Where's the actual hardware? Why didn't someone decap the tiny chip and probe it? Its design should be well within today's reverse engineering labs' capabilities.
Making sense of the alleged Supermicro motherboard attack
41–50 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#42Earlier quoted context omitted.
You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.
Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.
Re: Making sense of the alleged Supermicro motherboard attack
#43Earlier quoted context omitted.
EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant
Are you basing this off the photo in the Bloomberg article that shows a small (0402?) SMT package with three terminals? I wonder if that's an actual photo of the chip in question.
But I'm not sure.
Re: Making sense of the alleged Supermicro motherboard attack
#44I'm no expert, but wouldn't be more efficient to completely replace the BMC with a malicious one? That way it should be virtually impossible to detect
In true HN fashion, I’m not an expert either, but I can think of two plausible reasons. 1) Directly compromising via software the BMC is easy to detect if you bothered to look. (i.e. checksums don’t match), and would only last as long as the BMC isn’t flashed. 2) It’s simply currently easier to make a second component, rather than to integrate it into the main chip directly. Of course, if I was in charge of this proj…
Re: Making sense of the alleged Supermicro motherboard attack
#45Earlier quoted context omitted.
That’s my main takeaway from all of this- Elemental is great at their job and didn’t just do a half assed attempt at an audit. They actually did what they were hired to do. I wonder how rare that is.
You perhaps meant not Elemental, but Elemental's auditors is great at their job. > ... In late spring of 2015, Elemental’s staff boxed up several servers and sent them to Ontario, Canada, for the third-party security company to test, the person says. Nested on the servers’ motherboards, the testers found a tiny microchip ...
Re: Making sense of the alleged Supermicro motherboard attack
#46Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…
Re: Making sense of the alleged Supermicro motherboard attack
#47Re: Making sense of the alleged Supermicro motherboard attack
#48Earlier quoted context omitted.
> notice any of the outbound traffic Outbound traffic is allowed unrestricted in 95% of the deployments, it is just a life fact, people trust their own systems.
Yep, lack of egress filtering everywhere. Scary how many cloud deployments I see that are like this. Improvements in automation tools and the ability of cheap cloud resources enable people to roll out instance after instance with the same basic configuration mistakes.
Re: Making sense of the alleged Supermicro motherboard attack
#49Earlier quoted context omitted.
You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.
Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.
Re: Making sense of the alleged Supermicro motherboard attack
#50What's still missing in the overall story, is what Apple and Amazon denials mean. The Bloomberg article says Apple and Amazon independently discovered these chips (Amazon via a 3rd party) in 2015; but the blanket denials by both companies appear to deny this discovery and reporting to U.S. authorities. I'd argue it's unethical for a company to apply falsus in uno, falsus in omnibus to a PR statement, but it's plausible there is a sufficiently misleading or false claim in the Bloomberg article that they feel it's legitimate to dismiss the entire article. In the meantime, the company denials have to be treated as conjecture.