Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

41–50 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#41

That story is a bit odd, still -- normally behind the connector there is optionally magnetics, and at least a PHY... being able to integrate the magnetics in the connector exists allright, but adding the phy /as well/ must make it a marvel of integration regular manufacturers would dream of... especially at Gb speed! Also, you can't really 'piggyback' ethernet easily, for the same reasons; you would need TWO phy in t…

Elsewhere in this thread there is an actual link to an actual NSA device that does exactly this. I don't think it's in the realm of science fiction.

If you look at that illustration, you see that it's not just one ethernet connector, it's one of these massive connector stack with one ethernet and 2 USB, also, it adds quite a bit of depth to the connector; it must have been made with one particular brand/type of motherboard in mind.

Still, if these are in the wild, then perhaps our chinese friends might have reduced the footprint even more to the size of one connector.

I know the connectors with integrated magnetics are quite a bit 'longer' and 'beefier' than the passive ones.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#42
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#44

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

> The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

Would the US government have to force these companies to lie? It's quite possible that the denials were the result of voluntary cooperation.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#45
post #18

It may soon be that the only companies who can sell hardware outside of their own country are those who sell Open Source Hardware which can be 100% verified as true to its published design.

> It may soon be that the only companies who can sell hardware outside of their own country are those who sell Open Source Hardware which can be 100% verified as true to its published design.

That would be a very, very good outcome, IMHO. Use espionage fears to push forward other objectives, like open source.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#46
post #4

This saga is fascinating I really have no doubt of the hardware existing. Thought the original picture from the article and description made it hard for me to imagine the connectivity. is it connected to the SPI of the BMC flash/OS storage? Why would software integrity checks like making sure the image is signed and not tampered wouldn't capture it? (Answer to this one sounds easy bad security practices regarding fir…

This article talks about something elsewhere entirely than the original one, and unrelated to the BMC.

Yes I read it. seems they added another device to the network/ethernet interface which they detected sending network packets.

Curious how this one affected the server or did compare to the original article.

This one seems more benign considering it won't be able to mess around like the BMC has access to things like secure boot and other system busses like the PCI.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#47
Set aside whether this report is reliable or not, I don't see how something like the Digi Connect ME:

https://www.digi.com/products/embedded-systems/system-on-mod...

or the 9210 version:

https://www.digi.com/products/embedded-systems/system-on-mod...

cannot exist in Gb speed, if I recall correctly the original Digi Connect came out in 2005 or so.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#48
post #8

OK so this is a different hack than Bloomberg reported before: ethernet jack piggyback instead of bmc. I'm not sure this adds credibility to the allegations in the other story. The details that Bloomberg related previously are so different that this couldnt be what they originally were reporting on. This adds to the China hacking server board narrative, but it does nothing to prove the Bloomberg reporting actually tr…

Read it more carefully. The ethernet jack is a tactic used by US intelligence years ago. That was mentioned in the story to explain the history of supply chain attacks.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#50

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

> The US cannot force those companies to lie

That's a nice government tender you're working on, looks very profitable! Would be a shame if someone rejected it because reasons.

While it isn't the direct influence described i imagine this scenario is highly effective and getting companies to stay in line.

Post reply on HN