Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

231–240 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#231
post #188

Earlier quoted context omitted.

Plausible deniability. Wouldn't surprise me if China is getting the blame for a LOT of US hacking.

With the current political climate, that might be the intention. If you undermine international trade though marketing you don't have to fight a tariff war.

Seems like all US conflicts are now an excuse to race to the bottom with whoever our "enemy" is. We imported torture from the middle east and now state run news and corporations from China.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#232
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts of it. We successfully confirmed the problem was on our (in)side by booting the affected server on a USB stick and made it generate controlled traffic to controlled destinations on the internet that were synchronized using a LFSR. The server was decommissioned and the issue was escalated above my paygrade with clear instructions not to talk about it. I won't give an exact year for this incident but it happened in this decade but before Snowden.

Personally I'm confident Bloomberg's reporting is accurate to a high degree. Based on prior experience with investigative journalism there's no way they would go all in with a story like this if they weren't standing on firm ground. Every single sentence would've been vetted. For each statement made there would be someone whose job would be to reject it unless you could back it up properly. This is also why you don't see these entities defending their story against random criticism that pops up. Most if not all decisions have already been made by the time it goes public.

The fact that there's now a second story on the same topic is a good sign. The reporting of these things are usually followed up by additional pieces to increase the impact (and revenue of course).

They claim they have 17 independent sources. That's pretty impressive in itself. It also means that they probably worked real hard verifying their sources' claims and inputs. I find it unlikely that they would've acquired all those sources unless the thing was real.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#233
I'm not sure it matters to me whether the original article is 100% correct. What I think the original article points out correctly is that the Chinese supply chain is possibly a pretty easy vector for hardware based hacks. I would suspect most nation states have the pull to bribe/blackmail contractors to make malicious modifications. Though the chinese gov. would be the most likely culprit.

It also seems plausible the NSA would prefer techies not to look too closely at their hardware *removes tinfoil hat

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#234

Some real doublethink going on here, with Bloomberg continuing to insist that supply chain attacks are real, yet seemingly accepting the denials of each company involved. I am really not sure what to make of this.

This is just a suggestion, but it might be useful to stop thinking about news reports as "the news report says X is real and true", because that's not what most news reports actually say. The text used usually reads like: "An unnamed source says blah blah", and "Joe Smith, a retied auto-worker, says blah blah blah", or "In response, a spokesman for Large Company, Inc. says blah blah blah blah", and so forth. Bloomber…

It is not that cut and dry though. By publishing this story, they are asserting that the hack happened. They are not saying the attack is possible. They are saying it happened and that halved SMCI's market value. If they are wrong, Bloomberg is going to pay through the teeth for this one.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#235

Earlier quoted context omitted.

That raises an interesting question about just how targeted this kind of attack could be. At manufacture time, do the folks on the assembly line (so to speak) know who a particular board is going to? If not, they would have to add the extra chip to all outgoing boards, which means there should be plenty of them in the wild, no?

Or swap the boards out in transit.

Seems more problematic though. You'd have to manufacture the doctored boards, extract them from the normal shipping process, keep them hidden somewhere, then swap them out for the ones destined for the target customer(s). I guess it could be done, but it seems risky.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#237
post #152

Earlier quoted context omitted.

What's the point of classifying national security threats?

I don't necessarily agree with the below, but one could argue that classification is necessary to prevent mass panic/prevent attempted vigilante justice/protect the government's image/buy the government time to investigate/respond appropriately.

Things get voted on and positions change so I have no idea what you're referring to with "the below," but it's much simpler than trying to protect "the government's image."

If you're attempting to hack me or steal data from me and I know you're trying (specifically as would be the case with this chip if the story holds up) then I'm in a much better position to try to figure out how, or provide misinformation, or try to turn someone in the chain of custody if anything needs to be physically handled. Or at the very least, if it's an espionage or military situation, it makes it easier to know who to kill.

All of that goes out the window if you immediately disclose every threat. Whoever is attacking you will simply use the means you haven't discovered yet and stop using the ones you have.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#238

Earlier quoted context omitted.

> China's leadership is calm and not prone to knee-jerk responses Communist China is ruled by a genocidal mafia with a well-known penchant for sudden outbursts of violence. From its bloody inception, through the Great Leap Forward, the TianAnMen Massacre, the persecution of FaLunGong followers and recently Muslims — the regime has shown it's completely incapable of serving its people. When times get tough they invari…

You're not refuting anything the post you're responding says. Murdering people can be a completely non knee-jerk response to domestic issues. They ARE getting away with it, aren't they?

That's certainly one way to look at it.

I guess I'm projecting some semblance of humanity onto them. I'd assume even the most evil would usually want to hold off murder till nothing else works. Hopefully karma is about to catch up.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#239
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

IANASecurityExpert but one one the named sources of the original claim also came out to say that the 'original attack' was a conceptual idea he had but that doesn't even make sense to apply in practice (considering better alternatives) http://appleinsider.com/articles/18/10/08/security-researche...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#240
post #21

So it is a compromised ethernet adapter. Nobody question the ability of Chinese spies to plant such a thing, but the "Big Hack" story implies that this is used as a mass infiltration tool, which I still find very improbable and lacks any evidence.

The way I interpret it is: since it's being introduced at the manufacturing plant, those installing the devices have no idea where the finished product will end up. Thus, these are not targetted attacks; they could wind up in the servers of a Fortune 500 company, or just as easily in some hobbyist's home lab. You'd need to compromise a large percentage of the products to increase the chances of landing a juicy target…

Considering that large scale internet companies like Amazon and Apple buy enormous amounts of hardware, it's not an insane strategy. If you compromise 1 of every 1,000 pieces of hardware (or even one of every 10,000) odds are you'll end up in a major datacenter pretty quickly.
Post reply on HN