Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

321–330 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#321
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

> it's illegal to report an attack by US intelligence agencies

Is this true? I mean outside a specific gag order or working under a clearance, you could find an issue with a piece of equipment, publicly talk about it and then be arrested because it turned out it was the US government who caused the issue?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#322

Earlier quoted context omitted.

Very easily, that's how https://en.wikipedia.org/wiki/Alex_Stamos#Yahoo !

Except they didn't keep it wrapped, did they? And people all the way to the CEO knew about it.

Point being it started with the CEO.. At what point do you suspect the publicist of all people was clued in? Absolutely never.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#323
post #190

Earlier quoted context omitted.

"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."

I have to assume we'll start to see a rise in American high tech manufacturing for security purposes alone. Some of these companies may want to manufacturer these critical components themselves, maybe even hand deliver them from their US factory to their customers in the US too. I know that some refineries do direct delivery for some of their large customers, especially industrial lubricants and other by-products. If…

>we'll start to see a rise in American high tech manufacturing for security purposes alone.

Already exists in the form of 'country of origin' procurement for high security applications.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#324
I want to mention a. political side of the argument- M Bloomberg himself is very pro open trade and has strongly hinted at running in 2020. Also, newspapers don't usually hurt your owners' candidacy, even for explosive stories. Bloomberg isn't just putting it's reputation on stake here, it's legitimized Trump presidency further. I would say there is definitely something behind this story.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#325

Earlier quoted context omitted.

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

Yeah - when I add to it that, as a non-American, I can (annectodaly) observe a rise in different kinds of news that involve China in a negative context for the last 6m especially, it's hard to form an opinion. In terms of security concerns also - come on, we know by now to which lengths the US goes in this area, and they're surely doing worse stuff than this, I'd expect no one would doubt it any more. So, either they…

Still doesn’t mean you shouldn’t be concerned by China’s super position in the global supply chain...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#327

Earlier quoted context omitted.

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

If information, ideas, knowledge were shared openly we wouldnt have these kinds of ridoculous events. This kind of news is what keeps nations siloed and prevents collaboration. At the same time maybe this will also force us to abandon trust all together and move towards verifying.

Indeed. I saw a brilliant presentation in 2012 by Michael Mitzenmacher from Harvard on verifiable computing in the cloud. It was based on this paper:

https://arxiv.org/pdf/1202.1350v3.pdf

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#328

Earlier quoted context omitted.

The initial allegations from Bloomberg suggested ON the otherboard, not in, as I understand it.

There was mention of one being discovered buried inside the FR4 PCB material.

I don't think you'll find this in a board that doesn't otherwise normally have lots of other buried components ... The added cost of that extra process (using buried components) is so way higher than normal and such a board is going to look noticeably different from a normal board ... I'm tempted to think that someone told the Bloomberg guys that it was possible and the took it that it had happened

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#329
post #48
post #8

OK so this is a different hack than Bloomberg reported before: ethernet jack piggyback instead of bmc. I'm not sure this adds credibility to the allegations in the other story. The details that Bloomberg related previously are so different that this couldnt be what they originally were reporting on. This adds to the China hacking server board narrative, but it does nothing to prove the Bloomberg reporting actually tr…

Read it more carefully. The ethernet jack is a tactic used by US intelligence years ago. That was mentioned in the story to explain the history of supply chain attacks.

> subsequent physical inspection revealed an implant built into the server’s Ethernet connector

It looks pretty clear that this is the hack in question, not an example.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#330

Earlier quoted context omitted.

It's very possible Steve wouldn't know, both owing to past precedent (see SmokeyJ's comment on Alex Stamos) and owing to whether or not he's cleared.

He about has to be cleared if he's the security chief over govcloud.

I may be mistaken but I'm fairly confident govcloud is an unclassified network.
Post reply on HN