Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

291–300 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#291

Ok, that finally makes a bit of sense about "if" this is true, how it might be carried out. And I agree with the author that the simplest action for a chip on the SPI bus would be to hold the MISO line low during power on to suggest to the BMC chip that its QSPI flash isn't programmed (note that QSPI starts up as 'regular' SPI and then switches over[1]). I would guess that the next thing the BMC would do is assume it…

One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?

Two things help you here; SPI usage and CMOS I/O pins.

The SPI bus can be configured with shared master-in-slave-out(MISO)/master-out-slave-in(MOSI) lines since many SPI chips won't even drive the bus if their chip select line is not driven low. Thus the MISO and MOSI pins usually have a fair bit of buffering on them and will often be connected to the bus with a 1K resistor (either externally or built into the chip[1]). On a 5V system this limits the source current to 5mA. Either way these pins are designed to take some abuse.

Current drive is another issue because typically the output driver, if it isn't open drain, will use a p-type drive transistor which has a harder time passing current than an n-type transistor does. As a result the spec iOh (output current when the device is held high) is much lower than iOl (input current when the device pulls the pin low). So one pin to ground will overwhelm the output driver and pull the line effectively to a low state (not as low as it would if nobody was trying to pull it high, but low enough to read as 0). You will see this technique used in 'wired and' type circuits, where output pins are connected in common to a line, and any one going low will pull the bus low. If they are all logic 1 the bus is logic one, if one or more of them are logic 0 the bus reads logic zero.

[1] Yes I know that on "high speed" SPI ports this is not done because of the parasitic inductance in said resistor rounding out the edges of the data pulses with respect to the clock line thus reducing setup and hold time margins for accurate data transmission.

Re: Making sense of the alleged Supermicro motherboard attack

#292
post #87

Earlier quoted context omitted.

I think the attacks are real and if China is doing it then anyone else may be doing it as well including the US.

Anyone else literally can't because they don't have supply chain advantage that China has.

NSA intercepted routers to do pretty much the same kind of hack. https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

Re: Making sense of the alleged Supermicro motherboard attack

#293

Earlier quoted context omitted.

These days 20mA is a "high current" I/O. When you do the math on an 88-pin package, 20mA * N active outputs gets big pretty fast. The max total I/O current can be found somewhere around page 987 of the data sheet... don't stop reading early... :) (edit: 88 I/O is a modest size microcontroller sort of chip)

I don't understand how this is relevant to holding a single pin low.

it's even easier than the comment above suggests

Re: Making sense of the alleged Supermicro motherboard attack

#294
post #163

Earlier quoted context omitted.

Not only that, which base stations don't have Chinese components? But cpu, baseband, ram etc is certainly more serious consideration... And I don't see how you can get around that. Unless you plan to build a dumb phone around a Motorola 68k or something?

Ericsson for one.

Without components from China? Today?

Re: Making sense of the alleged Supermicro motherboard attack

#295
BMCs have always been an Achilles heel.

HP's iLo could be got into if you used `curl -H "Connection: AAAAAAAAAAAAAAAAAAAAAAAAAAAAA"`

Supermicro's horrid BMCs, of which there are many, all were horrendously lax in security, long before this chip was, or was not inserted. You didn't buy supermicro if you were worried about security, you bought them if you needed to stack stuff high, cheap and dense.

There is a reason why its best practice to put them on separate networks, with as much stuff between it and anyone else. BMCs are massive backdoors, and should be treated with caution.

Re: Making sense of the alleged Supermicro motherboard attack

#297
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

I think these attacks are theoretically real. I don't think these specific instances of the attack as described by Bloomberg are real. The only plausible scenario in which none of Bloomberg, Apple, and Amazon are knowingly lying is one in which only a select few employees at Apple/Amazon knew about this and were talking to the FBI, as you suggested. Except this doesn't make sense. The only way in which a select few e…

>How would it even be possible for the government to have determined that Apple and Amazon had their hardware compromised without Apple and Amazon's knowing cooperation?

By having a spy in Chinese intelligence who sells it, then doing inspection when hardware goes through customs.

Re: Making sense of the alleged Supermicro motherboard attack

#298
post #239

Earlier quoted context omitted.

I'm not sure where you're reading the Apple denial you're referring to, but this is *incredibly clear, detailed, and leaves no room to wiggle: "Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in l…

Those aren't clear at all. They're clear to you because you don't see the weasel wording. "Apple has never found [...]" So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.…

Are the courts not capable of dealing with silly word games?

Re: Making sense of the alleged Supermicro motherboard attack

#299
post #256

Earlier quoted context omitted.

No. But gag orders do not require the recipient to lie about it. Someone who is under a gag order simply doesn't comment one way or the other about it. FWIW this is the principle behind warrant canaries. A warrant canary is the practice of putting a statement such as "we have not received any NSLs" in a regular report, and then omitting it once you have received an NSL. Because you've conditioned people to expect its…

I'm pretty sure that this strategy won't hold up in court. If you have a sign that indicates that a secret event have not happened, the intent of removing the sign is to indicate that the secret event did happen. The intent is particularly obvious to the originator of the secret event, so you won't be able to argue in the court that it was entirely coincidental.

Warrant canaries have reasonable precedent in the US because of the First Amendment. See New York Times Co. v. United States.

This isn't true and they probably don't work in any other country in the world. They're explicitly illegal in Australia, apparently.

Re: Making sense of the alleged Supermicro motherboard attack

#300
post #256

Earlier quoted context omitted.

I'm pretty sure that this strategy won't hold up in court. If you have a sign that indicates that a secret event have not happened, the intent of removing the sign is to indicate that the secret event did happen. The intent is particularly obvious to the originator of the secret event, so you won't be able to argue in the court that it was entirely coincidental.

I agree. Could you have a canary community that calls companies once/quarter and specifically asks the NSL question? Seems safer for the companies themselves.

The legal system doesn't appreciate cleverness and you get negative points for trying. Either everything would work or nothing will.
Post reply on HN