Live data from Hacker News

Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

servethehome.com

11–20 of 30 posts

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#11
post #9

Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...

As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to use https://en.wikipedia.org/wiki/IEEE_802.1X

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#12
post #7

> Bloomberg says it is in line with memory to CPUs to intercept some password validation code I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wire…

I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#13
post #6
post #4

>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.

We’re seeing a lot of anti Chinese and anti Russian news. I have a tendency to believe them but at the same time there’s of course never going to be reported in the US what we are doing.

> there’s of course never going to be reported in the US what we are doing

That doesn't square with all the reports on US domestic and international spying, much of it in the NY Times, not to mention The Intercept and others. How do you think we know about it? Not from Chinese and Russian newspapers.

> We’re seeing a lot of anti Chinese and anti Russian news

Hmmm ... maybe we're seeing a lot of Chinese and Russian activity. If you look at coverage of the current US President, you might notice a lot of 'anti-US' news also. Under the prior administration, there was a lot of that on Fox News and in the Wall Street Journal.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#14
post #4

>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.

Do you have any evidence? Otherwise the comment is no better than another kind of op.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#15
Disappointed that there was not any actual technical substance to this article aside from the pictures of the boards. I was excited for a moment, hoping they'd get further until the details, but it ended up in some opinionated rant about how the SEC should get involved.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#16
post #9

Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...

As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…

In the other threads it has been mentioned that this hypothetical attack could run similarly to the US/Xerox op in the Cold War. The Xerox machines recorded data which was collected by a Xerox technician during regular maintenance. A board with a trojan chip on it could potentially record data to be collected during an RMA. No need for network transmission.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#17
post #9

Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...

As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…

If the rogue firmware was indeed loaded from this chip, the "bridge mode" could have been forcefully activated.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#18
post #9

Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...

As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…

The article did mention something around the lines of "the compromised machines could talk to other compromised machines on a network" so I guess the idea is to find a compromised machine close enough to an edge network to reach a C&C server?

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#19

Earlier quoted context omitted.

As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…

If the rogue firmware was indeed loaded from this chip, the "bridge mode" could have been forcefully activated.

But monitoring software really wouldn't detect this...?

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#20
post #7

> Bloomberg says it is in line with memory to CPUs to intercept some password validation code I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wire…

I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.

It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack.

And I believe that once you control the BIOS image you control the boot chain of trust.

Post reply on HN