Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

271–280 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#271

Ok, that finally makes a bit of sense about "if" this is true, how it might be carried out. And I agree with the author that the simplest action for a chip on the SPI bus would be to hold the MISO line low during power on to suggest to the BMC chip that its QSPI flash isn't programmed (note that QSPI starts up as 'regular' SPI and then switches over[1]). I would guess that the next thing the BMC would do is assume it…

One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?

It's not like the MISO line is tied to a power rail. You just need to sink more current than the output of the chip you are trying to override. So the driver is likely in the single digit milliamp range, and in any case, you don't care if you toast the output driver on that chip. In fact, if you do, bonus!

Re: Making sense of the alleged Supermicro motherboard attack

#272

Earlier quoted context omitted.

One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?

"Lots of current" in this case would only be about 20mA, generating heat that you can easily dissipate from just the surface of a 0201 resistor. I doubt many microprocessors have pins that can drive higher current than that. Realistically, in order to drive it low you don't have to bring it down to 0V. Most 5V chips will stop registering logic high around 2.5-3.3V for example.

These days 20mA is a "high current" I/O. When you do the math on an 88-pin package, 20mA * N active outputs gets big pretty fast. The max total I/O current can be found somewhere around page 987 of the data sheet... don't stop reading early... :)

(edit: 88 I/O is a modest size microcontroller sort of chip)

Re: Making sense of the alleged Supermicro motherboard attack

#273

Earlier quoted context omitted.

Could they say if they were?

No. But gag orders do not require the recipient to lie about it. Someone who is under a gag order simply doesn't comment one way or the other about it. FWIW this is the principle behind warrant canaries. A warrant canary is the practice of putting a statement such as "we have not received any NSLs" in a regular report, and then omitting it once you have received an NSL. Because you've conditioned people to expect its…

What happens when you're legally obligated to comment? Like, if you receive an NSL about something, and then later are subpoenaed/compelled to testify before a grand jury or judicial inquest about that same thing?

Neither grand juries nor coroners "outrank" the Executive (unlike Congress, who I would assume can just throw out the NSL to get testimony, since they have similar powers, like throwing out a document's top-secret classified status to get it read into the public record.) But in both situations, you can still be found in contempt of court if you just say "no comment."

Re: Making sense of the alleged Supermicro motherboard attack

#274
post #71
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

The press release specifically said that they are not under any sort of order preventing any disclosure.

And while it is indeed possible for the government to make you stay quiet, forcing you to lie is considered compelled speech, which is a fundamental aspect of current thinking on the 1st Amendment, and not something that is likely to change. No, not even when a three-letter agency wants it.

Also nobody at the either the NSA nor Apple cares about the sort of everyday world news you're mentioning. Maybe lay of the Tom Clancy for a while?

Re: Making sense of the alleged Supermicro motherboard attack

#275

Earlier quoted context omitted.

According to this comment, the BMC is at least capable of working off the real NIC instead, and will do so if you don't hook up the management NIC. https://news.ycombinator.com/item?id=18138411

This is a BIOS setting, and even while the BMC's working over the primary NIC, it retains its independent MAC and IP address (and VLAN if you set it up). Also, even if the NIC is shared with the BMC and the OS, you cannot see the NIC of the BMC on the PCI bus. They are isolated at the hardware level. I manage lots of these servers for a long time, and this is my firsthand experience. :)

The BMC using the correct MAC and IP address is entirely down to the honesty of the software running on the BMC.

Re: Making sense of the alleged Supermicro motherboard attack

#276
post #239

Earlier quoted context omitted.

I'm not sure where you're reading the Apple denial you're referring to, but this is *incredibly clear, detailed, and leaves no room to wiggle: "Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in l…

Those aren't clear at all. They're clear to you because you don't see the weasel wording. "Apple has never found [...]" So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.…

> So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.

You’re making up new assertions from whole cloth - the original story claimed Apple found the chips then alerted the FBI. Apple explicitly and clearly denies every single aspect of the BW/Bloomberg story, and your objection to their denial is that they didn’t deny actions never presented in the article?

That’s called a straw man, and it doesn’t pass muster...

Re: Making sense of the alleged Supermicro motherboard attack

#277

Earlier quoted context omitted.

One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?

It's not like the MISO line is tied to a power rail. You just need to sink more current than the output of the chip you are trying to override. So the driver is likely in the single digit milliamp range, and in any case, you don't care if you toast the output driver on that chip. In fact, if you do, bonus!

Ok, but i suppose that in the future chip output pads can have circuitry which can detect a forced output (by measuring current). When this happens, the chip could short-circuit power lines, or superimpose a signal on the power-lines to notify the rest of the system.

Re: Making sense of the alleged Supermicro motherboard attack

#278
post #191
post #154

Earlier quoted context omitted.

What’s the difference if that open source risc is manufactured in the same Chinese plant?

More likely a fab in Taiwan than China. You can run your RISC-V cores on an FPGA if you’re really paranoid. Of course, you’d be sacrificing performance.

every FPGA is far more closed and secretive about its internals than Intel ever has been about its CPUs.

Re: Making sense of the alleged Supermicro motherboard attack

#279
post #77

The fact that cursory examination finds the attack is not only entirely feasible, and completely undefended against, but that the hardware shown in the Bloomberg animation is precisely the hardware which would be required to pull off the attack is quite astonishing. Whose “law” is it that the closer you are to an event the more you can see that the reporting on the event is desperately flawed? This has almost always…

> Whose “law” is it that the closer you are to an event the more you can see that the reporting on the event is desperately flawed?

idk, but this description of Gell-Mann amnesia seems to touch on that idea

https://en.wikipedia.org/wiki/Gell-Mann_amnesia_effect

Re: Making sense of the alleged Supermicro motherboard attack

#280
post #77

The fact that cursory examination finds the attack is not only entirely feasible, and completely undefended against, but that the hardware shown in the Bloomberg animation is precisely the hardware which would be required to pull off the attack is quite astonishing. Whose “law” is it that the closer you are to an event the more you can see that the reporting on the event is desperately flawed? This has almost always…

> ...a middle-manager plant intercepted the message as it went up the line...

maybe such a manager would, by doing that in this case, be protecting the top level execs

Post reply on HN