Los Angeles Times

China espionage alleged

The Asian nation put surveillan­ce chips in servers used by tech giants, report says.

- By Craig Timberg, Ellen Nakashima and Hamza Shaban Timberg, Nakashima and Shaban write for the Washington Post.

China secretly inserted surveillan­ce microchips into servers used by major technology companies, including Apple Inc. and Amazon.com Inc., in an audacious military operation likely to further inflame trade tensions between the United States and its leading source of electronic­s components and products, Bloomberg Businesswe­ek reported Thursday.

The article detailed a sweeping, years-long effort to install the surveillan­ce chips in servers whose motherboar­ds — the brains of the powerful computers — were assembled in China. The servers of one affected company were used by U.S. government clients, including Defense Department data centers, Navy warships and CIA drone operations.

The extent of the data China collected from the surveillan­ce chips was not clear from the report, and no consumer informatio­n was known to have been stolen, according to Bloomberg Businesswe­ek. But it said a top-secret U.S. government investigat­ion, dating from 2015 and involving the FBI, remains open.

The story cited 17 unnamed sources, including industry insiders and current and former U.S. officials. The Chinese government, Apple, Amazon and other involved companies disputed the report to Bloomberg Businesswe­ek, and the FBI and U.S. intelligen­ce officials declined to comment.

One U.S. official told the Washington Post on Thursday that the thrust of Bloomberg Businesswe­ek’s reporting was accurate. This person spoke on the condition of anonymity to discuss matters not approved for public release.

The revelation­s came just hours before Vice President Mike Pence was to deliver a stinging rebuke of China in a speech at the Hudson Institute in Washington. Pence was expected to criticize what the Trump administra­tions sees as China’s increasing­ly aggressive behavior, including allegation­s by President Trump last week that the country is meddling in the U.S. midterm election.

The United States and China are locked in a bitter trade war, with tariffs on huge amounts of each other’s products.

The reported manipulati­on of electronic­s supply chains to U.S. companies are certain to sharpen longstandi­ng questions about the crucial but uneasy relationsh­ip between the world’s two leading economies. American companies design and sell leading technology products, such as servers, laptop computers and smartphone­s, which are built and assembled largely in China.

U.S. officials long have worried about the potential for altered microchips or other components to be secretly inserted into products and shipped to the United States and elsewhere, opening doors to long-term spying on computer users and their informatio­n networks.

Surveillan­ce through altered hardware is more difficult to execute than more familiar hacks to software, but the results can be harder to remedy because the components must be detected and physically removed, or use of the hardware must be stopped.

The surveillan­ce microchips reportedly could have connected to outside computers and secretly downloaded software to bypass security protection­s — such as passwords or encryption keys — stored elsewhere on the affected servers, enabling remote computeriz­ed spying.

The operation, which Bloomberg Businesswe­ek attributed to a Chinese military unit that specialize­s in hacking hardware, worked by inserting a tiny, innocuous-looking microchip onto motherboar­ds in servers produced by Super Micro Computer Inc., a leading supplier of such equipment. The San Jose company is American but the motherboar­ds were assembled mainly in China.

Apple and Amazon both discovered the surveillan­ce chips in 2015 and took steps to replace the affected servers, according to the report, which described close cooperatio­n between U.S. investigat­ors and affected companies. The report said dozens of companies may have used sabotaged servers in their data centers before the Chinese operation was detected.

On Thursday morning, Apple referred the Washington Post to its statement in the Bloomberg Businesswe­ek story alleging that the reporting was inaccurate. “Apple has never found malicious chips, ‘hardware manipulati­ons’ or vulnerabil­ities purposely planted in any server,” the statement said. “Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigat­ion by the FBI, nor are our contacts in law enforcemen­t.”

The report also quoted denial of the reporting by Amazon Web Services, a cloud-services subsidiary of Amazon, which in 2015 acquired a company, Elemental, whose servers reportedly were affected by the Chinese operation. (The Washington Post is owned by Amazon Chief Executive Jeff Bezos.)

“It’s untrue that AWS knew about a supply chain compromise, an issue with malicious chips, or hardware modificati­ons when acquiring Elemental,” the Amazon statement said. “It’s also untrue that AWS knew about servers containing malicious chips or modificati­ons in data centers based in China, or that AWS worked with the FBI to investigat­e or provide data about malicious hardware.”

Super Micro said in its statement, “We are not aware of any investigat­ion regarding this topic nor have we been contacted by any government agency in this regard.”

 ?? Tripplaar Kristoffer Sipa ?? AMAZON Web Services, a cloud-services subsidiary of Amazon, denied a report that malicious chips or hardware modificati­ons were found in its servers.
Tripplaar Kristoffer Sipa AMAZON Web Services, a cloud-services subsidiary of Amazon, denied a report that malicious chips or hardware modificati­ons were found in its servers.

Newspapers in English

Newspapers from United States