Live data from Hacker News

Supermicro boards were so bug ridden, why would hackers ever need implants?

arstechnica.com

11–20 of 81 posts

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#11

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

I think it's plausible there's a disinformation campaign behind this strange story and that Bloomberg were the eager dupes.

But unnamed sources are known to the reporters and as "senior national security officials" they should be easy to verify and difficult to fake.

My guess is it's a subgroup of one of the agencies running a relatively independent operation to boost distrust of China. A rather inexperienced or at least incompetent group, based on how awkwardly it's gone over.

(Not that I've come to any conclusions... I think there's more info to come on this.)

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#12
While I don't think Bloomberg's story looks very plausible, perhaps one motivation for cryptic hardware modification at a time when firmware weaknesses were being discovered might be precisely because the easier-to-exploit firmware weaknesses were being discovered, and so might not be exploitable much longer? It might not have seemed plausible that the vulnerabilities would be discovered but then not fixed to the extent that, it turns out, they were not.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#13
I don't really see why everyone is calling this implausible. Modchips have been around for at least 15 years. The idea of the clipper chip is 25 years old. At every hacker conference there are people "hacking" devices by various buses or interfaces.

If there is anything working against the Bloomberg story it is that it is too plausible. Often reality clashes with imagination, but the Bloomberg story contains almost everything you could imagine happening.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#14

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

No need for that much tinfoil, this came in parts straight from the Pentagon [0] and Bloomberg's "specialist", Tavis Ormandy, turned out to have a vested interest in selling "cyber security" related products aimed at supposedly fixing exactly these kinds of supply chain problems [1].

Imho The Register also points out some interesting details about this whole thing [2]

It's not really that surprising, fits perfectly into Trump's narrative of "They took our manufacturing, it's time to take it back to the US!". Gotta start somewhere, telling everybody China is selling a lot of bad apples seems like a simple enough start.

[0] https://s3.amazonaws.com/static.militarytimes.com/assets/eo-...

[1] https://web.archive.org/web/20170721190725/http://www.sepio....

[2] https://www.theregister.co.uk/2018/10/04/supermicro_bloomber...

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#15
post #10

I feel like this article reflects some significant technical confusion. The BMC is supposed to be on a trusted network inaccessible from the outside. I've always viewed authentication on the BMC as being like the numeric lock on luggage--it's designed to keep honest people honest, not for real security. Being able to bypass the BMC security is really not a big deal. What the Bloomberg article says about the hardware…

BMCs like DRAC or iLO are invaluable when you have hundreds or thousands of fresh servers with no OS. The BMC lets you mount an OS or hypervisor ISO in a way reminiscent of DaemonTools et al., and update bios and other firmware from a shared network folder. I'm pretty sure there's even an API to develop against.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#16
“There are so many far easier ways to do the same job. It makes no sense—from a capability, cost, complexity, reliability, repudiability perspective—to do it as described in the article.”

Considering the US went to the trouble of wiring the North Atlantic for sound to catch Russian submarines during the cold war, and tapped undersea cables using divers and submarines, this is so implausible for a nation state? Large state actors specialize in activities for national defense that make "no sense—from a capability, cost, complexity, reliability, repudiability[sic] perspective".

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#17
post #13

I don't really see why everyone is calling this implausible. Modchips have been around for at least 15 years. The idea of the clipper chip is 25 years old. At every hacker conference there are people "hacking" devices by various buses or interfaces. If there is anything working against the Bloomberg story it is that it is too plausible. Often reality clashes with imagination, but the Bloomberg story contains almost e…

Exactly.

How much has the US spent on the F-35? How much has China spent on making artificial islands? Yet engineering a chip and bribing/threatening a few factory workers is beyond the pale?

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#19
post #10

I feel like this article reflects some significant technical confusion. The BMC is supposed to be on a trusted network inaccessible from the outside. I've always viewed authentication on the BMC as being like the numeric lock on luggage--it's designed to keep honest people honest, not for real security. Being able to bypass the BMC security is really not a big deal. What the Bloomberg article says about the hardware…

BMCs like DRAC or iLO are invaluable when you have hundreds or thousands of fresh servers with no OS. The BMC lets you mount an OS or hypervisor ISO in a way reminiscent of DaemonTools et al. , and update bios and other firmware from a shared network folder. I'm pretty sure there's even an API to develop against.

BMC's are great--all my home builds have them because I'm too old to be fiddling around trying to figure out why a computer won't boot an installer from a USB key. But even on my home network the BMC's are on a separate switch on a subnet that doesn't have internet access except through a VPN gateway.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#20

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

Why would he do this its going to damage china economically and diplomatically.
Post reply on HN