Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

311–320 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#311
post #79

Earlier quoted context omitted.

My take on this is that it's been fairly obvious for a long time that these kinds of attacks are possible (if not easy) with today's technology. One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. So why is this suddenly breaking news? It bears resemblance to most of the propaganda stories we have seen in rec…

>One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality. Don't you think it's going to be suspicious when you see a capacitor with 6 pins? Don't you think anyone that inspects the motherboard is going to wonder why a capacitor has 4 additional lines going to a critical flash chip? Seriously.... The entire article…

It would not have to have more than two leads, depending on its use in the circuit. It was an example meant to illustrate how the dramatically different levels of miniaturization can make it hard to reason about attack vectors.

Consider what a state actor could do with access to modern microprocessor level fabrication.

I'd expect that we'd see features such as the following:

- sophisticated intra-chip communication

- long periods of total dormancy of the exploits

- circuitry capable of receiving a "it's safe to begin the attack" message

- surprising communications vectors for exfiltration

- technology to make malicious parts appear under x-ray to be normal

- fallback to awaiting the message to perform DoS if more sophisticated attack vectors are not possible

I agree with your suggestion about using the existing footprint, etc. There is likely some very sophisticated tech for making malicious parts x-ray and test as normal in every respect.

The network connector exploit described in the article would be easily detectable by temperature dissipation measurements. So distributed methodologies are likely in use.

I'd also estimate that a large number of mobile devices have built-in hardware compromises that are dormant and can be used if necessary. These would be the simplest attacks to carry out and would have extremely high yield. Things like:

- phones suddenly jamming the 4G and WiFi network simultaneously

- hardware implants to help detect whether a device is being used by a high value target. Such an attack could be created using a tiny bit of silicon and would be dormant in most cases.

The biggest risk to a state actor doing these kinds of attacks is being detected, so firmware based attacks are potentially more risky than hardware attacks, since we are better at detecting a checksum mismatch than we are at testing hardware across the spectrum of possible input conditions that might trigger unusual behavior.

So I think we'd see state actors dipping their toe in slowly to these kinds of attacks, first establishing the supply chain hacks without anything malicious going on, and then gradually phasing in actual malicious hardware once the relevant parameters for the attack are better understood.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#312
post #188

Earlier quoted context omitted.

With the current political climate, that might be the intention. If you undermine international trade though marketing you don't have to fight a tariff war.

Seems like all US conflicts are now an excuse to race to the bottom with whoever our "enemy" is. We imported torture from the middle east and now state run news and corporations from China.

[deleted]

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#313
post #209

Earlier quoted context omitted.

When a threat is discovered it can be very helpful if the attacker does not know you've discovered the threat. Now you can observe them and only intervene when absolutely necessary, thus giving you time to learn more about the attackers and their methods.

Right. So, if this hack is real, the attacker now knows we know.

Yes, it was made public at this time for a reason. I have no idea about who made it public and why, but you can be sure there is a bigger game here.

Did the journalist and/or their friends and family make money on the massive drop in Supermicro stock?

Is the Trump administration asking to push this information out to earn favor in the trade war?

Are the investigators stumped and using this in an attempt to flush out new leads?

No idea.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#314
post #191

Earlier quoted context omitted.

The cleared department is handled the same way as in the military in terms of security. Amazon has SCIF's etc. So unless a disgruntled employee steps forward who doesn't care about there life, I imagine its easily contained (and symptoms of an employee being disgruntled are highly monitored when they hold a clearance)

I’m thinking about the non cleared data center folk, the sys admins and developers who use the servers for their applications. How do a bunch of Supermicro servers vanish wintout anyone noticing? I’d expect quite a few people would be involved that do not have any clearances. Apple is known for their secrecy but a few other companies named are not.

At the scale their datacenter are, they must be replacing a full rack of servers every single day, just to follow a standard 3 years depreciation policy.

Servers practically vanish every single day. Add a few more supermicro and it's not even noticeable. Business as usual.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#315

Earlier quoted context omitted.

It's very possible Steve wouldn't know, both owing to past precedent (see SmokeyJ's comment on Alex Stamos) and owing to whether or not he's cleared.

He about has to be cleared if he's the security chief over govcloud.

Whoever directly oversees it and acts as the stakeholder for GovCloud should be, sure, but there's no reason for the person above the direct overseer to be cleared. Otherwise by that logic Bezos should be cleared as well.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#316
post #220

Appleboum said one key sign of the implant is that the manipulated Ethernet connector has metal sides instead of the usual plastic ones. The metal is necessary to diffuse heat from the chip hidden inside, which acts like a mini computer. "The module looks really innocent, high quality and 'original' but it was added as part of a supply chain attack," he said. How uncommon are metal vs plastic ethernet connector sleev…

I don't recall seeing a board-mounted Ethernet jack that didn't have metal sides.

Reasons for an Ethernet jack to include a small metal enclosure:

1. The jack is subject to physical strain as we insert, remove, and tug on the cables. Most components are affixed to the board using only solder on the signal leads, but these do not provide significant mechanical strength. If you've ever had a bad headphone jack on personal electronics you are familiar with this phenomenon. So the little metal box has additional metal tabs that fit snugly in holes or slots on the board, and provide a stronger mechanical fit and a much larger surface area for solder adhesion.

2. Electromagnetic interference compliance. While Ethernet by definition involves pumping gigahertz signals out a long wire, these signals are carefully shaped and the cables pairs twisted to reduce leakage. But the designer of the jack doesn't know how much EM is flying around inside the case into which the port will be fitted. A metal box around the jack minimizes the size of the unshielded opening in the case. If you've installed a PC motherboard, you know the springy metal fingers on the backplate that seal against the block of external ports.

Is it possible the article is talking about an Ethernet cable plug? I have occasionally seen those with metal sides. But they are not normally supplied as part of a motherboard or server.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#317
maybe its just me but this seems all too familiar. we've seen it happen with iraq, reputable media outputs sensational hostile state actions, immediately faces criticism, but more importantly the timing after announcing China tried meddling with elections.

i dont know sometimes i like reading into the big picture, what is the purpose of this bloomberg article for those outside HN? it won't invoke feelings of calm but rather moral panic. now half the americans are riled up to think china is attacking usa, and we remember they need just teh right amount of support.

also as the noose is tightening around trump, a war or a limited military conflict would be the perfect distraction.

/end conspiracy

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#320

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Same here. I have four different Supermicro motherboards purchased in May for servers in my home. I'm sure there exist people and organizations in the world capable of putting malicious hardware on one of these such that I can't detect them. But insofar as I've personally examined them and the available evidence from Bloomberg, color me skeptical...

Are your Ethernet shells metal, as described in the article, or plastic which the article describes as normal?
Post reply on HN