Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

141–150 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#141
post #65

Earlier quoted context omitted.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

Wasn't PRISM all about attacking American companies with covert implants? For instance tapping into Google region to region data transfers, after which Google started encrypting everything.

My understanding is that the google tapping was done in UK using British intelligence services, thus bypassing the legal constraints.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#142

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

The most compelling explanation I've heard is that the BMC chip could be programmed by two distinct flash chips, one for factory programming and one for some other purpose. In some SKUs, the latter isn't populated but it has a higher priority than the first chip. Since there are many flash chips fitting the same pin out, all it took was soldering a compromised flash chip (with firmware for the BMC chip) onto pads tha…

By explanation do you mean theory or is it coming from somebody who has special knowledge of the situation?

I'm not trying to be adversarial, even if it's only a theory it's an interesting one, but given the amount of conflicting information we have regarding this whole mess I think it's important to be clear about what's pure speculation and what's been reported by people supposedly in the know.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#143

Earlier quoted context omitted.

You would recognize what looks like an extra resistor?

The supposed infiltrated part is a six terminal RF device. Not something that would ordinarily show up on a server motherboard. In any case, Joe Fitzpatrick has already disclosed that he used the part merely as an example and Jordan Robertson expanded that into a work of fiction.

Where is the 6-terminal claim from?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#144
post #59
post #20

Earlier quoted context omitted.

If it's correct, it's highly likely that most cloud vendors are in the same boat. Imagine Google or AWS, who each have multiple millions of servers: even if they build their own motherboards, there are so many 3rd party components there's no way to vet all the boards. Their IDS will catch some, but not all. One might imagine a cloud vendor is constantly the target from multiple state actors, foreign and domestic, all…

I can't imagine the cost of x-ray-ing all motherboards on an AWS scale.

X-ray won't catch substitute chips: they will have the same package and same markings but a few extra functions on their silicon. Good luck eyeballing that one. I think you're right though: they should examine a sample of the boards at lest.

In addition--layering defense--one would imagine simply putting a motherboard on a quarantine LAN, simulating their production network, and watching its network traffic for phoning home.

The real implants might be waiting for a specific situation, like a date or a string on the bus, so you never really know if you got them all.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#145

Earlier quoted context omitted.

Wasn't PRISM all about attacking American companies with covert implants? For instance tapping into Google region to region data transfers, after which Google started encrypting everything.

I thought PRISM wasn't covert. Companies were compelled to allow them to install their sniffing hardware, it was all above-board. Snowden even leaked an internal slideshow with a nice timeline of when each tech company joined the program.

Parts of that whole expose were covert. In the case of Google we know by tapping fiber connections that they had between data centers (as sseth mentioned, using foreign intelligence peers to do an end run around legal protections), which was on Google owned fiber, theoretically entirely "in-house", so Google transferred it unencrypted. I believe they called this operation "Muscular". After the fiasco Google started assuming everything was hostile.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#147

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

>The US cannot force those companies to lie.

But they can. Maybe only in cases where silence is a canary, but that still sets a precedence for them being able to force you to lie.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#148

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

> the organizations that are denying it have no knowledge that it occurred

Are you saying that Steve Schmidt, the AWS chief infosec officer didn't know about the hack? Or that his article [0] was published to purposely hide it?

If only one person in Amazon knew about it, it would be Schmidt. And if Schmidt knew, I don't think he'd write an article so strongly claiming Amazon doesn't know anything about it. The only thing in my mind that lends credence to Schmidt covering it up purposely is that $10B contract the Pentagon is putting out- perhaps they've told him to play ball as part of getting the contract. But even then it seems a stretch.

[0]https://aws.amazon.com/blogs/security/setting-the-record-str...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#150

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

You have it backwards. The government can't force them to put out "no comment" press releases. They can force them not to reveal certain information. Maybe that means the only logical thing to do is to say "no comment", but it certainly doesn't prevent a company from commenting as long as they don't reveal the gagged info.
Post reply on HN