Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

201–210 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#201
What if the bloomberg article was a sort of false flag?

The Trump administration has been consistently escalating retoric against the Chinese, and it's not hard to imagine the CIA/NSA/etc intentionally leaking facts to bloomberg that would make China look like a national security threat. This could even be done in a way where the security agencies don't leak anything actually false, but let the non-phds at bloomberg run wild with speculation to create a sensationalist story that's not really true. A recent WSJ article [1] has called particular attention to the Trump administration's escalating anti-Chinese rhetoric, calling it the start of a "second cold war". We know for a fact that these sorts of operations happened during the first cold war [2], so it's not at all hard to imagine they would happen now.

A false flag attack fits with all the information we have so far about the event: There's no direct evidence of the attack, and if the bloomberg article is ever proven to be false, then only a small number of security researchers (and HNers) will ever learn about the retraction. The vast majority of Americans will only remember reading about how "China hacked major US companies" and create an anti-Chinese atmosphere that will help fuel future anti-Chinese policies.

[1] https://www.wsj.com/articles/mike-pence-announces-cold-war-i...

[2] https://fas.org/sgp/news/2002/02/re022502.html

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#203

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

Ignorance is not a defense, especially for a director of security. Lying about knowing how the organization you lead operates is a bad as directly lying about how your organization operates.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#204
post #190

Earlier quoted context omitted.

The lack of (publicly available) evidence is annoying, since there are a lot of people who'd love to check their own servers. As this is an attack directed at high profile targets it's unlikely the average size company will have ended up with one of those, but it's still a fun exercise IMO. It would also be great to know what the attribution is based on. Just the fact that they're manufactured in China? Who else migh…

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

I have to assume we'll start to see a rise in American high tech manufacturing for security purposes alone. Some of these companies may want to manufacturer these critical components themselves, maybe even hand deliver them from their US factory to their customers in the US too.

I know that some refineries do direct delivery for some of their large customers, especially industrial lubricants and other by-products. If the order is big enough, or someone wants to pay the premium, then direct delivery could be very feasible for tech too.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#205
post #79

Earlier quoted context omitted.

My take on this is that it's been fairly obvious for a long time that these kinds of attacks are possible (if not easy) with today's technology. One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. So why is this suddenly breaking news? It bears resemblance to most of the propaganda stories we have seen in rec…

> Our president has already been attacking China with rhetoric and trade sanctions, and this story is meant to turn public opinion broadly against China. Ah yes, Bloomberg, well-known for protectionist rhetoric and support for Trump. > top universities are 10x more competitive (or more) than top US universities. A citation would be very helpful here. And no, number of paper's published isn > This is foolhardy, becaus…

You're conflating rationality with propriety. China wanted Meng Hongwei to make it easier to use Interpol to track down Chinese dissidents, directly in conflict with the Interpol charter; and merely two years later they kidnap, disappear him, and charge him with disloyalty to the Chinese Communist Party. He was supposed to be their stooge pigeon, but was clearly ineffective. Again from their point of view, entirely rational to have him removed because he wasn't doing what was expected. And that's what's so conspicuous, they openly admit China was his master, not Interpol.

China, Xi, and the Party are in a sense all one in the same thing. There is nothing more important than loyalty to the one Party, and the concept of one Party rule. And Uighurs are a threat to that, so they're labeled terrorists. If you accept the idea that one party rule is necessary, it's entirely rational to aggressively, perhaps even violently, ban all possible opposition. That's the nature of any autocracy.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#206

Earlier quoted context omitted.

Same here. I have four different Supermicro motherboards purchased in May for servers in my home. I'm sure there exist people and organizations in the world capable of putting malicious hardware on one of these such that I can't detect them. But insofar as I've personally examined them and the available evidence from Bloomberg, color me skeptical...

Ok now try to patch the BMC, you can actually talk to it with openipmi on local host.

I'm familiar with OpenIPMI (I use it for remote fan control a lot) but I'm not clear on what exactly you want me to try?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#207
post #152

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

What's the point of classifying national security threats?

When a threat is discovered it can be very helpful if the attacker does not know you've discovered the threat.

Now you can observe them and only intervene when absolutely necessary, thus giving you time to learn more about the attackers and their methods.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#208

Earlier quoted context omitted.

The most compelling explanation I've heard is that the BMC chip could be programmed by two distinct flash chips, one for factory programming and one for some other purpose. In some SKUs, the latter isn't populated but it has a higher priority than the first chip. Since there are many flash chips fitting the same pin out, all it took was soldering a compromised flash chip (with firmware for the BMC chip) onto pads tha…

The BMCs on the newest Supermicro servers are from ASPEED. The X10 models have the AST2400 [0] and the X11 models have the AST2500 [1]. They have ARM CPUs and run, basically, an embedded Linux. If you wanted to "backdoor" motherboards that shipped with these BMCs, wouldn't it would be much easier to just install your own "customized" version of the firmware on them? It certainly seems that it'd be much more difficult…

If possible, it is better to have separate hardware that can continuously compromise the firmware. That way your exploit continues to exist even if valid firmware is flashed directly onto the memory module.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#209
post #152

Earlier quoted context omitted.

What's the point of classifying national security threats?

When a threat is discovered it can be very helpful if the attacker does not know you've discovered the threat. Now you can observe them and only intervene when absolutely necessary, thus giving you time to learn more about the attackers and their methods.

Right. So, if this hack is real, the attacker now knows we know.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#210

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

The Bloomberg article specifically claimed that Apple themselves discovered the chip in a random spot check. If an Apple employee discovered it, it would have been communicated all the way up to the executive level prior to notifying anyone outside the company (such as the FBI), which means you can't just chalk this up to a handful of lower-level Apple employees being covered by a gag order and the executives not knowing.
Post reply on HN