Live data from Hacker News

Supermicro boards were so bug ridden, why would hackers ever need implants?

arstechnica.com

1–10 of 81 posts

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#4
Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear?

If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current government bodies are not just staying mum, but actually denying knowledge of the story.

With the software attacks being much more feasible as the Ars article points out than a hardware attack, then it would also make it so that the vehement denials from affected companies would be true as well. The whole thing could be a large disinformation campaign to strike at the very core of what many would otherwise consider reasonable security.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#5

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

It seems like this would be a really bad idea. Scaring companies away from buying Chinese-manufactured products couldn't possibly be worth the respect through fear.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#6

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

No.

A better tinfoil hat theory is that the whole story was fabricated by Russia, to (you know, as always) sow chaos.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#7

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

But the effect of that would be to cause massive distrust of Chinese suppliers and cause a shift away from electronics being produced there. IC and cyber experts generally identify the Chinese as using intelligence operations for primarily economic purposes, as compared to Russian/Iranian/North Korean objectives being military or political. A Chinese military intelligence agency using cyber espionage to intentionally disrupt one of the most significant export industries of the Chinese economy does not seem likely, nor does it seem to provide such an out-sized strategic benefit as to be worth the economic cost.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#8

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

I can't cite this case specifically, but normally it would be incredibly difficult to impersonate a government official as a source.

In my experience verifying a source means weeding out that possibility before publishing... e.g, cross-checking data from a third party (background checks, employment history, social media accounts, public records), then photos of credentials, video chats, etc. Then you cross-reference information with other sources on the story, etc... conspiracy is possible, but unless Bloomberg is inflating the number of sources it has, it would have to be a massive undertaking (state-sponsored).

Anonymous doesn't typically mean someone just calls up and says something and then it's off to the presses. They know exactly who gave them the information, but they're protecting the identities.

Maybe claims of "fake news" would be a lot less common if more people knew what went into verifying information before a major news outlet publishes a story.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#9
post #7

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

But the effect of that would be to cause massive distrust of Chinese suppliers and cause a shift away from electronics being produced there. IC and cyber experts generally identify the Chinese as using intelligence operations for primarily economic purposes, as compared to Russian/Iranian/North Korean objectives being military or political. A Chinese military intelligence agency using cyber espionage to intentionally…

Good point, I agree with that thinking. But the actual execution of such a hardware-based attack would surely be discovered at some point anyway, and risk the same negative outcome. So then that would leave the only possible conclusion that the story just isn't true at all. In the end, none of it makes clear sense...

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#10
I feel like this article reflects some significant technical confusion. The BMC is supposed to be on a trusted network inaccessible from the outside. I've always viewed authentication on the BMC as being like the numeric lock on luggage--it's designed to keep honest people honest, not for real security. Being able to bypass the BMC security is really not a big deal. What the Bloomberg article says about the hardware exploit is much worse:

> > The rogue instructions, Bloomberg reported, caused the BMCs to download malicious code from attacker-controlled computers and have it executed by the server’s operating system.

It's using the fact that the BMC has unfettered access to the rest of the machine to compromise the code running on the server itself. That's valuable even if the BMC itself is on a private network inaccessible to the attacker.

Post reply on HN