Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

211–220 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#211
post #198

Earlier quoted context omitted.

> the NSA would make sense as the source of the implant. That doesn't make sense based on the assumption that US telecom companies already cooperate extensively with US inteligence agencies.

"Extensively" is not 100%

The only US Telecom that did not allow NSA direct access to vacuum up transmissions was Qwest, and their CEO was sent to prison.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#212
post #17

I find it hard to believe, that Bloomberg would publish an extremely detailed story involving some of the largest public companies in the world, knowing that it is entirely false. The cost of reputation is just too high.

Isn't that the question, though. I don't think anyone is accusing them of publishing information that they know to be false. It seems more likely that their sources are just not as good as believed and possibly have reinforced the details and information through an echo chamber. If these sources are within the same subsection of the industry and regularly exchange information, it may just be that they've been regurgi…

Not to be tin-foily, but it is also possible that Bloomberg has been deliberately fed or seeded with "bad" information -- it doesn't have to be an organic echo chamber. But no, I don't think Bloomberg itself set out to deliberately make a false story.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#213
post #163

Earlier quoted context omitted.

You don't know that. We do know that the USG covertly intercepted fiber communications. https://www.washingtonpost.com/news/the-switch/wp/2013/11/04...

The story literally quotes the general of the NSA, saying they go though the FBI to get a FISA court order to compel the company.. Additionally, the story quoted talks about how the UK obtained the data and gave it to the NSA. Nowhere is the NSA installing covert implants. They just don't do that. The CIA does that :)

> The story literally quotes the general of the NSA

Ah, so he pinky-promised? Well OK then!

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#214

Earlier quoted context omitted.

The most compelling explanation I've heard is that the BMC chip could be programmed by two distinct flash chips, one for factory programming and one for some other purpose. In some SKUs, the latter isn't populated but it has a higher priority than the first chip. Since there are many flash chips fitting the same pin out, all it took was soldering a compromised flash chip (with firmware for the BMC chip) onto pads tha…

The BMCs on the newest Supermicro servers are from ASPEED. The X10 models have the AST2400 [0] and the X11 models have the AST2500 [1]. They have ARM CPUs and run, basically, an embedded Linux. If you wanted to "backdoor" motherboards that shipped with these BMCs, wouldn't it would be much easier to just install your own "customized" version of the firmware on them? It certainly seems that it'd be much more difficult…

because all it takes for it to be discovered is someone checking the SPI flash contents

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#215

Earlier quoted context omitted.

A public company issuing such strongly-worded denials that turn out to be untrue would be leaving themselves at risk of an investigation by the SEC and/or a shareholder lawsuit.

It would be pretty extraordinary for the government to sue a company for cooperating with the government. A company has to follow court orders. The government would have to sue itself.

If they didn't have to lie and there was no legal order but voluntary cooperation, as the grandparent post suggests, then such voluntary misinformation can easily be a violation of SEC requirements; and one part of the government certainly can prosecute you for doing something that another part of the government suggested (but didn't/couldn't legally require), it wouldn't be the first time.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#216
post #190

Earlier quoted context omitted.

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

I have to assume we'll start to see a rise in American high tech manufacturing for security purposes alone. Some of these companies may want to manufacturer these critical components themselves, maybe even hand deliver them from their US factory to their customers in the US too. I know that some refineries do direct delivery for some of their large customers, especially industrial lubricants and other by-products. If…

What high technology manufacturing America does is in the security space, otherwise Japan is a trusted source.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#217
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification.

This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern.

On the other hand, the denials from the companies cited in the first article are remarkably strong. And again this article fails to give relevant details. It just cites a security contractor who says he had a client who had this issue.

But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think?

It strikes me that if your goal was to ramp up tension between the US and China at multiple levels, then planting this sort of story would be a great way to accomplish it. Politicians can cite national security. Wary consumers are triggered over privacy. Corporations become more and more gunshy of investing in China and partnering with Chinese manufacturers.

I hate to dream up conspiracy theories. And yet, we live in a world where many states, politicians, organized crime groups, political groups, and corporations are all intentionally spreading disinformation of all sorts all the time designed precisely to ratchet up tension and suspicion.

I don't really believe that's what's going on just yet. But I also don't believe it's as straightforward as the Bloomberg stories make it out to be, either. Something very strange is going on.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#218

Earlier quoted context omitted.

Isn't that the question, though. I don't think anyone is accusing them of publishing information that they know to be false. It seems more likely that their sources are just not as good as believed and possibly have reinforced the details and information through an echo chamber. If these sources are within the same subsection of the industry and regularly exchange information, it may just be that they've been regurgi…

Not to be tin-foily, but it is also possible that Bloomberg has been deliberately fed or seeded with "bad" information -- it doesn't have to be an organic echo chamber. But no, I don't think Bloomberg itself set out to deliberately make a false story.

Of course it's possible. Foreign states have fed much less believable information to work against US interests and a good chunk of the population believes it wholesale.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#219
post #79

Earlier quoted context omitted.

My take on this is that it's been fairly obvious for a long time that these kinds of attacks are possible (if not easy) with today's technology. One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. So why is this suddenly breaking news? It bears resemblance to most of the propaganda stories we have seen in rec…

> China's leadership is calm and not prone to knee-jerk responses Communist China is ruled by a genocidal mafia with a well-known penchant for sudden outbursts of violence. From its bloody inception, through the Great Leap Forward, the TianAnMen Massacre, the persecution of FaLunGong followers and recently Muslims — the regime has shown it's completely incapable of serving its people. When times get tough they invari…

You're not refuting anything the post you're responding says.

Murdering people can be a completely non knee-jerk response to domestic issues. They ARE getting away with it, aren't they?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#220
Appleboum said one key sign of the implant is that the manipulated Ethernet connector has metal sides instead of the usual plastic ones. The metal is necessary to diffuse heat from the chip hidden inside, which acts like a mini computer. "The module looks really innocent, high quality and 'original' but it was added as part of a supply chain attack," he said.

How uncommon are metal vs plastic ethernet connector sleeves?

This seems like a clue that even non-experts could use to track down an implant.

Post reply on HN