OK so this is a different hack than Bloomberg reported before: ethernet jack piggyback instead of bmc. I'm not sure this adds credibility to the allegations in the other story. The details that Bloomberg related previously are so different that this couldnt be what they originally were reporting on. This adds to the China hacking server board narrative, but it does nothing to prove the Bloomberg reporting actually tr…
Note that BMCs can also piggyback on ethernet ports; I've seen some vendors use a shared ethernet port for OOB and ethernet. Which is fun because you can accidentally put a super important insecure oob service on the same jack as an internet exposed web service.
New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
251–260 of 379 posts
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#252Earlier quoted context omitted.
But they probably can force a handful of engineers to tell nothing to their employer, who would be vehemently denying in good faith.
How would the government get in contact with the engineers who discovered the hack without going through their managers, the CISO, etc. ?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#253Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
is it? and if you were witness to such an attack, how would you be able to attribute it to the USA vs some other actor?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#254So I'm having doubts that Supermicro's Chinese CM has any idea who the end customer of any of their boards is. Maybe it's different for really huge customer, but I still have doubts- it implies they are building to order and have no inventory.
This implies that the CM installs the Chinese Spy Chip on every board, or a random sampling of boards (so they should show up in the wild) or the tampering happens later in the supply chain- in the US.
Also I have further doubts about embedding a chip in a middle layer of a PCB. I doubt the CM is going to add that much extra expense when it's easier to add a chip to the surface. You don't really buy much secrecy from embedding a chip given that it's easy to x-ray a board, so why bother?
Anyway, there are devices called optical comparators. Supermicro could buy some security by providing comparison images that allow customers to perform an incoming inspection. I'm thinking they should do this now to add assurance / help their stock price.
Here is an optical one:
https://www.visionxinc.com/digital-optical-comparators/pcb
Here is an X-Ray one:
http://www.glenbrooktech.com/multi-layer-pcb.php
Maybe the X-Ray inspection could pick up the Ethernet connector attack.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#255Earlier quoted context omitted.
I really want to see someone on here with access to one of their recent boards try and report on this. I'd try it, but I sold my last Supermicro board years ago.
Try what? Updating the firmware? I do it every time a new firmware version is released.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#256Earlier quoted context omitted.
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…
> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think? Are they? The authors of this story published an unverified and in corroborated story about Heartbleed a few years ago, claiming that the NSA knew about it and was exploiting it ( https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/... ).
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#257That story is a bit odd, still -- normally behind the connector there is optionally magnetics, and at least a PHY... being able to integrate the magnetics in the connector exists allright, but adding the phy /as well/ must make it a marvel of integration regular manufacturers would dream of... especially at Gb speed! Also, you can't really 'piggyback' ethernet easily, for the same reasons; you would need TWO phy in t…
> Also, you can't really 'piggyback' ethernet easily, for the same reasons; you would need TWO phy in there to decode/reencode... Pretty much every BMC in existence (well, the ones that comply with the Data Center Manageability Interface, at least) can "piggyback" on top of an onboard Ethernet interface.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#258Earlier quoted context omitted.
If you look at the activity in the frequency domain, you might find a clock that's present in adulterated hardware that's missing in the nominal hardware. > exposed power consumption of random periphery parts Sampling these analog signals is done outside of the computer itself. Even if it were exposed via i2c, you couldn't trust anything that it would tell you.
To me the article reads like it's a purely software solution, thus my confusion, but that might be misinterpretation.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#259Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…
No conspiracy theory needed, traditional media is dying, and in their last gasps of air they are destroying their credibility for the sake of clickbait articles without proper facts and coberation. They are being deceptive, because they know outrage and politically dividing stories are still working.
It's really said, but transparent. No way, Apple officially writes that rebuttle on their website if the story is true.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#260Earlier quoted context omitted.
If you look at that illustration, you see that it's not just one ethernet connector, it's one of these massive connector stack with one ethernet and 2 USB, also, it adds quite a bit of depth to the connector; it must have been made with one particular brand/type of motherboard in mind. Still, if these are in the wild, then perhaps our chinese friends might have reduced the footprint even more to the size of one conne…
That's also at least a five year old implant since Snowden leaked it back in 2013.