Live data from Hacker News

Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

servethehome.com

21–30 of 30 posts

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#21
post #20

Earlier quoted context omitted.

I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.

It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.

You can update the BIOS via SuperMicro's IPMI. It's actually a feature you have to pay extra for: https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S...

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#22
post #20

Earlier quoted context omitted.

I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.

It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.

You can flash the BIOS from BMC on some SuperMicro motherboards. But wait..you can flash the bios from the OS on many machines so why is this a new more dangerous attack vector? Because SM can sign their own BIOS image?

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#23
post #21
post #20

Earlier quoted context omitted.

It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.

You can update the BIOS via SuperMicro's IPMI. It's actually a feature you have to pay extra for: https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S...

Getting them to take your money in exchange for that utility turns out to be hard. I seem to recall figuring out a way to work around the lack of it, but details have been paved out. I think it involved building the OS-based BIOS flashing tool from source.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#24
Thanks for this investigation. I was trying to think of what an actor in a position to insert such chips at a manufacturing level would actually want. You've got some tough limitations - you want a security hole that you can exploit on highly firewalled, monitored, and locked-down servers running a variety of software types. But it also needs to be hard to detect and exploit without knowing some sort of secret. If anyone notices you using the exploit, you're screwed. If any security researcher or black-hat hacker finds it too, you're also screwed. It'd have to be pretty good to avoid that, since those guys are probably fuzzing servers all the time. You'd have to be very careful how you used it - if anybody traces a known data breach to this, then you're screwed too.

Presuming you can get control of the BMC and transmit arbitrary network traffic, you'd have to limit it somehow. At least some of the compromised servers would be installed in places where any unexpected outgoing network traffic would be noticed and investigated. Large amounts of detectable traffic could be generated too if these things are all pinging away at something. You'd have to trigger it somehow I suppose. But what kind of trigger can you set up on a server running an unknown OS in unknown configuration that may be behind lots of firewalls? Are we sending some kind of weird magic packet to the server? If I was Google or something, I'd have dumb filtering firewalls set up in front of my servers that drop anything that doesn't look like normal network traffic, just to keep any random person from fuzzing the server and triggering some weird unknown bug.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#27
post #4

>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.

Patrick Kennedy missed the point of the Bloomberg article, there. Bloomberg pointed out that the qualitative difference is that this is not an exploit of some existing BMC firmware vulnerability. It is the sly introduction of subverted hardware at the point of manufacture and the corruption of the supply chain. It's not the BMC that is the locus of the vulnerability, but the supply chain itself. People had hypothesized this over the years. The Bloomberg report points out that it is a threat model that people seemed unwilling to pay attention to for economic and political reasons. That report, if true, is tantamount to "Yes, you were right about the threat; and this is not a hypothetical any more. China actually did it some years ago.".

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#28

Earlier quoted context omitted.

As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…

In the other threads it has been mentioned that this hypothetical attack could run similarly to the US/Xerox op in the Cold War. The Xerox machines recorded data which was collected by a Xerox technician during regular maintenance. A board with a trojan chip on it could potentially record data to be collected during an RMA. No need for network transmission.

Heck, you can find millions of pages of highly confidential documentation in any Xerox copier junkyard--it's all standardly copied to their internal disks, which are never cleaned on junking.

This caused a small stink a while back but I doubt if anything's changed.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#29
post #19

Earlier quoted context omitted.

If the rogue firmware was indeed loaded from this chip, the "bridge mode" could have been forcefully activated.

But monitoring software really wouldn't detect this...?

"Monitoring software" could really mean anything, or nothing.

Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate

#30
post #19

Earlier quoted context omitted.

But monitoring software really wouldn't detect this...?

"Monitoring software" could really mean anything, or nothing.

Parent probably means network exfiltration detection.
Post reply on HN