Want to be a reporter or would you like to buy a report for the best price?
Just Sign Up here!
Privacy guidelines License our content Help
Super Micro has said it has found no malicious hardware in its products, in another effort to refute a news report that China’s intelligence services planted malicious chips in the company’s server motherboards, reported South China Morning Post (Hong Kong).
The server maker, whose products were said to be compromised in a bombshell article by Bloomberg Businessweek magazine on October 4, said that, contrary to the report’s claim, no government agency had contacted the company about such hardware.
In a letter emailed to Florida Senator Marco Rubio and Connecticut Senator Richard Blumenthal – a copy of which was obtained by the South China Morning Post – Super Micro (also known as Supermicro) denied Bloomberg’s reports.
“We are confident the recent Bloomberg Businessweek stories are wrong,” wrote Perry Hayes, president of Super Micro Netherlands and its senior vice-president of investor relations.
“In fact, we believe that it is impossible as a practical matter to insert unauthorised malicious chips onto our boards during the manufacturing process.”
The letter was sent in response to a request for information from the senators earlier this month.
Addressing the allegation that chips were planted during manufacturing to infiltrate companies, Hayes wrote that Super Micro’s “test processes at every step are designed to alert us to any discrepancies from our base design”.
The designs are “extremely complex, making it practically impossible to insert an unauthorised component onto a motherboard without it being caught by the checks.”
Hayes went on to write that “because Supermicro is the only one that maintains the master files”, changes to the design by one downstream manufacturer “would create an obvious mismatch between the design and manufactured board”.
The company “has never found any unaccounted-for modifications of its firmware”, the letter said.
In Bloomberg Businessweek’s October cover story, titled “The Big Hack”, it claimed that Chinese spies infiltrated the supply chains to install tiny chips the size of a grain of rice onto the company’s motherboards.
The story also said investigators found the Chinese infiltration through Super Micro reached almost 30 companies, including Amazon and Apple.
Amazon, Apple and Super Micro immediately denied the veracity of the story in separate statements on the same day.
In the days that followed, the US Department of Homeland Security issued a statement to say that “we have no reason to doubt the statements from the companies named in the story”, in support of the three companies’ denials.
Officials at the Federal Bureau of Investigation and the National Security Agency expressed caution at a Senate hearing and to a reporter, respectively, saying the related claims in the story had not been corroborated.
On October 19, Apple chief executive Tim Cook, in a BuzzFeed interview, called for Bloomberg to retract the story, in a first-ever move by the executive to demand a news story be pulled.
Andy Sassy, head of Amazon Web Services, and Charles Liang, Super Micro’s chief executive, joined Cook in requesting a retraction of the story in the same week.
Super Micro stressed that the company “has not been approached by law enforcement regarding an ongoing investigation that Bloomberg claims exists”.
Super Micro said it also “independently investigated Apple’s report”. “Based on information from Apple and our own investigation, Super Micro reached the same conclusion as Apple – our products had not been systematically affected by malicious actors.”
In response to the senators’ questions about the company’s interactions with the Chinese government, Hayes wrote that “the Chinese government has never requested access to Super Micro’s confidential security information or sought to restrict information regarding the security of Super Micro’s products.”
A Bloomberg representative did not immediately respond to a request seeking comment.
show source https://www.scmp.com/news/china/diplomacy/article/2170971/super-micro-tells-us-lawmakers-it-found-no-chinese-spy-chips