Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

151–160 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#151
post #148

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

> the organizations that are denying it have no knowledge that it occurred Are you saying that Steve Schmidt, the AWS chief infosec officer didn't know about the hack? Or that his article [0] was published to purposely hide it? If only one person in Amazon knew about it, it would be Schmidt. And if Schmidt knew, I don't think he'd write an article so strongly claiming Amazon doesn't know anything about it. The only t…

https://en.wikipedia.org/wiki/Alex_Stamos#Yahoo!

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#152

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

What's the point of classifying national security threats?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#153
post #124

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

I knew a dozen people working on Amazon Go for like 4 years before it launched. Not one person leaked, even internally, what the hell they were building. Just that it was awesome and I should come join their team.

Somehow, Amazon is really good at keeping secrets.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#154
post #107

Earlier quoted context omitted.

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

But they probably can force a handful of engineers to tell nothing to their employer, who would be vehemently denying in good faith.

How would the government get in contact with the engineers who discovered the hack without going through their managers, the CISO, etc. ?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#155
post #124

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

If it is classified and a cleared employee at Amazon/Apple/etc. blabbled there would be life altering consequences for them.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#156
post #44

Earlier quoted context omitted.

> The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud. Would the US government have to force these companies to lie? It's quite possible that the denials were the result of voluntary cooperation.

A public company issuing such strongly-worded denials that turn out to be untrue would be leaving themselves at risk of an investigation by the SEC and/or a shareholder lawsuit.

It would be pretty extraordinary for the government to sue a company for cooperating with the government.

A company has to follow court orders. The government would have to sue itself.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#158
post #148

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

> the organizations that are denying it have no knowledge that it occurred Are you saying that Steve Schmidt, the AWS chief infosec officer didn't know about the hack? Or that his article [0] was published to purposely hide it? If only one person in Amazon knew about it, it would be Schmidt. And if Schmidt knew, I don't think he'd write an article so strongly claiming Amazon doesn't know anything about it. The only t…

It's very possible Steve wouldn't know, both owing to past precedent (see SmokeyJ's comment on Alex Stamos) and owing to whether or not he's cleared.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#159
post #79

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

My take on this is that it's been fairly obvious for a long time that these kinds of attacks are possible (if not easy) with today's technology. One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. So why is this suddenly breaking news? It bears resemblance to most of the propaganda stories we have seen in rec…

POTUS has also explicitly stated China is meddling in the 2018 election, against him and Republicans, and assigned a motive.

“They do not want me or us to win because I am the first president ever to challenge China on trade,”

And converse to the calm of China, he is impulsive and has floated the idea of selective defaults on Treasury securities. And he has ample experience with this himself. It is in the realm of ridiculous conspiracy theories, but POTUS is a walking pile of ridiculous conspiracies theories, so why is defaulting on only Chinese owned securities more ridiculous than nuking Pyongyong? (Of course, only one of those can actually be contained.)

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#160

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

The most compelling explanation I've heard is that the BMC chip could be programmed by two distinct flash chips, one for factory programming and one for some other purpose. In some SKUs, the latter isn't populated but it has a higher priority than the first chip. Since there are many flash chips fitting the same pin out, all it took was soldering a compromised flash chip (with firmware for the BMC chip) onto pads tha…

The BMCs on the newest Supermicro servers are from ASPEED. The X10 models have the AST2400 [0] and the X11 models have the AST2500 [1]. They have ARM CPUs and run, basically, an embedded Linux.

If you wanted to "backdoor" motherboards that shipped with these BMCs, wouldn't it would be much easier to just install your own "customized" version of the firmware on them? It certainly seems that it'd be much more difficult to incorporate another device into the system.

[0]: https://www.aspeedtech.com/products.php?fPath=20&rId=376

[1]: https://www.aspeedtech.com/products.php?fPath=20&rId=440

Post reply on HN