Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

161–170 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#162

Earlier quoted context omitted.

It's just my opinion, and so I held off saying, yesterday, but: The immediate economic outfall (co-morbid with institutional panic) would be so severe that this aspect alone would represent a national security issue.

Supermicro stock dipped down to 50 % or so (20->10).

Supermicro has been dealing with some accounting irregularities for the last year or so. This news certainly hasn't helped, but they were already in a shaky position.

https://www.marketwatch.com/story/super-micros-stock-set-to-...

Re: Making sense of the alleged Supermicro motherboard attack

#163
post #113

Earlier quoted context omitted.

No more Chinese phones for me either way. It's enough that Google knows everything about me, PLA doesn't have to.

What phones do not have Chinese components?

Not only that, which base stations don't have Chinese components?

But cpu, baseband, ram etc is certainly more serious consideration... And I don't see how you can get around that. Unless you plan to build a dumb phone around a Motorola 68k or something?

Re: Making sense of the alleged Supermicro motherboard attack

#164

Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.

> Why wouldn’t a company notice any of the outbound traffic using firewalls?

If you deploy several thousand of those backdoor chips, you wouldn't set them up to ping your C&C infrastructure all on its own. Rather, you'd use a magic string as a trigger to activate the backdoor in some few targets to reduce the chance of the outbound traffic being detected.

Re: Making sense of the alleged Supermicro motherboard attack

#165
There's a problem with exfiltrate via BMC network theory.

In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection to outside, no unknown traffic, just silence. Only exception may be the discovery packets of some BMCs, which can find similar servers and form federations for easier management. Even this needs some setup beforehand.

Re: Making sense of the alleged Supermicro motherboard attack

#166

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

> ... high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. MFG test guy here (not supermicro!) Not necessarily. Automated production tests are there to configure and exercise the system and confirm it works as specified. Such tests are good at things like finding bad solder joints, pick-and-place mishaps, misconfiguration of firmware and weeding out product that fai…

In other words, most automated tests are regression tests.

Re: Making sense of the alleged Supermicro motherboard attack

#167
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

> It's hard for me to guess why the companies involved would deny that these exist.

My guess is that they know that everyone's confidence in them would crumble. Every business, ever household, everyone, would suddenly be aware that their data is not safe, even in the hands of the ones who say "trust us, we'll keep it safe".

Re: Making sense of the alleged Supermicro motherboard attack

#168

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

And if they were, you think they would admit it?

Re: Making sense of the alleged Supermicro motherboard attack

#169
post #71

Earlier quoted context omitted.

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Are you sure about that? I recall reading, in reference to canary clauses (https://en.wikipedia.org/wiki/Warrant_canary) that the government can and has required lying. If there's an ongoing national security concern, I would expect that they would.

Re: Making sense of the alleged Supermicro motherboard attack

#170

Earlier quoted context omitted.

Take a look at ASpeed (BMC supplier) stock movement: https://finance.yahoo.com/quote/5274.TWO/chart?p=5274.TWO

That movement seems to have started about two weeks ago. I don't think it's related to this news.

I'm sure it didn't help!
Post reply on HN