Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

101–110 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#101

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It would explain the bizarre hiring practices - plausibly relevant, but often in areas most devs just don't use day to day - that you could coach fellow agents to pass!

(I've never actually bothered interviewing with any of the above, maybe it's all entirely normal or you need to write your own self-balancing tree implementation regularly).

Re: Making sense of the alleged Supermicro motherboard attack

#102
post #26

Earlier quoted context omitted.

Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.

otoh you have to consider the probability that flashing the firmware will brick your server (p >> 0.0 in my experience).

Absolutely, and I think that is why a lot of people are reluctant to do it. It's a fragile process and if you lose power or have a random cosmic ray hit at the wrong time it's game over.

Re: Making sense of the alleged Supermicro motherboard attack

#103
post #26

Earlier quoted context omitted.

You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.

Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.

There's quite a lot of embedded firmware that isn't derived or controlled or affected by BIOS/UEFI firmware updates. e.g. Thunderbolt (PCIe) firmware.

Re: Making sense of the alleged Supermicro motherboard attack

#104

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

I wonder if there isn't some level of national security super mega secret scenario situation where the government requires companies to do something and the government indemnifies them against all risks associated with the required action.

hasn't it been the case with NSA and carriers all along?

http://articles.latimes.com/2012/oct/09/business/la-fi-court...

"Congress granted retroactive immunity to people or companies aiding U.S. intelligence agents."

In this case i'd not be surprised if Google/FB/AMZN/Apple/MS/Supermicro were even part of the CIA/NSA counter-sting - feeding of the false info back to Chinese intelligence through the detected 'mistery' chips.

Re: Making sense of the alleged Supermicro motherboard attack

#105

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

I wonder if there isn't some level of national security super mega secret scenario situation where the government requires companies to do something and the government indemnifies them against all risks associated with the required action.

How does the USG indemnify these companies for the massive breach of trust if that's indeed the case? You can't pay for trust.

Re: Making sense of the alleged Supermicro motherboard attack

#106
post #71

Earlier quoted context omitted.

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions:

> Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Re: Making sense of the alleged Supermicro motherboard attack

#107

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It's easy to imagine one human killing another, happens all the time. That doesn't imply that any given person who stands accused of murder did it.

Re: Making sense of the alleged Supermicro motherboard attack

#108
post #104

Earlier quoted context omitted.

I wonder if there isn't some level of national security super mega secret scenario situation where the government requires companies to do something and the government indemnifies them against all risks associated with the required action.

hasn't it been the case with NSA and carriers all along? http://articles.latimes.com/2012/oct/09/business/la-fi-court... "Congress granted retroactive immunity to people or companies aiding U.S. intelligence agents." In this case i'd not be surprised if Google/FB/AMZN/Apple/MS/Supermicro were even part of the CIA/NSA counter-sting - feeding of the false info back to Chinese intelligence through the detected 'mistery'…

The carriers never lied about it. They were provided immunity from criminal lawsuits, not civil lawsuits.

Re: Making sense of the alleged Supermicro motherboard attack

#109
Can someone outline some reasons for me why nobody has come up with an actual physical example of a compromised board? I'm not trying to make a point, I just want to get a more complete picture of the issue, and the biggest thing that stands out to me is the lack of physical evidence.

Re: Making sense of the alleged Supermicro motherboard attack

#110
post #74
post #13

Earlier quoted context omitted.

Or even why two SPI roms? Why not just one with special code? It's not like anyone is routinely reverse engineering the BMC boot code. It seems like an awful lot of provable trouble to go through (note that there is no physical evidence in the public eye yet) when you could do the same thing, at the factory, with just software.

it's pretty easy to dump an SPI chip and some vendors/customers routinely do so. In this model, the implant basically contains a binary patch that is injected at boot time over a segment of the BMC binary - counter overflows, chip cuts out the SPI and transmits its payload instead. After the payload is injected the implant goes dormant again/resumes passing through the SPI, so dumping the ROM after boot, or even phys…

Wu-tang.
Post reply on HN