites I read now are from foreign newspapers. It seems like there aren't any neutral reporting news agencies in the U.S. anymore.
    larryjwwatto_cobra
  • Reply 8 of 14
    tzeshantzeshan Posts: 2,351member
    "Bloomberg hasn't backed down from its claims, and U.S. senators have asked Super Micro for answers."

    This is incredible. After over two thousands years learning how to find truths, the western civilization still is doing it wrong. 
    watto_cobra
  • Reply 9 of 14
    tzeshan said:
    "Bloomberg hasn't backed down from its claims, and U.S. senators have asked Super Micro for answers."

    This is incredible. After over two thousands years learning how to find truths, the western civilization still is doing it wrong. 
    It reminds me of the time Congress asked the insurance companies what ‘became Obamacare’ should look like. (And no Trump didn’t “fix” it)

    Is it any surprise insurance companies ended up rolling in the $$$ while the average Joe got bilked...

    For the record, I’m very security conscious and I wouldn’t hesitate to buy a Super Micro motherboard.  Bloomberg bought a lie, and needs to own up to their mistake.  Bloomberg is better than most, so no boycott from me...


    watto_cobra
  • Reply 10 of 14
    chasmchasm Posts: 3,294member
    One has to wonder how many millions of dollars have been wasted by Apple, Amazon, the military, the other companies Bloomberg refuses to name, Congress, and now Super Micro in proving Bloomberg lied.

    I wonder if the companies and the government can ever recover those costs after they prove Bloomberg wrong.
    edited October 2018 watto_cobrajony0
  • Reply 11 of 14
    maestro64maestro64 Posts: 5,043member
    Soli said:
    Journalists can and will make mistakes. Sources can lie and people can be duped, especially when it's backed by a foreign agency disseminating a false narrative. We accept this and (for everyone that is rational) we accept this will occur from time-to-time. The difference is that real journalists and the media outlets who employ them will admit when they are wrong or duped. These bad actors hurt all of journalism, so at this point I am boycotting Bloomberg just as I do Fox News for purposely choosing to push a false narrative.
    Actually, Howard Stern foreshadowed all of what we see in the media today. Howard and his cohorts use to try and get the media to buy into so stupid premises Howard's team came up with and then report on it. He started this back in the 80's and more times than not the media would report information as fact only to have Howard and his crew call them out on it.

    The media today is too interested in telling a story then reporting the fact. I was in the meeting with my boss and higher level exec and we were dealing with a major issue and my boss said to everyone "they would not care about the facts once they hear the story." This is what the media is doing, they hope we do not care about the facts once we hear their story.
    radarthekat
  • Reply 12 of 14
    maestro64maestro64 Posts: 5,043member
    Soli said:
    Journalists can and will make mistakes. Sources can lie and people can be duped, especially when it's backed by a foreign agency disseminating a false narrative. We accept this and (for everyone that is rational) we accept this will occur from time-to-time. The difference is that real journalists and the media outlets who employ them will admit when they are wrong or duped. These bad actors hurt all of journalism, so at this point I am boycotting Bloomberg just as I do Fox News for purposely choosing to push a false narrative.
    I'm actually really surprised Bloomberg won't retract the story. You can say the same about CNN, MSNBC, etc. They push a false narrative as well. The only news sites I read now are from foreign newspapers. It seems like there aren't any neutral reporting news agencies in the U.S. anymore.

    The problem, most of US media just report on each other stories. Instead of reporting on what they know as fact they just repeat what other news outlets have reported. There is very little original reporting going on. They are all assuming what Bloomberg is reporting is factual instead of doing their own work, these people probably think it was okay to copy other people's work in high school and college.
    edited October 2018
  • Reply 13 of 14
    radarthekatradarthekat Posts: 3,842moderator
    chasm said:
    One has to wonder how many millions of dollars have been wasted by Apple, Amazon, the military, the other companies Bloomberg refuses to name, Congress, and now Super Micro in proving Bloomberg lied.

    I wonder if the companies and the government can ever recover those costs after they prove Bloomberg wrong.
    Worse yet, if Bloomberg were correct then why hold back the names of the other companies affected?  This implies Nloomnerg is okay allowing those companies to continue to unknowingly be hacked.  And that alone puts the lie to Bloomberg’s story, as if there needed to be yet one more bit of logic pointing to that conclusion.  
  • Reply 14 of 14
    Rayz2016 said:
    And still Bloomberg stays silent.

    With their credibility on the line, surely now is the time to produce the evidence. National security is at stake here. Just holding back the evidence like this is criminal. 

    They can wait till SuperMicro conducts their investigation and then claim that SuperMicro removed all traces of the malicious chips!
    watto_cobra
Sign In or Register to comment.