Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

11–20 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#11

They don’t say what the hack was and definitely do not say it was one of their pins. Probably some truth here, but as hard as they try, does not seem supportive of their “chinese pin” theory. Very suspicious that this is related, I’m guessing they’re trying to do anything to cover their asses.

This seems different than the extra chip attack according to the article. "subsequent physical inspection revealed an implant built into the server’s Ethernet connector"

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#13
post #4

This saga is fascinating I really have no doubt of the hardware existing. Thought the original picture from the article and description made it hard for me to imagine the connectivity. is it connected to the SPI of the BMC flash/OS storage? Why would software integrity checks like making sure the image is signed and not tampered wouldn't capture it? (Answer to this one sounds easy bad security practices regarding fir…

This article talks about something elsewhere entirely than the original one, and unrelated to the BMC.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#15
Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher.

The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS...

I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid situation where people are afraid to report foreign intelligence attacks because it's illegal to report an attack by US intelligence agencies, aren't we?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#16
post #9

They don’t say what the hack was and definitely do not say it was one of their pins. Probably some truth here, but as hard as they try, does not seem supportive of their “chinese pin” theory. Very suspicious that this is related, I’m guessing they’re trying to do anything to cover their asses.

Sounds like the Ethernet connector module was not from the, ahem, correct manufacturer: “Appleboum said one key sign of the implant is that the manipulated Ethernet connector has metal sides instead of the usual plastic ones. The metal is necessary to diffuse heat from the chip hidden inside, which acts like a mini computer. "The module looks really innocent, high quality and 'original' but it was added as part of a…

I'm not sure I believe this one as much, just based on the part you quoted. I can see a chip manipulating the BMC/IPMI flash to make it do things it shouldn't. I don't see how an ethernet port could be modified to be interesting. They're typically after the magnetics, or contain the magnetics themselves, so the only source of power would be the activity LEDs, or something, or maybe we assume a custom PCB as well. You've then also got to have it doing gigabit ethernet, or otherwise tampering with data it got from that interface, which feels unlikely. Maybe it's just the same as the last implant story, hidden in a less easy to find place? Hard to know without something even approaching technical information.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#19
That story is a bit odd, still -- normally behind the connector there is optionally magnetics, and at least a PHY... being able to integrate the magnetics in the connector exists allright, but adding the phy /as well/ must make it a marvel of integration regular manufacturers would dream of... especially at Gb speed!

Also, you can't really 'piggyback' ethernet easily, for the same reasons; you would need TWO phy in there to decode/reencode...

Even if you'd want to 'piggyback' on the link itself, it would be very, very difficult to say the least -- Gb ethernet is definitely not a gimme to synthesise, let alone piggyback.

So, color me dubious -- the SPI 'chip' of last week was a but dubious but doable (given not just a custom chip, but a custom PCB) but this ethernet story makes even less sense!

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#20

Earlier quoted context omitted.

If Super Micro goes under and we discover this story was massively incorrect, can they sue for the lost market value? If so, this may cost bloomberg billions.

and if it is correct?

If it's correct, it's highly likely that most cloud vendors are in the same boat. Imagine Google or AWS, who each have multiple millions of servers: even if they build their own motherboards, there are so many 3rd party components there's no way to vet all the boards. Their IDS will catch some, but not all.

One might imagine a cloud vendor is constantly the target from multiple state actors, foreign and domestic, all vying for universal access.

Post reply on HN