Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

211–220 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#211
post #94

Earlier quoted context omitted.

> Why wouldn’t a company notice any of the outbound traffic using firewalls? This is telling you that your experience is limited, not that the story is wrong. Trying to do egress filtering at scale is extremely hard for all but the most basic threats. If they open a socket to data-collector.pla.cn, yes, probably a majority of large shops would notice that within a few months but what if it's just a connection to S3/E…

General practice for things like BMC and other out of band control systems is to put them on isolated vlans and default deny any non-approved traffic. There is no way that any large tech company security operation misses this traffic phoning home from a management vlan.

That's true but right now I can think of at least three options where that wouldn't be relevant:

1. The implant can use the host network interface before the host OS starts 2. The implementation depends on VLAN tagging and the implant simply uses configures its network interface to use the same tag as the host interface 3. The implant can compromise the host OS when it loads and use its networking stack after it loads

Re: Making sense of the alleged Supermicro motherboard attack

#212
post #119
post #112

Earlier quoted context omitted.

Now you have a second device to buy, secure and support, and it can't do everything that an ILOM can (most importantly, remote power management). Having had security updates for KVMs, I'm also not sure your assumption that it's safer is true in any meaningful sense. Management engine vulnerabilities have gotten a lot of hype over the last year or two but most of it has been marketing for security companies rather tha…

For many BMCs the second network port is a figment of your imagination. The BMC is capable of intercepting and injecting network frames on the host's interfaces. Just because you have the management port wired to a different VLAN or even a separate physical LAN means nothing.

It's true that many BMCs use the same physical network interface but that doesn't help an attacker hit it with a remote exploit. It could be relevant in the question of what could be done after compromise but for preventing that initial attack it's pretty effective.

Re: Making sense of the alleged Supermicro motherboard attack

#213
post #71
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

not being allowed to admit it due to national security reasons

Came here to say this. When I read Amazon’s rebuttal my gut said “what if these folks had to respond but weren’t allowed to tell the truth?”. If the allegations went unanswered it could be damaging to Amazon and tip the hand of the spooks. If they answered and said they did find the devices the story could run away from them, the internet mob is good at writing articles with “problematic” in the title.

Still I think this was a calculated leak. Why? Probably to put pressure on China in negotiations.

Re: Making sense of the alleged Supermicro motherboard attack

#214
post #87

Earlier quoted context omitted.

I think the attacks are real and if China is doing it then anyone else may be doing it as well including the US.

Anyone else literally can't because they don't have supply chain advantage that China has.

But can't they take advantage of the vulnerability created by the chips, without caring about who put them there?

Re: Making sense of the alleged Supermicro motherboard attack

#215

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Could they say if they were?

Re: Making sense of the alleged Supermicro motherboard attack

#216

Earlier quoted context omitted.

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

I wonder if there isn't some level of national security super mega secret scenario situation where the government requires companies to do something and the government indemnifies them against all risks associated with the required action.

I would be highly surprised if this wasn’t the case.

Re: Making sense of the alleged Supermicro motherboard attack

#217

There's a problem with exfiltrate via BMC network theory. In a sane setup, your BMC connection cannot access internet. You should build an isolated intranet for it (including VLAN or hardware isolation, not just subnet/IP), and put a VPN in the front gate. As a result, you login to your data center, or go to there if you like metaphors. If nobody’s there via VPN, BMC network is a silent and dark place. No connection…

If the BMC has write access to host memory it could surely use that access to create a side channel using the host's network interfaces. Having said that, it would be nice if networks were segmented in the way you describe. I've been appalled at the lack of segmentation I've seen in companies of all sizes that I've had gigs for.

Today's network cards are small computers of their own. So it'd be very hard to inject packages with all this kernel-hardware integration at the module level IMHO. The card would probably throw a tantrum if you try to access it directly.

TBH, while I'm knowledgeable about hardware, I'm a total beginner in attack side of cybersecurity.

At least, we are segmenting our networks like that.

Re: Making sense of the alleged Supermicro motherboard attack

#218

Earlier quoted context omitted.

Supermicro stock dipped down to 50 % or so (20->10).

Supermicro has been dealing with some accounting irregularities for the last year or so. This news certainly hasn't helped , but they were already in a shaky position. https://www.marketwatch.com/story/super-micros-stock-set-to-...

Or that’s a cover story for the dismantling of the spy operation.

Re: Making sense of the alleged Supermicro motherboard attack

#219
post #157

Earlier quoted context omitted.

It's not that you get one chance to do something like this, it's that there is one total chance to do something like this. After it's been discovered, it's much harder to do it again for everyone - so if you never do it, then you don't get the benefit and Russia or USA or someone else does that and gets the benefit and you still lose the ability to do it in the future.

The second generation chips mentioned in the Bloomberg article were fitted inside the plastic of the motherboard. I don't think it's a stretch to imagine that such chips might be really difficult to spot. And if they aren't the natural next step for a nation state is to build an xx billion dollar fab factory and produce smd "resistors" that contain one of these chips. I think the real trick is a real covert channel t…

[deleted]

Re: Making sense of the alleged Supermicro motherboard attack

#220
post #187

Earlier quoted context omitted.

I wonder if China is making all these cheap wifi chips (esp8266, esp32) etc as backdoors into US infrastructure.

And how could you use esp chips as "backdoors"? Maybe espressif made them because they thought there is a good market for low-cost SoC with good network stack?

I hope that is the case; the pessimist in me says the price/performance is too good to be true.
Post reply on HN