They are my oldest and deadliest enemy. You cannot trust them.
If Hitler invaded Hell, I would give a favourable reference to the Devil.

Friday, October 05

Geek

Daily News Stuff 5 October 2018

Tech News

  • The top story of the day is The Big Hack: How China Used a Tiny Chip to Infiltrate U.S. Companies. (Bloomberg)

    The story is that a tiny chip - smaller than a grain of rice - was added to certain SuperMicro motherboards, used by companies including Apple and Amazon and various US government departments, that would subvert the security of the BMC module (a sort of remote control for servers) and allow hackers arbitrary remote access.

    The story has been corroborated by official statements from Apple and Amazon.

    No, wait, not corroborated, what's the other one? Excoriated.

    They did everything but declare Bloomberg anathema and launch a holy war, and I wouldn't be all that surprised if that happens tomorrow.

    Apple
    Over the course of the past year, Bloomberg has contacted us multiple times with claims, sometimes vague and sometimes elaborate, of an alleged security incident at Apple. Each time, we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them. We have repeatedly and consistently offered factual responses, on the record, refuting virtually every aspect of Bloomberg’s story relating to Apple.

    On this we can be very clear: Apple has never found malicious chips, "hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement.
    Amazon
    Today, Bloomberg BusinessWeek published a story claiming that AWS was aware of modified hardware or malicious chips in SuperMicro motherboards in Elemental Media’s hardware at the time Amazon acquired Elemental in 2015, and that Amazon was aware of modified hardware or chips in AWS’s China Region.

    As we shared with Bloomberg BusinessWeek multiple times over the last couple months, this is untrue. At no time, past or present, have we ever found any issues relating to modified hardware or malicious chips in SuperMicro motherboards in any Elemental or Amazon systems. Nor have we engaged in an investigation with the government.

    There are so many inaccuracies in ‎this article as it relates to Amazon that they’re hard to count. We will name only a few of them here. First, when Amazon was considering acquiring Elemental, we did a lot of due diligence with our own security team, and also commissioned a single external security company to do a security assessment for us as well. That report did not identify any issues with modified chips or hardware. As is typical with most of these audits, it offered some recommended areas to remediate, and we fixed all critical issues before the acquisition closed. This was the sole external security report commissioned. Bloomberg has admittedly never seen our commissioned security report nor any other (and refused to share any details of any purported other report with us).
    So far there is no independent verification of any of Bloomberg's claims. All their sources are anonymous, and none have spoken to any other news outlet.

    There's basically two ways this can go: Either two of the world's largest companies just invited regulators and class-action lawyers to tapdance on their heads, or Bloomberg just proved once again that those layers and layers of fact-checkers are less use than a fishnet umbrella on the Moon.

    Serve the Home is dubious and adds this:
    First and foremost, I think we need to call for an immediate SEC investigation around anyone who has recently taken short positions or sold shares in Supermicro. With the accompanying Supermicro stock price hit that was foreseeable prior to the story, if anyone knew the story would be published, and acted on that non-public or classified information, the SEC needs to take action. There seems to have been over 20 people that knew about this.

    This article by the grugq [seriously] delves deeper.  His conclusion: BMC is an active threat in itself, but the Bloomberg story fails in achieving even basic standards of verification.

    My take on all this - provisional, pending actual evidence - is that Bloomberg got played.  And they got played because they are morons.

    No-one
    interested in getting a security story out would take it to Bloomberg - they are completely and utterly incompetent to evaluate such claims, or even to research the story.

    Any actual security researcher would have a field day with this.  Any skilled security researcher would have it blown wide open inside a week.  Bloomberg took three years to report on it, and at the end, they still have nothing to show but anonymous hearsay.

    Who perpetrated the hoax, and for what reasons, is an open question, and we may see hints based on which three letter agency shows up to ask pointed questions of the idiots at Bloomberg.

    As a side note: Any tech journalist who is still reporting this as "well sourced" is not to be trusted about anything, not even reading press releases verbatim.

  • Nokia is making phones again. (AnandTech)

    More than that, they seem to be making really good phones.


Social Media News



Video of the Day


Toucan play at that game.

Posted by: Pixy Misa at 06:59 PM | Comments (1) | Add Comment | Trackbacks (Suck)
Post contains 963 words, total size 8 kb.

Thursday, October 04

Geek

Daily News Stuff 4 October 2018

Tech News

Social Media News



Video of the Day

Posted by: Pixy Misa at 04:14 PM | Comments (3) | Add Comment | Trackbacks (Suck)
Post contains 346 words, total size 4 kb.

Wednesday, October 03

Geek

Daily News Stuff 3 October 2018

Tech News

  • Microsoft releases their new Surface lineup. (AnandTech)

    They have new CPUs, and are now available in a choice of colours: Grey or black.

    And that's it. HP needn't have worried.

  • Microsoft also released the Windows 10 October update. (PCPer)

    It has... Something. Probably. Exciting stuff from Microsoft.

  • Microsoft also announced headphones. (Tom's Hardware)

    They cost $349 and are headphones.

    Microsoft are really hitting it out of the plate today.

  • Wait - Microsoft also updated the Surface Studio. (TechCrunch)

    While still ferociously expensive, it at least has decent specs, with a quad-core i7 CPU and GTX 1060 or 1070 graphics, and a 1TB or 2TB SSD replacing the absurd laptop hard disk of the original.


Social Media News

Posted by: Pixy Misa at 01:46 PM | Comments (2) | Add Comment | Trackbacks (Suck)
Post contains 230 words, total size 3 kb.

Tuesday, October 02

Geek

Daily News Stuff 2 October 2018

Tech News

  • I really need to deploy that new editor with its auto-save feature.

  • HP announced their Spectre Folio, a leather-wrapped convertible laptop like the Spectre x2 only extra leathery.  (AnandTech)

    It's hamstrung by a 5W CPU (the x2 has a 15W part).  I'm guessing it's fanless and silent and has great battery life, but the x2 can actually do stuff.

    Microsoft is launching new Surface hardware in the next few hours, so this is HP trying to grab some news in front of that event.  Good luck with that; they make great hardware but their marketing department needs to be fired en masse:
    "Have you sniffed your PC recently?" Wolff asked. "Other than a whiff of ozone, they generally really don't have a smell, there is no memory associated with them. It's pretty cold. We wanted something that offered more than that, and that was our mission."
      (ZDNet)

    Really, HP, you just needed to note that it has separate PgUp/PgDn/Home/End keys and I'd be sold.  (Thurrott.com)

    It does look good, I must admit.

  • Chrome 69 sucks.  I've had more problems with it than the last 50 release combined.  Guess they were too busy mangling URLs to wrangle bugs.

  • Houston we have a problem with our robot brothel.  (ZDNet)

Social Media News

Posted by: Pixy Misa at 11:22 PM | No Comments | Add Comment | Trackbacks (Suck)
Post contains 233 words, total size 3 kb.

Monday, October 01

Geek

Daily News Stuff 1 October 2018

Tech News

  • The DOJ is suing California over their new net neutrality legislation.  (TechCrunch)

    I wasn't comfortable with the federal government regulating net neutrality, and for exactly the same reasons I'm not comfortable with the federal government preventing the states from regulating net neutrality. 

    More knowledgeable observers than I are citing Wickard v. Filburn as the constitutional basis for this.  I was aware of that decision but didn't know it by name.  It essentially rules that intrastate commerce is interstate commerce because if you are engaging in intrastate commerce you have removed yourself from the totality of interstate commerce which means that you are altering the scope of interstate commerce and can be regulated by the federal government under the Commerce Clause EVEN IF YOU NEVER ENGAGED IN COMMERCE IN THE FIRST PLACE because it would have impacted price stabilisation programs which as a libertarian-leaning Australian strikes me as fucking insane.

    So a single farmer from Ohio growing wheat to feed his own animals in 1938 could decide the fate of the entire internet.
  • molten is a minimal, extensible, fast and productive framework for building HTTP APIs with Python.

    [Looks at code samples.]

    You've turned Python into Ruby.  That's amazing.  I'm not even mad.



Social Media News



Sorry, that's a complete lie.  The shit hasn't just hit the fan, it's gone suborbital.  But I'm taking a day off from that crap.



Video of the Day


One treeelion dollars.  Bits.  One treeelion bits.  Well, one hundred billion bits.  Per second.  Ish.

Posted by: Pixy Misa at 04:32 PM | Comments (5) | Add Comment | Trackbacks (Suck)
Post contains 252 words, total size 2 kb.

<< Page 4 of 4 >>
72kb generated in CPU 0.0188, elapsed 0.1846 seconds.
54 queries taking 0.1723 seconds, 358 records returned.
Powered by Minx 1.1.6c-pink.
Using http / http://ai.mee.nu / 356