Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

131–140 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#131
post #111
post #96

Earlier quoted context omitted.

> Finally a named source, but [...] Indeed, insisting on evidence and reasoned argument is a good thing. > I'm now wondering if someone found an NSA implant and misreported it as Chinese. Sigh... If you don't know you don't know. You can't use uncertainty about the source of someone else's hyped conspiracy theory as evidence for your own nuttery. Stop it.

Who knows... but it is funny that healthy skepticism can transform into this kind of acceptance. First disbelief, then, well ok, maybe but if it is, it’s probably not the suspected entity, but an altogether different entity... it’s like multiplying probabilities but thinking it increases likelihood.

Conspiracy theories do love the combination of the whataboutism and the competitive debate strategy of "spreading" where you make lots of weak (or better yet, completely unsubstantiated) points, and if your opponent fails to refute everyone, you win.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#132

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

You would recognize what looks like an extra resistor?

The supposed infiltrated part is a six terminal RF device. Not something that would ordinarily show up on a server motherboard. In any case, Joe Fitzpatrick has already disclosed that he used the part merely as an example and Jordan Robertson expanded that into a work of fiction.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#133
post #106
post #26

Earlier quoted context omitted.

You could easily DoS obviously, but beyond that I agree that it seems tricky to do anything worthwhile.

It could just be a sort of beacon to help identify where hardware went after the manufacturing process. If the same company is building the same hardware, the agent can slip in something more nefarious to make sure they target the right company. Servers are commodity products but they aren't manufactured in mass quantities like phones are. If a company orders thousands of them, that's likely thousands that will need…

How would such a beacon work though? As RL_Quine points out there's only so much you can do at this point, especially if you want to be super stealthy. If you wanted to send a ping to an external server you'd have to craft an ethernet frame with the right target MAC address containing an IP datagram with the right IP address to be routed correctly in the datacenter and through the public firewall. You better make sure that your packet looks legit otherwise you're sure to trip anything looking for suspicious activity. "Hey look, our servers send weird packets to this suspicious IP, what gives?"

And you have to do all that with a very low power device running from within the port itself. Seems like a very high bar to me, especially when there seems to be so many easier ways to backdoor a motherboard.

But maybe the component is only hosted in the ethernet port but is actually connected to other signals on the motherboard.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#134
post #124

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

The cleared department is handled the same way as in the military in terms of security. Amazon has SCIF's etc. So unless a disgruntled employee steps forward who doesn't care about there life, I imagine its easily contained (and symptoms of an employee being disgruntled are highly monitored when they hold a clearance)

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#135
post #124

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

1) Everybody involved has agreed to keep secrets.

2) You compartmentalize everyone so nobody has the complete picture.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#136

Earlier quoted context omitted.

You would recognize what looks like an extra resistor?

The supposed infiltrated part is a six terminal RF device. Not something that would ordinarily show up on a server motherboard. In any case, Joe Fitzpatrick has already disclosed that he used the part merely as an example and Jordan Robertson expanded that into a work of fiction.

[deleted]

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#138
post #124

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

Very easily, that's how https://en.wikipedia.org/wiki/Alex_Stamos#Yahoo!

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#139
post #65

Earlier quoted context omitted.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

Wasn't PRISM all about attacking American companies with covert implants? For instance tapping into Google region to region data transfers, after which Google started encrypting everything.

I thought PRISM wasn't covert. Companies were compelled to allow them to install their sniffing hardware, it was all above-board. Snowden even leaked an internal slideshow with a nice timeline of when each tech company joined the program.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#140

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Same here. I have four different Supermicro motherboards purchased in May for servers in my home. I'm sure there exist people and organizations in the world capable of putting malicious hardware on one of these such that I can't detect them. But insofar as I've personally examined them and the available evidence from Bloomberg, color me skeptical...

Ok now try to patch the BMC, you can actually talk to it with openipmi on local host.
Post reply on HN