Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

241–250 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#241

I wonder what evidence caused them to claim the embedded "bug" is planted by China or its operatives -- how can they prove the source of the unauthorized modification? Are they just assuming?

This is my question as well.

> Based on his inspection of the device, Appleboum determined that the telecom company's server was modified at the factory where it was manufactured.

Any further evidence to support that claim? How can they be so sure that the boards weren't tampered with after they were manufactured and shipped to the states? Anyone with a little soldering experience could easily replace an ethernet port.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#242
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

Is it illegal to report an intelligence attack that is perceived to be foreign? If not, why not have all attack reports assume they are foreign to begin with? This would give the reporter credible deniability, and put the burden on the US government to argue otherwise. Regardless, the report is released without the reporter getting in hot water. Or am I missing something?

Incentive for a company to say "No" when the FBI offers to "fix" the problem quietly either by going up the chain of command internally to get answers and stop a blown attack on a US owned and operated business or use contacts within the US security infrastructure to stop the foreign criminal or state adversary.

Most of these attacks never leave the room at corporate HQ where they are discovered unless an engineer wants to permanently screw themselves out of a career.

I once tried to leave a linkedin recommendation for a friend I'd worked with on a high profile project where he discovered Chinese state actors performing corporate espionage and we stopped it. The FBI came in and carted off the servers, we switched data centers, re-deployed, and that was that. We would never have been the wiser if he weren't closely monitoring network characteristics. 3 years and 2 job changes later he messaged me back to say, "Thank you for the rec. but don't mention that shit!"

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#243
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Someone is wagging the dog

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#244
post #65
post #31

Earlier quoted context omitted.

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

but the NSA has been performing backdoors on hardware for years

PRISM

https://www.schneier.com/blog/archives/2018/08/backdoors_in_...

> Juniper has confirmed that an initial analysis of malware linked to the National Security Agency appears to affect its firewalls.

https://www.zdnet.com/article/juniper-confirms-leaked-nsa-ex...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#246
I've been wondering if Google and Google Cloud is affected by this? Does anyone know who Google uses to build the custom motherboards that they use? Also how does something like the Titan Chip [0] help protect against such attack?

I'm curious to understand if theres anything that can protect against this?

[0] https://cloud.google.com/blog/products/gcp/titan-in-depth-se...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#247
post #237

Earlier quoted context omitted.

I don't necessarily agree with the below, but one could argue that classification is necessary to prevent mass panic/prevent attempted vigilante justice/protect the government's image/buy the government time to investigate/respond appropriately.

Things get voted on and positions change so I have no idea what you're referring to with "the below," but it's much simpler than trying to protect "the government's image." If you're attempting to hack me or steal data from me and I know you're trying (specifically as would be the case with this chip if the story holds up) then I'm in a much better position to try to figure out how, or provide misinformation, or try…

Perhaps I should've written "the following" - I just meant the list that I provided in the rest of the sentence.

I believe you covered more in-depth content that could be filed under "buy the government time to investigate/respond appropriately."

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#248
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think?

Are they? The authors of this story published an unverified and in corroborated story about Heartbleed a few years ago, claiming that the NSA knew about it and was exploiting it (https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/...).

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#249

Earlier quoted context omitted.

The Bloomberg article specifically claimed that Apple themselves discovered the chip in a random spot check. If an Apple employee discovered it, it would have been communicated all the way up to the executive level prior to notifying anyone outside the company (such as the FBI), which means you can't just chalk this up to a handful of lower-level Apple employees being covered by a gag order and the executives not kno…

unless the NSA or another intelligence agency has an insider that could catch that before it made it up high enough to cause trouble. conceivably, someone below the insider could leak to Bloomberg realizing that they have limited options.

That seems like a lot of work. What would be the point of that?

If Amazon is being spied on by foreign intelligence, wouldn't the NSA want Amazon to know about it? Particularly since government data is hosted on Amazon's servers.

Post reply on HN