Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

271–280 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#271
post #261
post #190

Earlier quoted context omitted.

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

"Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China." That's interesting. As someone who has bought hundreds of thousands of dollars of gear from Supermicro (and has been a huge fan of their products and designs) I always thought their chassis were their core product. Recently SM started to go down th…

Every storage vendor eventually goes full NetApp. The money just looks too good.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#272

This story is getting more incredible every day. Bloomberg only has second hand sources, and all the exploit details are based on speculation from security researchers -- not from insiders. It looks like Bloomberg heard several rumors of supply chain manipulations, mixed that up with plausible scenarios thought up by security researchers, added a few photos from random electronic parts, and voila you have a compellin…

The reporters in question apparently have a reputation for credulously repeating things they hear about cyber-attacks.

https://twitter.com/RobertMLee/status/1049617855396933632

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#273
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

I looked at this back in 2013. Here's some slides from a talk I did after spending 48 hours with them[1].

The BMC back then was by a company called ATEN, who make KVMs. The modern BMC is by ASPEED - I don't know if they're related.

What's described in the article is exactly how the old ATEN firmware worked normally. It was a spectacularly poor product from a security perspective.

[1] - http://mandalorian.com/dl/himym.pdf

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#274
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts…

There is a big difference between claiming 17 sources, a claiming all 17 sources corroborate the full story. The Apple letter to Congress highlight that Bloomberg is relying on a single source for the specific claims about compromised servers being found at Apple.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#275
post #261
post #190

Earlier quoted context omitted.

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

"Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China." That's interesting. As someone who has bought hundreds of thousands of dollars of gear from Supermicro (and has been a huge fan of their products and designs) I always thought their chassis were their core product. Recently SM started to go down th…

> Luckily this coincided with the introduction of the 60bay HGST JBOD chassis. We haven't looked back.

Yes, these units are stellar and anyone buying Supermicro JBOD units should be looking into these as much better replacements. If you have volume they can be even more competitive than Supermicro if you push.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#276

Earlier quoted context omitted.

Or swap the boards out in transit.

Seems more problematic though. You'd have to manufacture the doctored boards, extract them from the normal shipping process, keep them hidden somewhere, then swap them out for the ones destined for the target customer(s). I guess it could be done, but it seems risky.

Couldn't it be done on-demand? Apple orders X hundred boards, motherboard manufacturer makes their small modification(s) to a line that is currently producing the same models of motherboard as Apple ordered, they produce a handful, then they revert and mix in a few of those modified boards into the real order. I don't really know the exact scale, so maybe they make a few hundred / the entire order with chips in them, but economic cost isn't a big deal for things like this, so even losing money making the modified boards wouldn't be the end of the world (and presumably they get a hefty sum of money for whoever is paying them to do this).

I thought China was famous for extremely short turnarounds for industrial engineering edits, so it seems plausible that they could manufacture the boards in a reactionary way and not need to do much in the way of logistics to get them to their targets.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#278

Earlier quoted context omitted.

The supposed infiltrated part is a six terminal RF device. Not something that would ordinarily show up on a server motherboard. In any case, Joe Fitzpatrick has already disclosed that he used the part merely as an example and Jordan Robertson expanded that into a work of fiction.

I hadn't seen this before, but searching for "Joe Fitzpatrick Jordan Robertson" finds https://appleinsider.com/articles/18/10/08/security-research... which seems to be what you were referring to?

The original source is Joe Fitzpatrick's interview with the Risky Business infosec podcast. Apple Insider is just summarizing some of the points from that interview:

https://risky.biz/RB517_feature/

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#279
post #99
post #57

Could be due to losses in "translation", but this paragraph seems odd: > Three security experts who have analyzed foreign hardware implants for the U.S. Department of Defense confirmed that the way Sepio's software detected the implant is sound. One of the few ways to identify suspicious hardware is by looking at the lowest levels of network traffic. Those include not only normal network transmissions, but also analo…

My consumer board exposes that information. There is a tab called system information with hardly readable text which lists all voltages etc by component I've never actually checked in the bios of any server, as that information was never relevant to me, but they probably have that as well

Voltage won't tell you anything. You need to measure current. If a 50ma part is consuming 75ma you would want to investigate why.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#280

Earlier quoted context omitted.

unless the NSA or another intelligence agency has an insider that could catch that before it made it up high enough to cause trouble. conceivably, someone below the insider could leak to Bloomberg realizing that they have limited options.

That seems like a lot of work. What would be the point of that? If Amazon is being spied on by foreign intelligence, wouldn't the NSA want Amazon to know about it? Particularly since government data is hosted on Amazon's servers.

Because now the NSA has a strategic foothold. If they acknowledge the hack, then the adversary will move on to something else. If they don't acknowledge it, they can secretly mitigate it, by feeding false data, for example, and waste the adversary's time.
Post reply on HN