Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

301–310 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#301
post #127

Earlier quoted context omitted.

Maybe you are not a high value target?

No comment.

If I was a high value target (and knew about it) I would definitely not let you know, if I was a high value target and did not know about it I would not be able to tell if I was or if I wasn't. So any high value target and anybody else would not be able to tell you they were a high value target.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#302

Earlier quoted context omitted.

Well, that depends on your definition of tampering, but if you want to exclude manufacturing something that is not what was specced then I am fine with that but please do supply a new term. I would definitely spot that device if it were on these boards because it was described in detail and there were some pictures of what it supposedly looked like. A device like that is not on either side of the board and it isn't i…

> I would definitely spot that device if it were on these boards because it was described in detail and there were some pictures of what it supposedly looked like. In case you missed it, there is an article posted today [0] that has this quote from "Hardware security expert Joe Fitzpatrick", one of the Bloomberg sources, regarding "the supposed spy chip": > In September when he asked me like, “Okay, hey, we think it…

Oh, that's interesting. So they basically took one guys hypothetical and turned that into a news item positively seeded with images of the hypothetical, rather than an actual device.

The original article has now dropped into the real of SF for me until they show a detailed shot of an actual board with a parasitic device on it. Until then this is a wild goose chase.

Thank you for pointing this out.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#303
post #256
post #248

Earlier quoted context omitted.

> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think? Are they? The authors of this story published an unverified and in corroborated story about Heartbleed a few years ago, claiming that the NSA knew about it and was exploiting it ( https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/... ).

And here's someone else calling out Bloomberg for an "unethical hatchet job" when reporting on a technical issue: https://www.semiaccurate.com/2012/10/08/bloomberg-wrong-abou...

To be fair, Clover Trail had all sorts of driver issues that never got resolved. I personally had to deal with the shitty GPU drivers for work. I can't speak to the power management since we were using the chip in a place where power management didn't matter, but I can see those being shit too.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#304
post #296

Earlier quoted context omitted.

This claim seems like a big dilemma for US white-hat security researchers: 1. As a white-hat security researcher, you have an ethical responsibility to publicly disclose vulnerabilities after doing the necessary due diligence (informing the affected parties privately, and giving them the necessary time to respond, investigate, and come up with an acceptable solution). 2. As a US citizen, you can't report attacks carr…

> As a US citizen, you can't report attacks carried out by US intelligence agencies. Sure you can. Short of a gag order (and maybe not even then) you can report intrusions all you like. In any event, how does one determine the nationality of hardware that shouldn't be there? It's not like there's going to be a snarky "Designed by the NSA in Fort Meade" logo on the chips in question.

If (IF!) you hold a civilian or military clearance, then you have a legal Duty to Report (DTR). That holds true whether its data in your clearance level or not.

You also abide by a whole slew of laws regarding sensitive, secret, top secret, or SCIF information. If I knowingly, or even suspect, some information if classified, and I transmit it to anyone else than my federal assigned contact, I'm breaking major federal laws.

A lot of security professionals in the US have such clearances. So finding a NSA implant or such proof makes it dangerous to talk about by default.

So yeah, a gag order by profession.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#305

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

[deleted]

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#306
post #148

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

> the organizations that are denying it have no knowledge that it occurred Are you saying that Steve Schmidt, the AWS chief infosec officer didn't know about the hack? Or that his article [0] was published to purposely hide it? If only one person in Amazon knew about it, it would be Schmidt. And if Schmidt knew, I don't think he'd write an article so strongly claiming Amazon doesn't know anything about it. The only t…

CISO is not the most likely point of crossover, the most likely point is the general counsel's office. Companies don't talk to the Feds without a lawyer, and they also don't issue high profile statements without a lawyer. And unlike the CISO, conversations with your lawyer are privileged.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#307
post #191

Earlier quoted context omitted.

The cleared department is handled the same way as in the military in terms of security. Amazon has SCIF's etc. So unless a disgruntled employee steps forward who doesn't care about there life, I imagine its easily contained (and symptoms of an employee being disgruntled are highly monitored when they hold a clearance)

I’m thinking about the non cleared data center folk, the sys admins and developers who use the servers for their applications. How do a bunch of Supermicro servers vanish wintout anyone noticing? I’d expect quite a few people would be involved that do not have any clearances. Apple is known for their secrecy but a few other companies named are not.

Maybe they didn't remove them.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#308
post #163

Earlier quoted context omitted.

You don't know that. We do know that the USG covertly intercepted fiber communications. https://www.washingtonpost.com/news/the-switch/wp/2013/11/04...

The story literally quotes the general of the NSA, saying they go though the FBI to get a FISA court order to compel the company.. Additionally, the story quoted talks about how the UK obtained the data and gave it to the NSA. Nowhere is the NSA installing covert implants. They just don't do that. The CIA does that :)

What I meant was that you don’t know it isn’t done.

You are taking the word of a spy? Did he say it wittingly?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#309
post #282

Earlier quoted context omitted.

German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts…

> Based on prior experience with investigative journalism there's no way they would go all in with a story like this if they weren't standing on firm ground. Every single sentence would've been vetted. And based on my prior experience I would make the exact opposite conclusion. Technical writers are rarely technical, and they seem to be happy to make stuff up and mislead - even if unintentionally - so long as they ma…

I agree that technical details sometimes gets misrepresented or come out plain wrong. That's my observation as well and it's annoying when you're knowledgeable in the subject and try to make sense of what you've read (or read between the lines).

I think a contributing factor is that it's generally hard to write about things you don't fully understand with the correct nomenclature. Especially when you might not be able to talk/ask for help about specifics with people more knowledgeable because of the secretive process.

Things could've been dumbed down, intentionally or unintentionally, by those involved. It wouldn't be hard to imagine a conversation like: "-So it was sort of a coupler thing? -You could say that, yes". Or what if the technical detail came from a Chinese source and Google translate mangled it?

The coupler thing is dumb and so is the picture (assuming it was a random product picture) but at least they might serve as a way of communicating the big picture: a hard to spot electronic "coupler" thing.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#310
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

If information, ideas, knowledge were shared openly we wouldnt have these kinds of ridoculous events. This kind of news is what keeps nations siloed and prevents collaboration. At the same time maybe this will also force us to abandon trust all together and move towards verifying.
Post reply on HN