Earlier quoted context omitted.
Maybe you are not a high value target?
That raises an interesting question about just how targeted this kind of attack could be. At manufacture time, do the folks on the assembly line (so to speak) know who a particular board is going to? If not, they would have to add the extra chip to all outgoing boards, which means there should be plenty of them in the wild, no?
New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
351–360 of 379 posts
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#352Earlier quoted context omitted.
You've got to be kidding. There's no way of validating anything about modern hardware, it's packed with independent systems running various firmware, software that's decades old, parts nobody can even identify unless you're the OEM. You can get to "that probably does this" level easily, but that doesn't tell you anything about its actual security or authenticity.
Is this a desirable state of affairs?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#353Earlier quoted context omitted.
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…
> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think? Are they? The authors of this story published an unverified and in corroborated story about Heartbleed a few years ago, claiming that the NSA knew about it and was exploiting it ( https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/... ).
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#354Earlier quoted context omitted.
Are you really a white-hat if you have to disclose vulnerabilities to an organisation known to exploit (or at least hoard) them?
Please quote me where I claimed to be a white hat.
https://dictionary.cambridge.org/grammar/british-grammar/pro...
https://www.quickanddirtytips.com/education/grammar/one-vers...
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#355Earlier quoted context omitted.
This claim seems like a big dilemma for US white-hat security researchers: 1. As a white-hat security researcher, you have an ethical responsibility to publicly disclose vulnerabilities after doing the necessary due diligence (informing the affected parties privately, and giving them the necessary time to respond, investigate, and come up with an acceptable solution). 2. As a US citizen, you can't report attacks carr…
> As a US citizen, you can't report attacks carried out by US intelligence agencies. Who says? Unless you've received a National Security Letter, a gag order from a court, or have a pre-existing relationship with the government that governs disclosure (e.g. security clearance), there's nothing preventing a researcher from disclosing lawfully obtained information. Stumbling upon a secret investigation doesn't make the…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#356Earlier quoted context omitted.
The story literally quotes the general of the NSA, saying they go though the FBI to get a FISA court order to compel the company.. Additionally, the story quoted talks about how the UK obtained the data and gave it to the NSA. Nowhere is the NSA installing covert implants. They just don't do that. The CIA does that :)
What I meant was that you don’t know it isn’t done. You are taking the word of a spy? Did he say it wittingly?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#357Earlier quoted context omitted.
"Who else might get their hands on these devices in the shipping chain?" From the original Businessweek article: "Supermicro has assembly facilities in California, the Netherlands, and Taiwan, but its motherboards—its core product—are nearly all manufactured by contractors in China."
I have to assume we'll start to see a rise in American high tech manufacturing for security purposes alone. Some of these companies may want to manufacturer these critical components themselves, maybe even hand deliver them from their US factory to their customers in the US too. I know that some refineries do direct delivery for some of their large customers, especially industrial lubricants and other by-products. If…
Personally, as someone outside the US, I would gladly trust alleged Chinese malware over known NSA malware. Or even better, literally any other country outside the 5-eyes.
[1]: https://www.theguardian.com/books/2014/may/12/glenn-greenwal...
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#358Earlier quoted context omitted.
I don't have the reference handy but someone claimed to be a source and they pointed to a generic item on digikey / mouser as an example. I imagine that it got extrapolated by Bloomberg into that. They really have no idea what they are talking about at this time and it's probably fluff.
I'm not sure why you're downvoted, except the lack of citation. Your recollection is correct, it's from the Joe Fitzpatrick interview with Risky Business, which was quoted by Apple Insider. (Fitzpatrick was named as a source in the original Bloomberg article.) Long story short, that photo does not show the device involved. "Robertson was unable to produce photographic evidence of the chips in question, saying they we…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#359Earlier quoted context omitted.
> As a US citizen, you can't report attacks carried out by US intelligence agencies. Who says? Unless you've received a National Security Letter, a gag order from a court, or have a pre-existing relationship with the government that governs disclosure (e.g. security clearance), there's nothing preventing a researcher from disclosing lawfully obtained information. Stumbling upon a secret investigation doesn't make the…
Are you sure that the Espionage Act (1917) doesn't cover this? In Australia we have many recent laws that completely restrict our ability to whistleblow on any government issue (though it's not illegal if we ensure that non-Australian nationals know about it -- which is obviously an impossible and stupid standard).
I suppose intent could be there if you share information about a device that says, "Warning: national defense injured if you disclose". But absent a duty I don't think a court would impute intent, especially considering the Free Speech issues (somewhat peculiar to the U.S.).
Notice that nobody has seriously suggested (AFAIK) that the journalists who assisted Snowden should be charged under the Espionage Act, even though their acts would seem to fit multiple provisions. I think that's because unlike Snowden they had no duty, which means the bar for the requisite intent and knowledge (i.e. whether something is really going to harm national defense) is incredibly high.
But who knows? It's a good point and it poses a ton of questions. Still, personally if I found a spying device on something I wouldn't hesitate to disclose it if it seemed noteworthy. I wouldn't feel chilled by the Espionage Act. The same law in some other country? Probably would think twice.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#360Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…