Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

31–40 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#31
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#33
post #25
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

>it's illegal to report an attack by US intelligence agencies Could you expand more on that?

IANAL, but New York Times Co. v. United States is a famous precedent for the first amendment protecting the press' right to publish classified government documents.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#34

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#35
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

> The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS....

Interesting. This one seems to rely on the presence of the USB connectors for powering. So, basically, any ethernet port with only Ethernet connectors should be safe from this kind of attack? The only powering option there should be PoE but I have yet to see someone buy PoE switches for a datacenter...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#37

Earlier quoted context omitted.

If Super Micro goes under and we discover this story was massively incorrect, can they sue for the lost market value? If so, this may cost bloomberg billions.

and if it is correct?

Then they’re screwed, because it was them who messed up and didn’t QA hard enough. We’ll see...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#38

Earlier quoted context omitted.

If Super Micro goes under and we discover this story was massively incorrect, can they sue for the lost market value? If so, this may cost bloomberg billions.

and if it is correct?

Following the first story it was reported that Amazon had already ditched Supermicro as a supplier.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#39
post #30
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

~

Just about anyone on Google's Project Zero team, off the top of my head. They would probably be both competent and enthusiastic.

Beyond that Apple, Microsoft, Tesla and probably Amazon have sufficiently capable public (or past public) researchers working for them. But I doubt many would want the publicity one way or the other.

Post reply on HN