Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

331–340 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#331
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

> it's illegal to report an attack by US intelligence agencies

Can you provide a citation for this statement please

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#332

Earlier quoted context omitted.

The only US Telecom that did not allow NSA direct access to vacuum up transmissions was Qwest, and their CEO was sent to prison.

..for insider trading. You are implying that he went to prison because of the NSA. He went to prison because he sold $52 million in stock after the intelligence community said they would no longer consider Qwest for classified government contracts because of his refusal to cooperate with the NSA. He went to prison because he sold stock based on insider information. Regardless of the reasons for his trade, it was stil…

Everyone breaks laws all the time. The question is whether the Government decides to focus on your activities in order to identify your crimes.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#333

Earlier quoted context omitted.

He about has to be cleared if he's the security chief over govcloud.

I may be mistaken but I'm fairly confident govcloud is an unclassified network.

At least publicly, they're acknowledged to go up to Secret right now. https://aws.amazon.com/blogs/publicsector/announcing-the-new...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#334
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts…

Interesting experience and thank you for the first-hand perspective!

I do have to disagree about the competency of Bloomberg, though, they publish a lot of speculative, low-tech AI/ML scare articles that can be described at best as "inaccurate" and, more realistically, as "making stuff up". They used to have a good reputation, probably from their financial journalism, but their tech work is not good but any reasonable measure, in my personal opinion.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#335
Looks like the infosec cold war is in full swing.

All secrets eventually leak. All secrets. No exceptions. Not even nation-state players with unlimited budgets can prevent leaks. This is reality.

What's a hacker (in the original sense: programmer, not cybercreep) to do?

Our task as custodians of secrets for our end-users is to reduce the attack surfaces on our systems, slow down those leaks and mitigate the effects of leaks when they happen. We must do these things to the best of our ability. We must do them whether we rig systems for large organizations or for our grandmothers.

Who's trustworthy?

Apple? Probably. They're pushing security as a major component of their brand.

AWS? Possibly. They have a lot to lose if they're compromised.

Microsoft? Possibly. They too have a lot to lose.

Seventeen well-placed but unnamed sources in the US security apparatus, babbling to journalists? Possibly.

Journalists? Their trustworthiness is eroding.

Cryptographers Whit Diffie, Martin Hellman, Ralph Merkle, Bruce Scheier, Ron Rivest and colleagues? Likely.

Motherboard vendors? Probably not.

Router / switch / firewall vendors? Probably not.

Nation-states? No. (They could change this by abolishing "security by obscurity" in their work, but that would require major changes in mindset.)

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#336

Earlier quoted context omitted.

I have to assume we'll start to see a rise in American high tech manufacturing for security purposes alone. Some of these companies may want to manufacturer these critical components themselves, maybe even hand deliver them from their US factory to their customers in the US too. I know that some refineries do direct delivery for some of their large customers, especially industrial lubricants and other by-products. If…

Is there any way to solve this problem without needing a "trusted manufacturer"? I know it won't probably won't apply to general purpose motherboards or devices, but is there a way to design or build some components or devices in a way that you can verify that they can perform their purpose and nothing more? If we start with that concept, and slowly build up "verifiably secure" components, they can be the islands of…

What happens when your attacker knows how your safeguards work and can route around your door though the windows?

For a motivated and well funded attacker who has an ability to manufacture a replacement chip with an additional coprocessor that can siphon or modify data from the main processors, network cards, and baseband modems, short of decapping every chip and component that comes through your assembly line your resources would be better spent on establishing trust mechanisms with your suppliers and the transportation couriers touching your devices before the end user acquires it.

https://en.wikipedia.org/wiki/Tailored_Access_Operations#Kno...

http://www.spiegel.de/international/world/the-nsa-uses-power...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#337
post #320

Earlier quoted context omitted.

Same here. I have four different Supermicro motherboards purchased in May for servers in my home. I'm sure there exist people and organizations in the world capable of putting malicious hardware on one of these such that I can't detect them. But insofar as I've personally examined them and the available evidence from Bloomberg, color me skeptical...

Are your Ethernet shells metal, as described in the article, or plastic which the article describes as normal?

This metal shells rubbish is a key indicator that the whole story is bogus. Metal is completely normal.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#338

Earlier quoted context omitted.

The most compelling explanation I've heard is that the BMC chip could be programmed by two distinct flash chips, one for factory programming and one for some other purpose. In some SKUs, the latter isn't populated but it has a higher priority than the first chip. Since there are many flash chips fitting the same pin out, all it took was soldering a compromised flash chip (with firmware for the BMC chip) onto pads tha…

The BMCs on the newest Supermicro servers are from ASPEED. The X10 models have the AST2400 [0] and the X11 models have the AST2500 [1]. They have ARM CPUs and run, basically, an embedded Linux. If you wanted to "backdoor" motherboards that shipped with these BMCs, wouldn't it would be much easier to just install your own "customized" version of the firmware on them? It certainly seems that it'd be much more difficult…

If I'm right, that's exactly what they did. When the BMC chip boots, it checks two flash chips for firmware so the attacker just uploaded their own code to one of a million standard SPI flash chips and plopped it onto the board. They didn't have to incorporate another device into the system, the system was already designed for two flash memory chips. However, to save money on some SKUs, the manufacturer left one of the positions on the board open.

Normally this wouldn't be worth talking about because most active chips are too complicated and too design/supplier specific to carry out an attack like this, but SPI flash is about as standard a footprint/protocol as you can get in EE short of transistors so if you ship a product that could be reprogrammed from unpopulated pads, you're opening yourself up to a large attack surface.

Honestly, after I read the latest BMC chip theory I was like: "Oh, shit. Have I done that?"

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#339

Is no one going to mention that the named source is ex-Israeli Unit 8200, whose alumni themselves have a long record of espionage in the US telecom sector?

Questions to ask when making up your own mind on this issue: AMDOCS billing customer list includes how many major US telcos? How much customer data is required to generate a bill? How much billing is executed in real or near-real time? How much is hosted off-site on non telco infrastructure? How many non-billing services? (Someone elsewhere here already mentioned 100% of voicemail is now outsourced to AMDOCS at one telco). Incidentally, the source for this article is also conveniently based in Maryland.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#340
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…

I think we should judge by facts,not by stereotypes. In my opinion, newspapers are all propaganda machines driven by some their benefit.
Post reply on HN