Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

91–100 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#91
post #57

Could be due to losses in "translation", but this paragraph seems odd: > Three security experts who have analyzed foreign hardware implants for the U.S. Department of Defense confirmed that the way Sepio's software detected the implant is sound. One of the few ways to identify suspicious hardware is by looking at the lowest levels of network traffic. Those include not only normal network transmissions, but also analo…

If both are going over the same physical interface, there could be tiny voltage drops to power the chip itself. The vague-as-ever article gives no indication as to how the chip would be powered, but such a small implant could conceivably leech off the legitimate ethernet interface.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#92

Earlier quoted context omitted.

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

But if the story was entirely false, they'd have sued Bloomberg for libel already.

That might still be in the works, legal process moves slowly. If we don't hear anything in another week or so, this could be worth considering.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#93

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

or 3) Bloomberg is vaguely correct, but wrong in the specifics, including naming Apple and Amazon.

I.e., They get credible reports of SuperMicro servers having been compromised, they know that Apple and Amazon are customers. They find 1 over eager source willing to say Apple and or Amazon received compromised servers.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#94

So does it really matter if it's true or not? Isn't the sane response to assume it's all true and verify your system integrity? Even if you find nothing you would then have a pile of strong evidence for the null case, eh?

You've got to be kidding. There's no way of validating anything about modern hardware, it's packed with independent systems running various firmware, software that's decades old, parts nobody can even identify unless you're the OEM. You can get to "that probably does this" level easily, but that doesn't tell you anything about its actual security or authenticity.

Funny you should say that... Guess what I'm working on, go on, guess. :-D

And don't call me kidding. ;-P

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#95
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

My understanding is that certain parts on the PCB were swapped out for malicous parts. If that's the case, it's probably not something that could be uncovered by a purley visual inspection. The 'spy' chips were likely made to look identical to the original parts.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#96
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

> Finally a named source, but [...]

Indeed, insisting on evidence and reasoned argument is a good thing.

> I'm now wondering if someone found an NSA implant and misreported it as Chinese.

Sigh...

If you don't know you don't know. You can't use uncertainty about the source of someone else's hyped conspiracy theory as evidence for your own nuttery. Stop it.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#97
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

> The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... . Interesting. This one seems to rely on the presence of the USB connectors for powering. So, basically, any ethernet port with only Ethernet connectors should be safe from this kind of attack? The only powering option there should be PoE but I ha…

"any ethernet port with only Ethernet connectors should be safe from this kind of attack? "

I know that some IPMI implementations can control/use the on board ethernet. There might be some hole there. Similar for the built in management on some Intel processors and nics.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#98

If Bloomberg's reporting is/was, in fact, entirely false then why wouldn't Amazon/Apple/Supermicro immediately sue them for libel/defamation?

In the U.S., there is a very high bar to accuse defamation. You not only need to prove the report is false, you also need to prove the reporter knew it was false and had bad intention to cause damage.

That's defamation, but not libel. For clearing libel, all you have to prove is that the statement was presented as fact, was false, and caused harm.

From my lay understanding, Supermicro has a slam dunk case given the impact on their stock price.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#99
post #57

Could be due to losses in "translation", but this paragraph seems odd: > Three security experts who have analyzed foreign hardware implants for the U.S. Department of Defense confirmed that the way Sepio's software detected the implant is sound. One of the few ways to identify suspicious hardware is by looking at the lowest levels of network traffic. Those include not only normal network transmissions, but also analo…

My consumer board exposes that information. There is a tab called system information with hardly readable text which lists all voltages etc by component

I've never actually checked in the bios of any server, as that information was never relevant to me, but they probably have that as well

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#100
post #21

So it is a compromised ethernet adapter. Nobody question the ability of Chinese spies to plant such a thing, but the "Big Hack" story implies that this is used as a mass infiltration tool, which I still find very improbable and lacks any evidence.

The way I interpret it is: since it's being introduced at the manufacturing plant, those installing the devices have no idea where the finished product will end up. Thus, these are not targetted attacks; they could wind up in the servers of a Fortune 500 company, or just as easily in some hobbyist's home lab. You'd need to compromise a large percentage of the products to increase the chances of landing a juicy target. The scattergun manner is what they're playing up here.
Post reply on HN