Live data from Hacker News

Supermicro boards were so bug ridden, why would hackers ever need implants?

arstechnica.com

31–40 of 81 posts

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#31
If Supermicro boards are bug-ridden, then I'd expect other manufacturer's boards to be equally bad or worse. I don't have a reason to defend Supermicro or some such, but where else in retail do you get specialized server boards like Supermicro sells? When Opteron was relatively new in 2004, I bought a two-socket board from Supermicro as the alternatives from well-known Taiwan manufacturers (ASUS, MSI, etc.) weren't as sophisticated (hadn't the PSUs and PSU connectors, power ratings, and rack-mount/tower convertible enclosures).

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#32
post #13

I don't really see why everyone is calling this implausible. Modchips have been around for at least 15 years. The idea of the clipper chip is 25 years old. At every hacker conference there are people "hacking" devices by various buses or interfaces. If there is anything working against the Bloomberg story it is that it is too plausible. Often reality clashes with imagination, but the Bloomberg story contains almost e…

Exactly. How much has the US spent on the F-35? How much has China spent on making artificial islands? Yet engineering a chip and bribing/threatening a few factory workers is beyond the pale?

[deleted]

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#33
post #13

I don't really see why everyone is calling this implausible. Modchips have been around for at least 15 years. The idea of the clipper chip is 25 years old. At every hacker conference there are people "hacking" devices by various buses or interfaces. If there is anything working against the Bloomberg story it is that it is too plausible. Often reality clashes with imagination, but the Bloomberg story contains almost e…

Exactly. How much has the US spent on the F-35? How much has China spent on making artificial islands? Yet engineering a chip and bribing/threatening a few factory workers is beyond the pale?

Bloomberg's claim is that a miniature device used for RF analog electronics was coopted and inserted into a board that would never have such a part designed in. This requires modifying the board artwork, the pick and place config, any automated inspection and test equipment, and adding a foreign part reel to the supply chain.

It is much easier to compromise firmware directly or modify ICs that are already part of the design. The risk of being caught is much lower and it would be stupid to attempt anything more elaborate.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#34
One researcher criticizes this type of hardware attack, saying:

Once discovered, such an attack would be burned for every affected board as people would replace them.

But this article also points out a case where, even after SuperMicro had published a patch to a serious BMC firmware vulnerability, 32,000 servers in the wild had not been updated a year later.

So, if software updates aren't always speedily/reliably deployed in the wild by customers, can we really expect hardware to be speedily replaced?

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#35

Okay, crazy tinfoil hat time: what if this story is a plant from a particular part of the Chinese government (like PLA Unit 61398), designed to give the impression of the ability to disrupt global supply chains and to build respect through fear? If all of these unnamed sources are unnamed because they were adversarial members impersonating government officials, then that would make a little more sense why current gov…

No need for that much tinfoil, this came in parts straight from the Pentagon [0] and Bloomberg's "specialist", Tavis Ormandy, turned out to have a vested interest in selling "cyber security" related products aimed at supposedly fixing exactly these kinds of supply chain problems [1]. Imho The Register also points out some interesting details about this whole thing [2] It's not really that surprising, fits perfectly i…

Do you mean someone else rather than Tavis Ormandy? As someone else has already pointed out, he's at Google Project Zero (which isn't in the business you describe) and I don't think he's ever worked for the company whose brochure you linked to, and so far as I can see he's been pretty rude about the Bloomberg story.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#36
post #30

Earlier quoted context omitted.

What has truly surprised me in all of this is the skepticism expressed about this being plausible. Most nerd sites are rife with thoughts on how insecure things are and hypothetical ideas on how something could be compromised but all of a sudden this one isn't possible? We know the US Gov't has done it in transit but it's ridiculous to think a state owned manufacturer wouldn't do it on the factory line? We know this…

I don't hear skepticism on plausibility. I just hear skepticism based on lack of actual evidence, as there has been, to date, exactly zero. For a hardware back that could only have been done at a large scale.

This is why I am skeptical. I will not presume to know how Supermicro and Elemental operate but I find it unlikely that this would go unnoticed by both of them. The guys I work with raise hell if CRCs on firmware images don't match, much less a BOM change. There are a lot of QA breakdowns that have to happen after manufacturing for this sort of attack to be successful. Could it happen? Sure, but there should be some sort of available evidence. What about the rest of Elemental's customers? Did the government manage to quietly take all of their servers as well?

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#37
The purpose of this whole thing was to manipulate the market. Super Micro stock fell 50% and still has not recovered since October 4th. Before the report its trading volume was invisible. After the report the volume experienced almost 2 orders of magnitude increase.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#38

Earlier quoted context omitted.

Exactly. How much has the US spent on the F-35? How much has China spent on making artificial islands? Yet engineering a chip and bribing/threatening a few factory workers is beyond the pale?

Bloomberg's claim is that a miniature device used for RF analog electronics was coopted and inserted into a board that would never have such a part designed in. This requires modifying the board artwork, the pick and place config, any automated inspection and test equipment, and adding a foreign part reel to the supply chain. It is much easier to compromise firmware directly or modify ICs that are already part of the…

[flagged]

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#39

Earlier quoted context omitted.

Exactly. How much has the US spent on the F-35? How much has China spent on making artificial islands? Yet engineering a chip and bribing/threatening a few factory workers is beyond the pale?

Bloomberg's claim is that a miniature device used for RF analog electronics was coopted and inserted into a board that would never have such a part designed in. This requires modifying the board artwork, the pick and place config, any automated inspection and test equipment, and adding a foreign part reel to the supply chain. It is much easier to compromise firmware directly or modify ICs that are already part of the…

  This requires [et c.]
Or, they could run their own fabrication facilty, where they can exert total control over the production line, in total secrecy, and you'd never know the difference, or notice a sacrifice in the fidelity of replication.

Think that's impossible? Not at the nation-state level. Not in communist countries where everything is property of the government by default. Not in capitalist countries like the United States, where entire nuclear facilities are replicated in secret. [0]

[0] https://www.businessinsider.com/the-us-built-a-secret-replic...

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#40
post #10

I feel like this article reflects some significant technical confusion. The BMC is supposed to be on a trusted network inaccessible from the outside. I've always viewed authentication on the BMC as being like the numeric lock on luggage--it's designed to keep honest people honest, not for real security. Being able to bypass the BMC security is really not a big deal. What the Bloomberg article says about the hardware…

Except that in many cases the BMC does not exposed to the internet, especially in situations where you get a dedicated server from somewhere and they want to give you low-level access to make changes to the server you are renting.

I know of at least 2 places where this is still the case (that or a remote IP KVM...).

The BMC should be on a trusted network, but most likely isn't.

Post reply on HN