Live data from Hacker News

Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

servethehome.com

1–10 of 30 posts

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#4
>Saying there is a vulnerability in a BMC is like saying the sun is hot.

This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#5

Why spend 2 paragraphs talking about how DRAM chips cannot be intercepted because of large number of lines only to get to the point later and say "BMC chips are more probable"? This is obvious. This article is annoying to read.

It wasn’t obvious to me. I’m glad they took the time to explain that. I never thought that RAM pins were multiplexed. I never thought about RAM pins at all.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#6
post #4

>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.

We’re seeing a lot of anti Chinese and anti Russian news. I have a tendency to believe them but at the same time there’s of course never going to be reported in the US what we are doing.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#7
> Bloomberg says it is in line with memory to CPUs to intercept some password validation code

I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wires could be enough to compromise it and gain God Mode over the early x86 SW environment.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#8

Why spend 2 paragraphs talking about how DRAM chips cannot be intercepted because of large number of lines only to get to the point later and say "BMC chips are more probable"? This is obvious. This article is annoying to read.

It seems weird because the Bloomberg article says they were connected to the BMC:

> The illicit chips could do all this because they were connected to the baseboard management controller, a kind of superchip that administrators use to remotely log in to problematic servers

The discussion of DRAM only really seems necessary if that _isn't_ plausible.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#10
> If the FBI, or other intelligence officials, had reason to believe Supermicro hardware was compromised, then we would expect it would have taken less than a few years for this procurement to stop.

From the perspective of someone who merely reads what experts write, that isn't true at all. If you have information on your enemy's operations and they are unaware, you have the information advantage and you don't give it up. You use it to monitor them, trace their activities: For example, where does the connection go? And where does the information go from there? Plant malware in whatever is sent back in order to trace who accesses it and maybe give you a backdoor, or if you can't do that plant false information and see where it turns up. Also, who is physically planting the PCB? Mine them, their activities, and social network for more intel.

Also undermine your enemy with false information and by shutting them down not now, reactively, but at the worst possible time for them - when the crisis hits in the South China Sea or Taiwan, pull the plug on their intel or start feeding it false info. And in the meantime, avoid giving them anything too valuable.

On one hand, undoubtedly I have massive blinds spots in my knowledge and the details are probably somehow wrong. On the other, I'm somewhat confident that many times, an intelligence agency would not reveal what they know and would do the kinds of things I'm discussing.

Post reply on HN