Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

31–40 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#31

Earlier quoted context omitted.

> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.

Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.

If I were an attacker in that situation I'd probably find a way to get my data to hitch a ride with other outgoing data

Re: Making sense of the alleged Supermicro motherboard attack

#32

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

That’s my main takeaway from all of this- Elemental is great at their job and didn’t just do a half assed attempt at an audit. They actually did what they were hired to do. I wonder how rare that is.

You perhaps meant not Elemental, but Elemental's auditors is great at their job.

> ... In late spring of 2015, Elemental’s staff boxed up several servers and sent them to Ontario, Canada, for the third-party security company to test, the person says. Nested on the servers’ motherboards, the testers found a tiny microchip ...

Re: Making sense of the alleged Supermicro motherboard attack

#33

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It's as hard to imagine as the NSA's surveillance systems.

I.e., it's not.

The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done.

China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the future: if you never do it, then you never get the benefit, and if you do do it, you get to do it once, and once is better than never.

Re: Making sense of the alleged Supermicro motherboard attack

#34
post #8

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

Depends on where it was added. Doing it as part of the assembly process would require having access to the pick and place software along with being able to load reels of the implant into the machine. A well placed insider may be able to make that happen, and automated optical inspections would be fed by the modified pick and place program, so checks would pass as the new component is part of the build.

Thanks for that info. I assumed that once the boards came back to SM's US premises, a second level of optical and other tests are done by SM employees. But perhaps that's not - or was not - their actual workflow.

Re: Making sense of the alleged Supermicro motherboard attack

#35

Earlier quoted context omitted.

Are you basing this off the photo in the Bloomberg article that shows a small (0402?) SMT package with three terminals? I wonder if that's an actual photo of the chip in question.

FTA: https://assets.bwbx.io/images/users/iqjWHBFdfxIU/iWRg56pmx50... > [...] a picture of the alleged implant. This shows a 6-pin silicon chip inside a roughly 1mm x 2mm ceramic package – as often used for capacitors and other so-called ‘passive’ components, which are typically overlooked.

It might be possible to mount an attack from a board location occupied by a legitimate passive component (or a single SOT-23 transistor, something like that). In that case the attacker would only need to replace a reel of legit passives in the PnP machine. Visually they'd be identical.

Re: Making sense of the alleged Supermicro motherboard attack

#36

Earlier quoted context omitted.

There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.

The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.

Aren't we talking about virtual machines running on this hardware?

Re: Making sense of the alleged Supermicro motherboard attack

#37

Earlier quoted context omitted.

There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.

The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.

Unless, just to provide a nightmare scenario, the routers that would detect it are also compromised.

Re: Making sense of the alleged Supermicro motherboard attack

#38

Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.

> notice any of the outbound traffic Outbound traffic is allowed unrestricted in 95% of the deployments, it is just a life fact, people trust their own systems.

Yep, lack of egress filtering everywhere. Scary how many cloud deployments I see that are like this. Improvements in automation tools and the ability of cheap cloud resources enable people to roll out instance after instance with the same basic configuration mistakes.

Re: Making sense of the alleged Supermicro motherboard attack

#39
post #5
post #3

Earlier quoted context omitted.

EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant

If it replaced a DNP part, it could have been found at a flying probe test. Half the expected impedance on a few of those pins? Also AOI might have picked up a difference.

Flying probe testing is unlikely to be used for this type of product.
Post reply on HN