Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

261–270 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#261
post #190

Earlier quoted context omitted.

The lack of (publicly available) evidence is annoying, since there are a lot of people who'd love to check their own servers. As this is an attack directed at high profile targets it's unlikely the average size company will have ended up with one of those, but it's still a fun exercise IMO. It would also be great to know what the attribution is based on. Just the fact that they're manufactured in China? Who else migh…

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

"Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

That's interesting. As someone who has bought hundreds of thousands of dollars of gear from Supermicro (and has been a huge fan of their products and designs) I always thought their chassis were their core product.

Recently SM started to go down the "you can't buy our JBOD chassis without buying them full of our qualified drives" ... I knew that was the end of the golden age (of SM).

Luckily this coincided with the introduction of the 60bay HGST JBOD chassis. We haven't looked back.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#262
post #33
post #25

Earlier quoted context omitted.

>it's illegal to report an attack by US intelligence agencies Could you expand more on that?

IANAL, but New York Times Co. v. United States is a famous precedent for the first amendment protecting the press' right to publish classified government documents.

That's what I was kind of getting at, the press is free to publish pretty much anything they'd like AFAIK.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#263
This story is getting more incredible every day.

Bloomberg only has second hand sources, and all the exploit details are based on speculation from security researchers -- not from insiders.

It looks like Bloomberg heard several rumors of supply chain manipulations, mixed that up with plausible scenarios thought up by security researchers, added a few photos from random electronic parts, and voila you have a compelling story to tell.

This "new evidence" talks about a completely different type of attack than the original article. It corroborates nothing. It just shows how misleading the original story was.

I think the most damning part was the use of so many misleading photos and illustrations. All photos were pure speculation (this is what this chip might look like, this is where it would make sense to put the chip). But neither the captions nor the text made that clear.

The only thing I believe about the story is that they have a couple of sources who have vague, second hand rumors about supply chain manipulation.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#264
post #18

It may soon be that the only companies who can sell hardware outside of their own country are those who sell Open Source Hardware which can be 100% verified as true to its published design.

How would that help? SuperMicro was not able to verify that what they designed and ordered is what was shipped.

What makes you think that just because it's open source, that that would change?

i.e. the design is "Open Source" to SuperMicro - but it didn't help them.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#265
post #65
post #31

Earlier quoted context omitted.

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

"SSL added and removed here ;-)" doesn't sound like a FISA court order.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#266
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think?

When the articles published by those "serious news organizations" concerns China, disinformation / lack of evidence are really common place if you carefully examine their source. I used to do so from time to time but grew tired of that

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#267

This story is getting more incredible every day. Bloomberg only has second hand sources, and all the exploit details are based on speculation from security researchers -- not from insiders. It looks like Bloomberg heard several rumors of supply chain manipulations, mixed that up with plausible scenarios thought up by security researchers, added a few photos from random electronic parts, and voila you have a compellin…

Yup. Which is why I'm holding on to my discount bin supermicro shares.

The bloomberg story stinks to high heavens even if there are live examples of infiltrated supply chains

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#268
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

That's not a conspiracy theory. It's standard type of policy and it would be surprising otherwise.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#269
post #198

Earlier quoted context omitted.

"Extensively" is not 100%

The only US Telecom that did not allow NSA direct access to vacuum up transmissions was Qwest, and their CEO was sent to prison.

..for insider trading. You are implying that he went to prison because of the NSA. He went to prison because he sold $52 million in stock after the intelligence community said they would no longer consider Qwest for classified government contracts because of his refusal to cooperate with the NSA.

He went to prison because he sold stock based on insider information. Regardless of the reasons for his trade, it was still insider information.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#270
The credibility of the journalists is being called into question by influential people in the infosec community:

https://twitter.com/RobertMLee/status/1049617855396933632?s=...

https://risky.biz/RB517_feature/

The podcast is an interview with Joe Fitzpatrick, one of the named sources. It's an impartial and mature discussion that left me with the same feeling of unease that Joe says he had when he first read the story. Basically, Joe would describe a theoretical hardware exploit to the Bloomberg journalist and the journo's sources would then confirm exactly that as a real world exploit.

Post reply on HN