Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

281–290 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#281
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

This claim seems like a big dilemma for US white-hat security researchers:

1. As a white-hat security researcher, you have an ethical responsibility to publicly disclose vulnerabilities after doing the necessary due diligence (informing the affected parties privately, and giving them the necessary time to respond, investigate, and come up with an acceptable solution).

2. As a US citizen, you can't report attacks carried out by US intelligence agencies.

I can definitely see the responsibility that patriotic duty would entail, but a citizen with no links to their country's intelligence agency being held responsible for the said agency's failure in maintaining operational discretion doesn't seem sensible to me.

Edit: update formatting.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#282
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts…

> Based on prior experience with investigative journalism there's no way they would go all in with a story like this if they weren't standing on firm ground. Every single sentence would've been vetted.

And based on my prior experience I would make the exact opposite conclusion. Technical writers are rarely technical, and they seem to be happy to make stuff up and mislead - even if unintentionally - so long as they make their deadlines.

Every tech article written about a subject I was directly involved in has not even gotten the spirit of the topic remotely accurate, much less minute technical details such as what chip is used where.

That said - I fully believe supply chains are entirely compromised. I just don't think in this case I'd really put much stock into this specific reporting - they've already been caught blatantly misleading their readers by putting up a photo of a stock Mouser part and not denoting it as such.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#284
post #275
post #261

Earlier quoted context omitted.

"Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China." That's interesting. As someone who has bought hundreds of thousands of dollars of gear from Supermicro (and has been a huge fan of their products and designs) I always thought their chassis were their core product. Recently SM started to go down th…

> Luckily this coincided with the introduction of the 60bay HGST JBOD chassis. We haven't looked back. Yes, these units are stellar and anyone buying Supermicro JBOD units should be looking into these as much better replacements. If you have volume they can be even more competitive than Supermicro if you push.

One very, very small gripe is that the HGST JBODs have no power switch. You power them on and off by inserting or yanking the power cables. Not my favorite SOP ...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#285

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Same here. I have four different Supermicro motherboards purchased in May for servers in my home. I'm sure there exist people and organizations in the world capable of putting malicious hardware on one of these such that I can't detect them. But insofar as I've personally examined them and the available evidence from Bloomberg, color me skeptical...

You purchased servers from 2013-2015 in May? As in used servers?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#286
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

Yeah - when I add to it that, as a non-American, I can (annectodaly) observe a rise in different kinds of news that involve China in a negative context for the last 6m especially, it's hard to form an opinion.

In terms of security concerns also - come on, we know by now to which lengths the US goes in this area, and they're surely doing worse stuff than this, I'd expect no one would doubt it any more. So, either they are genuinely surprised by this, which would be silly (a politically adversarial nation using an obvious opportunity - cheaper stuff being produced there for decades - and doing the same), or it's a part of a broader narrative that's being built.

And, to be clear, I don't think we (the world outside China) shouldn't be a bit worried given in what position _we've_ put China and how strong they are now - it's just that this kind of mass-manipulation and propaganda is the most-detested way of doing it for me...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#287

Earlier quoted context omitted.

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

This claim seems like a big dilemma for US white-hat security researchers: 1. As a white-hat security researcher, you have an ethical responsibility to publicly disclose vulnerabilities after doing the necessary due diligence (informing the affected parties privately, and giving them the necessary time to respond, investigate, and come up with an acceptable solution). 2. As a US citizen, you can't report attacks carr…

> As a US citizen, you can't report attacks carried out by US intelligence agencies.

Who says? Unless you've received a National Security Letter, a gag order from a court, or have a pre-existing relationship with the government that governs disclosure (e.g. security clearance), there's nothing preventing a researcher from disclosing lawfully obtained information. Stumbling upon a secret investigation doesn't make the information unlawfully obtained, even if you suspect it might be a secret investigation.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#288
post #181

Earlier quoted context omitted.

There were quite a few pictures of what is supposed to be the device in the Bloomberg article. Knowing what they say it looks like and knowing roughly where to look I'm 99.9% sure that none of the boards I have here have that device on them.

I don't have the reference handy but someone claimed to be a source and they pointed to a generic item on digikey / mouser as an example. I imagine that it got extrapolated by Bloomberg into that. They really have no idea what they are talking about at this time and it's probably fluff.

I'm not sure why you're downvoted, except the lack of citation. Your recollection is correct, it's from the Joe Fitzpatrick interview with Risky Business, which was quoted by Apple Insider. (Fitzpatrick was named as a source in the original Bloomberg article.)

Long story short, that photo does not show the device involved.

"Robertson was unable to produce photographic evidence of the chips in question, saying they were described to him by protected sources. Indeed, Robertson in September asked Fitzpatrick what a "signal amplifier or coupler" looks like, suggesting the publication narrowed the attack package down to that particular component. Fitzpatrick sent Robertson a link to a very small signal coupler sold by Mouser Electronics. "Turns out that's the exact coupler in all the images in the story," Fitzpatrick said.

https://appleinsider.com/articles/18/10/08/security-research...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#290
post #57

Could be due to losses in "translation", but this paragraph seems odd: > Three security experts who have analyzed foreign hardware implants for the U.S. Department of Defense confirmed that the way Sepio's software detected the implant is sound. One of the few ways to identify suspicious hardware is by looking at the lowest levels of network traffic. Those include not only normal network transmissions, but also analo…

Sampling the EM profile of a large number of boards PHY signals could lead you to a deviation that indicate an anomaly Whetever that anomaly has to be forwarded to maintenance or to security can be discussed however: is the EM profile "wrong" because of tampering or because some capacitor is about to blow up?
Post reply on HN