Oct 9, 2018

Bloomberg: China bugged ethernet hardware, too

Photo: Guirong Hao via iStock / Getty Images

Following up on its controversial story accusing China of implanting chips into Supermicro server motherboards to spy on companies, Bloomberg now reports that a researcher found a different implant in an unnamed company's Supermicro system.

The details: Yossi Appleboum, co-CEO of Sepio Systems, claims to have found a hardware implant in the "ethernet connector" of a telecom company's Supermicro motherboard in August. He could not reveal to Bloomberg what company he found the implant in due to a non-disclosure agreement.

The backdrop: Bloomberg's first story took flack after Homeland Security, the British cybersecurity agency NCSC, and the companies it named — Supermicro, Apple and Amazon — all denied the story.

What the new story means: The latest story provides a new data point that Supermicro systems were involved in espionage. That provides some general support for the first story.

  • It does not show evidence the implant in the first story existed, or that any of the narratives arround Apple and Amazon discovering that first implant in the first story were true.
  • The new story is based on the experiences of a single person and the secrecy around the target makes it hard for a third party to verify. "This would makes more sense in firmware than hardware," tweeted former NSA hacker Jake Williams, the founder of Rendition Infosec.
  • It matters whether the spying tool is hardware or firmware. Firmware, the code embedded in physical devices, is easier to replace than hardware. And it's more likely that spies could tamper with firmware without the cooperation of a company like Supermicro than that they could slip a chip into the assembly of a motherboard.

Go deeper

2 mins ago - Technology

Podcast: Social media maelstrom

Hundreds of Facebook employees yesterday walked off the job, to protest the big blue app's refusal to pull certain posts from President Trump, days after Trump threatened to change the laws around social media in response to a Twitter fact-check. Dan digs into what comes next with attorney Stewart Baker, former Department of Homeland Security assistant secretary for policy.

ICE and border agents deployed to help with protest enforcement

Police near the White House during George Floyd protests. Photo: Alex Wong/Getty Images

Immigration agents have been deployed to assist federal, state and local law enforcement amid intensifying protests over the police killing of George Floyd, immigration agency officials confirmed to Axios.

Why it matters: Local protests in cities across the U.S., a number of which have turned violent, have incited a strong federal response from agencies including the National Guard, Immigration and Customs Enforcement (ICE), Customs and Border Protection (CBP) — and President Trump himself.

Updated 1 hour ago - Politics & Policy

Biden: George Floyd's last words are "a wake-up call for our nation"

Former Vice President Joe Biden meets with clergy members and community activists during a visit to Bethel AME Church in Wilmington, Del. on June 1, 2020. Photo: JIM WATSON/AFP via Getty Images

Vice President Joe Biden is calling George Floyd’s dying words “a wake-up call for our nation,” and criticized President Trump’s decision to unleash tear gas on peaceful protesters outside the White House, in a civil rights speech from Philadelphia on Tuesday.

Why it matters: Biden in the address drew a sharp contrast between himself and Trump, whose first remarks addressing nationwide unrest Monday highlighted law and order, extreme demonstrations of militarized “strength” and other blustery threats.