Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

201–210 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#201

Earlier quoted context omitted.

I wonder if China is making all these cheap wifi chips (esp8266, esp32) etc as backdoors into US infrastructure.

I hope esp8266 & so are not relevant enough to have a sofisticated backdoor built in.

It seems likely that the esp8266 chip family is being used in industrial automation. It's a very powerful yet cheap chip, making it practically ideal for adding covert spyware. I love it, yet it scares me. It's a little too amazing.

Re: Making sense of the alleged Supermicro motherboard attack

#202
post #185

Earlier quoted context omitted.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Apple cannot do anything bad to China or their manufacturing stops. Apple would have to move tens of thousands of highly specific CNC machines from China to somewhere else, set them up, and get their line moving again. This is why I find the idea that Apple phones are "secure" to laughable on its face. China could kill years of Apple revenue if they ever did something truly offensive to the ruling party. Apple would…

Right, it's worth remembering that Apple deals with lawsuits all the time. All costs and benefits considered, it's probably the best option for them to lie about this for now, and plausible deniability is always a possibility ("at the time of writing, Apple PR were not aware of x, y and z"). The cost of losing access to the gigantic China market and its manufacturing operations would be much too great.

Re: Making sense of the alleged Supermicro motherboard attack

#203
post #185

Earlier quoted context omitted.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Apple cannot do anything bad to China or their manufacturing stops. Apple would have to move tens of thousands of highly specific CNC machines from China to somewhere else, set them up, and get their line moving again. This is why I find the idea that Apple phones are "secure" to laughable on its face. China could kill years of Apple revenue if they ever did something truly offensive to the ruling party. Apple would…

You could move every CNC machine from the manufacturing line and it would not matter.

These sneaky chips were embedded in the PCB. So this is a supplier trust issue.

Plus they probably did not implant every board, So somebody inside FoxConn had to slip in these 'special' pcb's in known Apple mobo orders..

Re: Making sense of the alleged Supermicro motherboard attack

#204

Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.

> Why wouldn’t a company notice any of the outbound traffic using firewalls?

IIRC the original story mentioned en passant that at least one company detected some odd behaviour on the network, which eventually resulted in hw examination and the uncovering of these moles. TBH, that part is immaterial: it might well be some parallel construction to avoid giving away NSA intel capabilities.

> Where did all the boards in question go?

Warehouse 51 [1] of course.

https://media1.fdncms.com/chicago/imager/best-approximation-...

Re: Making sense of the alleged Supermicro motherboard attack

#205
post #185

Earlier quoted context omitted.

Apple cannot do anything bad to China or their manufacturing stops. Apple would have to move tens of thousands of highly specific CNC machines from China to somewhere else, set them up, and get their line moving again. This is why I find the idea that Apple phones are "secure" to laughable on its face. China could kill years of Apple revenue if they ever did something truly offensive to the ruling party. Apple would…

China could cause huge harm to Apple, but the reverse is also true - how would the US government, other corporations, consumers and investors react to such a news? The ultimate source of most Chinese factory equipment is Europe and US anyway, under extreme political/consumer pressure electronics factories can be setup in a matter of months in US.

Not just the factories. Access to the market.

Re: Making sense of the alleged Supermicro motherboard attack

#206

Earlier quoted context omitted.

Thank you for the insight. I was rather naively imagining that every board is subject to some kind of x-ray image matching with the original PCB design to find differences. Not that simple, I see.

It's not uncommon at all to do AOI on all or a percentage of the PCBs. X-ray is more useful to identify solder issues or defects in the raw PCB itself.

Exactly. I've never seen x-ray used post SMT. We've used it to post-mortemly debug BGA issues.

Re: Making sense of the alleged Supermicro motherboard attack

#207
post #185

Earlier quoted context omitted.

Apple cannot do anything bad to China or their manufacturing stops. Apple would have to move tens of thousands of highly specific CNC machines from China to somewhere else, set them up, and get their line moving again. This is why I find the idea that Apple phones are "secure" to laughable on its face. China could kill years of Apple revenue if they ever did something truly offensive to the ruling party. Apple would…

China could cause huge harm to Apple, but the reverse is also true - how would the US government, other corporations, consumers and investors react to such a news? The ultimate source of most Chinese factory equipment is Europe and US anyway, under extreme political/consumer pressure electronics factories can be setup in a matter of months in US.

> China could cause huge harm to Apple, but the reverse is also true - how would the US government, other corporations, consumers and investors react to such a news?

They would react as usual: lots of whingeing, no action, and roll over for a belly scratch afterward.

> under extreme political/consumer pressure electronics factories can be setup in a matter of months in US.

It takes 9 months to make a baby no matter how many women you get pregnant ...

Many of these equipment manufacturers have entire facilities dedicated to producing equipment solely for Apple. They simply cannot replace that amount of equipment in any timely fashion.

Edit (external reference): http://www.iphonehacks.com/2016/10/next-iphone-probably-wont....

> Koenig writes. “Apple is such a huge buyer of a particular kind of mill (BT30 spindle drill-tap centers) that Fanuc, Brother and DMG Mori each have factories dedicated to building machines exclusively for Apple.”

Re: Making sense of the alleged Supermicro motherboard attack

#208

There's a problem with exfiltrate via BMC network theory. In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection…

According to this comment, the BMC is at least capable of working off the real NIC instead, and will do so if you don't hook up the management NIC. https://news.ycombinator.com/item?id=18138411

Re: Making sense of the alleged Supermicro motherboard attack

#209

There's a problem with exfiltrate via BMC network theory. In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection…

According to this comment, the BMC is at least capable of working off the real NIC instead, and will do so if you don't hook up the management NIC. https://news.ycombinator.com/item?id=18138411

This is a BIOS setting, and even while the BMC's working over the primary NIC, it retains its independent MAC and IP address (and VLAN if you set it up). Also, even if the NIC is shared with the BMC and the OS, you cannot see the NIC of the BMC on the PCI bus. They are isolated at the hardware level.

I manage lots of these servers for a long time, and this is my firsthand experience. :)

Re: Making sense of the alleged Supermicro motherboard attack

#210

There's a problem with exfiltrate via BMC network theory. In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection…

If the BMC has write access to host memory it could surely use that access to create a side channel using the host's network interfaces.

Having said that, it would be nice if networks were segmented in the way you describe. I've been appalled at the lack of segmentation I've seen in companies of all sizes that I've had gigs for.

Post reply on HN