Joe Uchill Profile picture
12 Feb, 11 tweets, 2 min read
There's a ton of stuff we don't know about Bloomberg Supermicro 1 and 2 that I'm not sure we're going to know. Here's what I do know about Supermicro 1, the original story:
I know a ton of national security and cybersecurity reporters and contractors who tried to substantiate the first story without success.

I tried to substantiate the first story without success.
People who I spoke to on Capitol Hill said they *wished* it was true to confirm what we generally know about China's industrial espionage.

People I spoke to in industry launched expensive investigations to see if they had been hit. They hadn't.
Amazon told me it investigated the claims after the Bloomberg story, to no avail.

Experts told me that the public denials from Apple and Amazon would put them in regulatory peril if they were lying.
In public: Rob Joyce said the NSA was baffled by the story and asked anyone with information to bring it to the NSA.

A key technical expert quoted in the article said he told the reporters he didn't believe the story about a microchip implant, but that was not in the story.
The general consensus from the original story was that if China was going to run this exact scenario, a firmware attack would be more likely than a microchip implant.
Bloomberg backed up their story a few days later with a single claim about backdoored ethernet hardware - which is still a distance from the original claim of a rice-sized microchip on the motherboard.
Supermicro commissioned their own third party investigation, which turned up nothing. At one point in the wake of the first story, their stock had dropped over 50%.
If you know anything that would substantiate either Supermicro story, my DMs are open.
I want to be absolutely clear: National security reporting is tough. Information is compartmentalized - not everyone knows everything. People draw connections that aren't there. People lie. There are tons of things I don't know.

If you know any of them, genuinely, let me know.
I noticed I left one out: DHS never notified anyone to mitigate the issue.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Joe Uchill

Joe Uchill Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @JoeUchill

10 Feb
The EAC is about to vote on the Voluntary Voting System Guidelines 2.0.

The most contentious point in VVSG is that it says wireless technology should be disabled and not completely removed from voting machines.
I'll try to live-tweet anything interesting, but am also expecting a call for work. So this thread may cut short at any time.

It could be very dramatic.
Disabling wifi rather than not purchasing machines that have wifi allows for more maneuverability in commercial, off the shelf purchases.
Read 19 tweets
7 Jan
The natsec/infosec implications of the coup attempt are staggering - not just in Pelosi's office.

They'll need to assume all systems and physical files were compromised, and catalog what of each was stolen, altered or destroyed
In the long run, they need an evacuation failsafe for computer systems.
I wasn't really referring to classified files. But it's worth noting that Mieke Eoyang disagrees both in terms of classified files and in general (down conversation).
Read 5 tweets
2 Jan
I AM GOING TO CONTINUE TO WATCH CSI:CYBER
By the end of the first season, over the course of several investigations, the FBI had hacked into Boston's transportation system, an online casino that was cooperating with the investigation and the camera on a teenage girl's home computer.

Where will they CSI:CYBER next?
Interesting notes from the intro to episode 1:
-Peter McNichol (Ghostbusters 2) has been replaced by Ted Danson.
-They've taken out the part where someone whispers "It can happen to you."
Read 133 tweets
1 Jan
The passage of the NDAA means that the Executive Branch gets a new staff member: the National Cybersecurity Director.
The position is modeled after the U.S. Trade Representative, and is one of the Cybersecurity Solarium’s suggestions.
The position is Senate confirmed.
Read 5 tweets
26 Dec 20
I AM GOING TO WATCH CSI CYBER.
There's two seasons of this? Jeepers.
Amazon knows something.
Read 145 tweets
26 Dec 20
Universes with Pedro Pascal in it:

Game of Thrones
DCEU
Star Wars
CSI
Law and Order
Buffy
Kingsman
The Equalizer
Universes without Pedro Pascal in it:

The Arrowverse
MCU
Star Trek
NCIS
James Bond
Pokemon
Harry Potter
Transformers
Jurassic Park
Also! He was in the 2011 Wonder Woman TV pilot.

He's a WW vet.
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!