Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

51–60 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#51
post #46

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It's not at all hard to imagine, especially from a country who is so paranoid about backdoors from other country's operating systems that they have written their own: https://en.wikipedia.org/wiki/Kylin_(operating_system)

“You only look behind the door if you have stood there yourself.”

Re: Making sense of the alleged Supermicro motherboard attack

#52

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

> what circumstances is it possible that SM's QC missed this out Rogue insider, paid or patriotic, likely both. > affect things like the power budget, weight, and latency All three would have no measurable change, falling into measurement error margin. Its a death sentence for Supermicro, nothing will help to restore trust. They should publish a detailed post-mortem analysis, though.

> They should publish a detailed post-mortem analysis, though.

More of an obituary at this point.

Re: Making sense of the alleged Supermicro motherboard attack

#54

Earlier quoted context omitted.

Yep, lack of egress filtering everywhere. Scary how many cloud deployments I see that are like this. Improvements in automation tools and the ability of cheap cloud resources enable people to roll out instance after instance with the same basic configuration mistakes.

Yum update, pip install whatever :)

Rubygems for everybody! Or arbitrary docker containers.

My current deployments allow outbound SMTP only. All software packages (rpm or whatever) get pushed in via rsync from the outside, or are built in an adjacent lab behind the firewalls and pushed across.

Re: Making sense of the alleged Supermicro motherboard attack

#55
post #3

Earlier quoted context omitted.

EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant

One of the bloomberg articles claimed that in some cases it was "thin enough that they’d been embedded between the layers of fiberglass" -- like as if it were a passive in a blind/buried via? This seems like a very sophisticated attack.

Not a sophisticated attack, but a standard industry practice for high value, high density boards. I first saw a buried passive 5 years ago.

Re: Making sense of the alleged Supermicro motherboard attack

#56
post #5
post #3

Earlier quoted context omitted.

EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant

If it replaced a DNP part, it could have been found at a flying probe test. Half the expected impedance on a few of those pins? Also AOI might have picked up a difference.

AOI would miss the chip if it were buried between layers or look exactly like a part it was replaced for.

Re: Making sense of the alleged Supermicro motherboard attack

#57

Earlier quoted context omitted.

I don’t know what you mean by the first question. The implication was that this was a bit of a drift net attack. Compromise a few lots, then wake them up a few months later figure out where they are. Most aren’t useful, but if you got the right batch, some might end up someplace interesting. I would assume the reason why no one noticed outbound traffic is because it’s dormant.

So if there’s a bunch of compromised boards, where are they? Which boards? If they truly are in a bunch of datacenters, and we know the manufacture and models, why hasn’t anyone just gone and looked? Or Why haven’t the leakers just provided the actual chip? It should have been as easy as ordering one.

Why are you assuming people haven't looked?

> Why haven’t the leakers just provided the actual chip? It should have been as easy as ordering one.

Sure, let me just order up a state intelligence compromise. It's right here on Alibaba right under Official_PLA_61398.

Re: Making sense of the alleged Supermicro motherboard attack

#58

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

    > ... high end server manufacturers like SM - use sophisticated automated tests and quality control on boards.
MFG test guy here (not supermicro!)

Not necessarily. Automated production tests are there to configure and exercise the system and confirm it works as specified. Such tests are good at things like finding bad solder joints, pick-and-place mishaps, misconfiguration of firmware and weeding out product that fails functional test. That, by itself, is hard enough.

Such tests are not _really_ able to detect things which no one is expecting, or worse, things which an adversary has specifically designed to avoid detection. Sure, if something gets "discovered" during a failure analysis, a test or process can be created to specifically address THAT problem in the future.

To find "unknown unknowns", you need an audit of some kind and that is definitely different from production test.

Re: Making sense of the alleged Supermicro motherboard attack

#59

Earlier quoted context omitted.

Yum update, pip install whatever :)

Rubygems for everybody! Or arbitrary docker containers. My current deployments allow outbound SMTP only. All software packages (rpm or whatever) get pushed in via rsync from the outside, or are built in an adjacent lab behind the firewalls and pushed across.

It may affect the very source box you are using for package downloads. I bet it is allowed to go outside unrestricted. Funny you mentioned Docker, it is a security nightmare in itself.

Re: Making sense of the alleged Supermicro motherboard attack

#60

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

> what circumstances is it possible that SM's QC missed this out Rogue insider, paid or patriotic, likely both. > affect things like the power budget, weight, and latency All three would have no measurable change, falling into measurement error margin. Its a death sentence for Supermicro, nothing will help to restore trust. They should publish a detailed post-mortem analysis, though.

They took pains to say that this was happening with sub-contractors in China building motherboards in excess of what Taiwan could handle. So to build trust they can pull back on that extra manufacturing capacity and move it elsewhere maybe South Korea.
Post reply on HN