Earlier quoted context omitted.
> As a US citizen, you can't report attacks carried out by US intelligence agencies. Sure you can. Short of a gag order (and maybe not even then) you can report intrusions all you like. In any event, how does one determine the nationality of hardware that shouldn't be there? It's not like there's going to be a snarky "Designed by the NSA in Fort Meade" logo on the chips in question.
If (IF!) you hold a civilian or military clearance, then you have a legal Duty to Report (DTR). That holds true whether its data in your clearance level or not. You also abide by a whole slew of laws regarding sensitive, secret, top secret, or SCIF information. If I knowingly, or even suspect, some information if classified, and I transmit it to anyone else than my federal assigned contact, I'm breaking major federal…
New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
341–350 of 379 posts
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#342Earlier quoted context omitted.
> Based on prior experience with investigative journalism there's no way they would go all in with a story like this if they weren't standing on firm ground. Every single sentence would've been vetted. And based on my prior experience I would make the exact opposite conclusion. Technical writers are rarely technical, and they seem to be happy to make stuff up and mislead - even if unintentionally - so long as they ma…
I agree that technical details sometimes gets misrepresented or come out plain wrong. That's my observation as well and it's annoying when you're knowledgeable in the subject and try to make sense of what you've read (or read between the lines). I think a contributing factor is that it's generally hard to write about things you don't fully understand with the correct nomenclature. Especially when you might not be abl…
Maybe there is something there, and/or there is a reason to talk/substitute in vague terms, but insofar as the explicit technical details are concerned, they don't appear credible. Then you're left with an empty allegation that you will have to decide to believe or not based on no other ground than potentiality.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#343Earlier quoted context omitted.
If (IF!) you hold a civilian or military clearance, then you have a legal Duty to Report (DTR). That holds true whether its data in your clearance level or not. You also abide by a whole slew of laws regarding sensitive, secret, top secret, or SCIF information. If I knowingly, or even suspect, some information if classified, and I transmit it to anyone else than my federal assigned contact, I'm breaking major federal…
Are you really a white-hat if you have to disclose vulnerabilities to an organisation known to exploit (or at least hoard) them?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#344Earlier quoted context omitted.
If (IF!) you hold a civilian or military clearance, then you have a legal Duty to Report (DTR). That holds true whether its data in your clearance level or not. You also abide by a whole slew of laws regarding sensitive, secret, top secret, or SCIF information. If I knowingly, or even suspect, some information if classified, and I transmit it to anyone else than my federal assigned contact, I'm breaking major federal…
Are you really a white-hat if you have to disclose vulnerabilities to an organisation known to exploit (or at least hoard) them?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#345Earlier quoted context omitted.
Are you really a white-hat if you have to disclose vulnerabilities to an organisation known to exploit (or at least hoard) them?
Please quote me where I claimed to be a white hat.
> This claim seems like a big dilemma for US white-hat security researchers
It seems like the two are mutually exclusive.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#346Earlier quoted context omitted.
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…
> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think? Are they? The authors of this story published an unverified and in corroborated story about Heartbleed a few years ago, claiming that the NSA knew about it and was exploiting it ( https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/... ).
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#347Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#348Earlier quoted context omitted.
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…
I think we should judge by facts,not by stereotypes. In my opinion, newspapers are all propaganda machines driven by some their benefit.
Cool. Let us test.
Error: Line 2:
> In my opinion, newspapers are all propaganda machines driven by some their benefit.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#349Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#350I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…
The Bloomberg article specifically claimed that Apple themselves discovered the chip in a random spot check. If an Apple employee discovered it, it would have been communicated all the way up to the executive level prior to notifying anyone outside the company (such as the FBI), which means you can't just chalk this up to a handful of lower-level Apple employees being covered by a gag order and the executives not kno…