Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

181–190 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#181

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Are you sure about that? I recall reading, in reference to canary clauses ( https://en.wikipedia.org/wiki/Warrant_canary ) that the government can and has required lying. If there's an ongoing national security concern, I would expect that they would.

The article you linked is primarily a disproof of your claim.

It cites some hearsay speculation that Warrant Canaries are illegal, and cites several court cases that say Warrant Canaries are protected and compelled lies are illegal: "West Virginia State Board of Education v. Barnette and Wooley v. Maynard rule the Free Speech Clause prohibits compelling someone to speak against one's wishes; this can easily be extended to prevent someone from being compelled to lie."

Re: Making sense of the alleged Supermicro motherboard attack

#182

There's a problem with exfiltrate via BMC network theory. In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection…

[deleted]

Re: Making sense of the alleged Supermicro motherboard attack

#183

Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.

Wouldn't be it possible to somehow hide a signature and instructions in legit MPEG payload? Think of video scaling service getting prepared video file with a binary pattern which once detected by hacked HW/FW would activate the hidden instructions and plant results in a response.

Re: Making sense of the alleged Supermicro motherboard attack

#184
post #172

A decade ago when I worked at Microsoft I shopped around the idea of using XBox as a basis for secure computing. XBox was designed to function in the hands of the adversary, to be robust against peripheral attacks and even motherboard mods. Even the main memory was encrypted by the on-CPU controller. Obviously, no open JTAGs. A lot of expertise there. In my fantasies it would form the basis of the DoD infrastructure…

Are you referring to the original Xbox? Modchips hit the scene for that in ~ 2 years after release. It's not exactly what I would consider a basis for secure computing. Or maybe you are just referencing the procedures "main memory was encrypted by the on-CPU controller. Obviously, no open JTAGs" should be ratified to create a basis for secure computing, a checklist of things to do/prevent before considering a device "Secure".

Re: Making sense of the alleged Supermicro motherboard attack

#185

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Apple cannot do anything bad to China or their manufacturing stops.

Apple would have to move tens of thousands of highly specific CNC machines from China to somewhere else, set them up, and get their line moving again.

This is why I find the idea that Apple phones are "secure" to laughable on its face. China could kill years of Apple revenue if they ever did something truly offensive to the ruling party.

Apple would roll over post haste if China demanded it.

Re: Making sense of the alleged Supermicro motherboard attack

#186
post #177
post #168

Earlier quoted context omitted.

And if they were, you think they would admit it?

They would not have blatantly lied about it in an official statement. That could not have passed legal.

Aren't they required to do so in the context of a NSL?

Re: Making sense of the alleged Supermicro motherboard attack

#187

Earlier quoted context omitted.

Especially if you: 1) happen to be country that makes all electronics 2) Company with a lot of ties to your country is happen to be top server supplier 3) Companies that use these servers happen to work for DoD, CIA and all major points of interest.

I wonder if China is making all these cheap wifi chips (esp8266, esp32) etc as backdoors into US infrastructure.

And how could you use esp chips as "backdoors"? Maybe espressif made them because they thought there is a good market for low-cost SoC with good network stack?

Re: Making sense of the alleged Supermicro motherboard attack

#188

Earlier quoted context omitted.

Especially if you: 1) happen to be country that makes all electronics 2) Company with a lot of ties to your country is happen to be top server supplier 3) Companies that use these servers happen to work for DoD, CIA and all major points of interest.

I wonder if China is making all these cheap wifi chips (esp8266, esp32) etc as backdoors into US infrastructure.

I hope esp8266 & so are not relevant enough to have a sofisticated backdoor built in.

Re: Making sense of the alleged Supermicro motherboard attack

#189
post #77

The fact that cursory examination finds the attack is not only entirely feasible, and completely undefended against, but that the hardware shown in the Bloomberg animation is precisely the hardware which would be required to pull off the attack is quite astonishing. Whose “law” is it that the closer you are to an event the more you can see that the reporting on the event is desperately flawed? This has almost always…

Or, it could be both.

It could have been a real attack vector that didn't actually infiltrate the companies in question due to having been caught upstream.

But as "attempted attack" sounds far less sexy than "actual attack," the sources may have exaggerated the impact/discovery to further trade negotiation objectives with the spin.

In fact, the BS discovery part of the story might be an attempt to parallel construct a reason it was discovered to cover for a program that might do independent testing of hardware which, if revealed, would give attackers some sense of sampling methodology to be able to counter.

That would explain the vehement denials from the companies allegedly compromised and yet the realistic attack vector published along with the US entity bans on using Chinese hardware around that time.

Post reply on HN