Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Bloomberg still has not retracted (or even really commented on) the Supermicro spy chip story, preferring to hope people just forget about it if they maintain total silence. They're fine if you need to look up where the Nasdaq closed yesterday, but don't expect serious tech reporting from them.


> not retracted (or even really commented on) the Supermicro spy chip story

They doubled down on it. They did a follow-up claiming that a cyber security researcher from a US-based firm had been called in to investigate suspicious traffic at a US telecom. The investigators claimed to have logs and a bunch of other evidence. The investigators also claimed that Bloomberg was misleading people by focusing on SuperMicro, as they'd reportedly seen to with other manufacturers too.


Hikivision literally sends hidden packages from their cameras to China.

Discovered by our security team where I work. It's the reason our VMS doesn't have support for Hikivision cameras.


"Discovered by our security team where I work"

Any published where?


Internal audit in the company for customers ( security Company).

A couple of years later, our US customer had the same conclusion. Probably that one was published ( US government)


Anecdotes are not data.

Really - they aren't.


We literally have a hardware device that removes any "spyware" from communicating externally because of it.

People in the security industry ( cameras) may know it.


It's interesting because servethehome.com found some oddly labeled chips at one point:

https://www.servethehome.com/dude-dell-hpe-ami-american-mega...

But yeah, saying the chips are everywhere is BS.


You’re really naive. Bloomberg is one of the better news outlets, and I would put no weight on Supermicro’s denials, as they have a pattern of lying about financials and have a sweepingly broad supply chain vulnerable to sabotage and counterfeiting.

The Federal government and some banks hire companies to do supply chain integrity inspection and management. They find bad parts all of the time, especially in the channel.

There’s a pretty obvious reason why they wouldn’t want to talk about a detected case of foreign espionage embedded in servers after publishing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: