Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

161–170 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#161

Earlier quoted context omitted.

The supposed infiltrated part is a six terminal RF device. Not something that would ordinarily show up on a server motherboard. In any case, Joe Fitzpatrick has already disclosed that he used the part merely as an example and Jordan Robertson expanded that into a work of fiction.

Where is the 6-terminal claim from?

The original Bloomberg article features images of a 6-terminal chip.

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/i0hZ31udMZ_...

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/i9VdsjZLS_P...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#162

Earlier quoted context omitted.

Elsewhere in this thread there is an actual link to an actual NSA device that does exactly this. I don't think it's in the realm of science fiction.

If you look at that illustration, you see that it's not just one ethernet connector, it's one of these massive connector stack with one ethernet and 2 USB, also, it adds quite a bit of depth to the connector; it must have been made with one particular brand/type of motherboard in mind. Still, if these are in the wild, then perhaps our chinese friends might have reduced the footprint even more to the size of one conne…

And you don't think such a device could be made quite a bit smaller today, with better manufacturing support?

I'm thinking it's entirely plausible that such devices exist, and are broadly in the wild. Mostly targeted. That said, our own govt (US) is not innocent. Neither are China, Russia and many others. It's what government espionage actors do.

I think it's a fault of many that US mfg has fallen off as much as it has, and that critical infrastructure would allow foreign mfg in general. Or at least final inspection and assembly internally. Not just the US, but most countries.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#163
post #65

Earlier quoted context omitted.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

You don't know that. We do know that the USG covertly intercepted fiber communications. https://www.washingtonpost.com/news/the-switch/wp/2013/11/04...

The story literally quotes the general of the NSA, saying they go though the FBI to get a FISA court order to compel the company..

Additionally, the story quoted talks about how the UK obtained the data and gave it to the NSA.

Nowhere is the NSA installing covert implants. They just don't do that.

The CIA does that :)

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#164
post #124

Earlier quoted context omitted.

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

Very easily, that's how https://en.wikipedia.org/wiki/Alex_Stamos#Yahoo !

Except they didn't keep it wrapped, did they? And people all the way to the CEO knew about it.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#166
post #31
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

> the NSA would make sense as the source of the implant.

That doesn't make sense based on the assumption that US telecom companies already cooperate extensively with US inteligence agencies.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#167
post #65
post #31

Earlier quoted context omitted.

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

> ...doesn't "attack" american companies with covert implants.

Specific example aside, it's worth talking about why this does happen. "Black bag jobs" can mean "we didn't get a warrant", but they can also mean "we got a warrant and still aren't telling".

Even given a court order, there's still a possibility that employing surveillance by fiat will cause somebody to leak, or modify how they handle data, or simply reveal information about what sort of surveillance tools a given agency employs. Given that a FISA order can be obtained without a defendant, getting a court order and then doing the thing secretly anyway gives a sort of "bowling with bumpers" advantage where the project is approved if it gets revealed, but also done without revealing anything if it isn't.

More disturbingly, there's also substantial evidence that the NSA attacks companies covertly in places where they couldn't get a court order. Taking a specific device out of the supply chain and adding surveillance before it's shipped to the destination is a warrant-worthy project. Setting up systematic physical vulnerabilities with a use case of "turn it on some time in the future to get something interesting" isn't in the purview of a FISA order, so if the NSA did do that it would have to be without an order.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#168
post #127

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Maybe you are not a high value target?

No comment.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#169

Earlier quoted context omitted.

Same here. I have four different Supermicro motherboards purchased in May for servers in my home. I'm sure there exist people and organizations in the world capable of putting malicious hardware on one of these such that I can't detect them. But insofar as I've personally examined them and the available evidence from Bloomberg, color me skeptical...

Ok now try to patch the BMC, you can actually talk to it with openipmi on local host.

I really want to see someone on here with access to one of their recent boards try and report on this. I'd try it, but I sold my last Supermicro board years ago.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#170

Earlier quoted context omitted.

The supposed infiltrated part is a six terminal RF device. Not something that would ordinarily show up on a server motherboard. In any case, Joe Fitzpatrick has already disclosed that he used the part merely as an example and Jordan Robertson expanded that into a work of fiction.

Where is the 6-terminal claim from?

There were quite a few pictures of what is supposed to be the device in the Bloomberg article. Knowing what they say it looks like and knowing roughly where to look I'm 99.9% sure that none of the boards I have here have that device on them.
Post reply on HN