Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

41–50 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#41
While it's practically certain that hacking attempts do happen from both state- and non-state actors, this particular instance is so "alleged" that it's practically theoretical.

Where's the actual hardware? Why didn't someone decap the tiny chip and probe it? Its design should be well within today's reverse engineering labs' capabilities.

Re: Making sense of the alleged Supermicro motherboard attack

#42
post #26

Earlier quoted context omitted.

You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.

Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.

otoh you have to consider the probability that flashing the firmware will brick your server (p >> 0.0 in my experience).

Re: Making sense of the alleged Supermicro motherboard attack

#43
post #3

Earlier quoted context omitted.

EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant

Are you basing this off the photo in the Bloomberg article that shows a small (0402?) SMT package with three terminals? I wonder if that's an actual photo of the chip in question.

Based on the captions in the original story, I think it's just a photo of a random signal conditioning coupler, which the chip in question was said to strongly resemble.

But I'm not sure.

Re: Making sense of the alleged Supermicro motherboard attack

#44

I'm no expert, but wouldn't be more efficient to completely replace the BMC with a malicious one? That way it should be virtually impossible to detect

In true HN fashion, I’m not an expert either, but I can think of two plausible reasons. 1) Directly compromising via software the BMC is easy to detect if you bothered to look. (i.e. checksums don’t match), and would only last as long as the BMC isn’t flashed. 2) It’s simply currently easier to make a second component, rather than to integrate it into the main chip directly. Of course, if I was in charge of this proj…

3) the purpose of the operation was to produce headlines and fear in the western press. A few bytes changed in some firmware, or even a malicious BMC design (presumably they're gate-array designs, not full-custom) wouldn't allow for macro photos of a chip the size of a grain of rice and all that.

Re: Making sense of the alleged Supermicro motherboard attack

#45

Earlier quoted context omitted.

That’s my main takeaway from all of this- Elemental is great at their job and didn’t just do a half assed attempt at an audit. They actually did what they were hired to do. I wonder how rare that is.

You perhaps meant not Elemental, but Elemental's auditors is great at their job. > ... In late spring of 2015, Elemental’s staff boxed up several servers and sent them to Ontario, Canada, for the third-party security company to test, the person says. Nested on the servers’ motherboards, the testers found a tiny microchip ...

[deleted]

Re: Making sense of the alleged Supermicro motherboard attack

#46

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It's not at all hard to imagine, especially from a country who is so paranoid about backdoors from other country's operating systems that they have written their own:

https://en.wikipedia.org/wiki/Kylin_(operating_system)

Re: Making sense of the alleged Supermicro motherboard attack

#48

Earlier quoted context omitted.

> notice any of the outbound traffic Outbound traffic is allowed unrestricted in 95% of the deployments, it is just a life fact, people trust their own systems.

Yep, lack of egress filtering everywhere. Scary how many cloud deployments I see that are like this. Improvements in automation tools and the ability of cheap cloud resources enable people to roll out instance after instance with the same basic configuration mistakes.

Yum update, pip install whatever :)

Re: Making sense of the alleged Supermicro motherboard attack

#49
post #26

Earlier quoted context omitted.

You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.

Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.

I know more than one vendor who's dumped firmware from BMCs to compare to the vendor image. Simply reflashing the firmware would be caught by this, an implant wouldn't.

Re: Making sense of the alleged Supermicro motherboard attack

#50
This article is worth skimming/reading in order to fill in the technical gaps in the Bloomberg article; but also describes the complexity of modern computers in a way I didn't previously appreciate.

What's still missing in the overall story, is what Apple and Amazon denials mean. The Bloomberg article says Apple and Amazon independently discovered these chips (Amazon via a 3rd party) in 2015; but the blanket denials by both companies appear to deny this discovery and reporting to U.S. authorities. I'd argue it's unethical for a company to apply falsus in uno, falsus in omnibus to a PR statement, but it's plausible there is a sufficiently misleading or false claim in the Bloomberg article that they feel it's legitimate to dismiss the entire article. In the meantime, the company denials have to be treated as conjecture.

Post reply on HN