Making sense of the alleged Supermicro motherboard attack
161–170 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#162Earlier quoted context omitted.
It's just my opinion, and so I held off saying, yesterday, but: The immediate economic outfall (co-morbid with institutional panic) would be so severe that this aspect alone would represent a national security issue.
Supermicro stock dipped down to 50 % or so (20->10).
https://www.marketwatch.com/story/super-micros-stock-set-to-...
Re: Making sense of the alleged Supermicro motherboard attack
#163Earlier quoted context omitted.
No more Chinese phones for me either way. It's enough that Google knows everything about me, PLA doesn't have to.
What phones do not have Chinese components?
But cpu, baseband, ram etc is certainly more serious consideration... And I don't see how you can get around that. Unless you plan to build a dumb phone around a Motorola 68k or something?
Re: Making sense of the alleged Supermicro motherboard attack
#164Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
If you deploy several thousand of those backdoor chips, you wouldn't set them up to ping your C&C infrastructure all on its own. Rather, you'd use a magic string as a trigger to activate the backdoor in some few targets to reduce the chance of the outbound traffic being detected.
Re: Making sense of the alleged Supermicro motherboard attack
#165In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection to outside, no unknown traffic, just silence. Only exception may be the discovery packets of some BMCs, which can find similar servers and form federations for easier management. Even this needs some setup beforehand.
Re: Making sense of the alleged Supermicro motherboard attack
#166It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…
> ... high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. MFG test guy here (not supermicro!) Not necessarily. Automated production tests are there to configure and exercise the system and confirm it works as specified. Such tests are good at things like finding bad solder joints, pick-and-place mishaps, misconfiguration of firmware and weeding out product that fai…
Re: Making sense of the alleged Supermicro motherboard attack
#167I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…
My guess is that they know that everyone's confidence in them would crumble. Every business, ever household, everyone, would suddenly be aware that their data is not safe, even in the hands of the ones who say "trust us, we'll keep it safe".
Re: Making sense of the alleged Supermicro motherboard attack
#168Earlier quoted context omitted.
If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.
Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.
Re: Making sense of the alleged Supermicro motherboard attack
#169Earlier quoted context omitted.
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.