Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

291–300 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#291
post #148

Earlier quoted context omitted.

> the organizations that are denying it have no knowledge that it occurred Are you saying that Steve Schmidt, the AWS chief infosec officer didn't know about the hack? Or that his article [0] was published to purposely hide it? If only one person in Amazon knew about it, it would be Schmidt. And if Schmidt knew, I don't think he'd write an article so strongly claiming Amazon doesn't know anything about it. The only t…

It's very possible Steve wouldn't know, both owing to past precedent (see SmokeyJ's comment on Alex Stamos) and owing to whether or not he's cleared.

He about has to be cleared if he's the security chief over govcloud.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#292
post #209

Earlier quoted context omitted.

When a threat is discovered it can be very helpful if the attacker does not know you've discovered the threat. Now you can observe them and only intervene when absolutely necessary, thus giving you time to learn more about the attackers and their methods.

Right. So, if this hack is real, the attacker now knows we know.

They might actually know for much longer: if your spying devices suddenly stop communicating to you, that's likely you've been discovered.

If that story is true (and I personnaly think it has a high probability to be), what would a gov or a large org do? Investigate, confirm they have been compromised but then.... leave the hw in place and data flowing back to the alien mothership? Unlikely.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#293
post #209

Earlier quoted context omitted.

When a threat is discovered it can be very helpful if the attacker does not know you've discovered the threat. Now you can observe them and only intervene when absolutely necessary, thus giving you time to learn more about the attackers and their methods.

Right. So, if this hack is real, the attacker now knows we know.

The previously reported issue was alleged to take place in 2013-2015.

This issue in this thread is alleged to have taken place in August 2018.

In the intervening time, much could have happened.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#294

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

It's interesting that everyone is assuming the only country interested in pressuring them to lie would be the US rather than China.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#295
post #284
post #275

Earlier quoted context omitted.

> Luckily this coincided with the introduction of the 60bay HGST JBOD chassis. We haven't looked back. Yes, these units are stellar and anyone buying Supermicro JBOD units should be looking into these as much better replacements. If you have volume they can be even more competitive than Supermicro if you push.

One very, very small gripe is that the HGST JBODs have no power switch. You power them on and off by inserting or yanking the power cables. Not my favorite SOP ...

Is that a real thing? Holy cow, I'm shocked (bad pun intended). What about adding an inline switch in the cord? Unless they expect everyone to be using a managed power system where each plug can be turned on/off, this just seems very odd decision to make.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#296

Earlier quoted context omitted.

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

This claim seems like a big dilemma for US white-hat security researchers: 1. As a white-hat security researcher, you have an ethical responsibility to publicly disclose vulnerabilities after doing the necessary due diligence (informing the affected parties privately, and giving them the necessary time to respond, investigate, and come up with an acceptable solution). 2. As a US citizen, you can't report attacks carr…

> As a US citizen, you can't report attacks carried out by US intelligence agencies.

Sure you can. Short of a gag order (and maybe not even then) you can report intrusions all you like.

In any event, how does one determine the nationality of hardware that shouldn't be there? It's not like there's going to be a snarky "Designed by the NSA in Fort Meade" logo on the chips in question.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#297
post #59
post #20

Earlier quoted context omitted.

If it's correct, it's highly likely that most cloud vendors are in the same boat. Imagine Google or AWS, who each have multiple millions of servers: even if they build their own motherboards, there are so many 3rd party components there's no way to vet all the boards. Their IDS will catch some, but not all. One might imagine a cloud vendor is constantly the target from multiple state actors, foreign and domestic, all…

I can't imagine the cost of x-ray-ing all motherboards on an AWS scale.

At that point they might as well just replace them. Which they presumably do every few years regardless.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#298
post #190

Earlier quoted context omitted.

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

I have to assume we'll start to see a rise in American high tech manufacturing for security purposes alone. Some of these companies may want to manufacturer these critical components themselves, maybe even hand deliver them from their US factory to their customers in the US too. I know that some refineries do direct delivery for some of their large customers, especially industrial lubricants and other by-products. If…

Is there any way to solve this problem without needing a "trusted manufacturer"?

I know it won't probably won't apply to general purpose motherboards or devices, but is there a way to design or build some components or devices in a way that you can verify that they can perform their purpose and nothing more?

If we start with that concept, and slowly build up "verifiably secure" components, they can be the islands of security that we can build off of without having to worry if the manufacturing plant left their door open one day and some random person was able to sneak in.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#299
post #284

Earlier quoted context omitted.

One very, very small gripe is that the HGST JBODs have no power switch. You power them on and off by inserting or yanking the power cables. Not my favorite SOP ...

Is that a real thing? Holy cow, I'm shocked (bad pun intended). What about adding an inline switch in the cord? Unless they expect everyone to be using a managed power system where each plug can be turned on/off, this just seems very odd decision to make.

As someone that flipped the power switch on a rack mounted machine by accident before, I could see how a power button or switch would be consitered a liability more than a benefit, especially when the solution (pull the power cable) is simple, foolproof, and doesn't happen that often to warrant optimizing!

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#300
post #65

Earlier quoted context omitted.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

Wasn't PRISM all about attacking American companies with covert implants? For instance tapping into Google region to region data transfers, after which Google started encrypting everything.

The program for tapping data center links had the internal code name MUSCULAR and was a partnership with the British GCHQ, who actually did the intercepting.

PRISM was at first reported as some sort of direct access to the servers of certain American companies, but it turned out to be the code name for a joint program with the FBI for using FISA warrants to request data from those companies.

Post reply on HN