Supermicro boards were so bug ridden, why would hackers ever need implants?
41–50 of 81 posts
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#42Earlier quoted context omitted.
But the effect of that would be to cause massive distrust of Chinese suppliers and cause a shift away from electronics being produced there. IC and cyber experts generally identify the Chinese as using intelligence operations for primarily economic purposes, as compared to Russian/Iranian/North Korean objectives being military or political. A Chinese military intelligence agency using cyber espionage to intentionally…
Good point, I agree with that thinking. But the actual execution of such a hardware-based attack would surely be discovered at some point anyway, and risk the same negative outcome. So then that would leave the only possible conclusion that the story just isn't true at all. In the end, none of it makes clear sense...
So in the planted story hypothesis, there is certainty of negative outcomes with only the potential for positive outcomes, and those only intangible, while in the this-is-real hypothesis, there is near certainty of some tangible benefit with good probability of significant tangible benefit, with only a potential, distant, deniable risk of negative outcome.
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#43I don't really see why everyone is calling this implausible. Modchips have been around for at least 15 years. The idea of the clipper chip is 25 years old. At every hacker conference there are people "hacking" devices by various buses or interfaces. If there is anything working against the Bloomberg story it is that it is too plausible. Often reality clashes with imagination, but the Bloomberg story contains almost e…
It isn't implausible because of it being difficult and expensive, its implausible because there already exist much easier, cheaper, and (arguably) harder to detect ways of subverting SuperMicro motherboards. As a bonus, subverting the BMC firmware is much harder to trace to the source since it could be injected by in so many ways by so many different people. Why use a thermonuclear device when a hand grenade accompli…
If anything I think the idea that a Chinese manufacturer with complete access to the hardware having to execute some exploit towards the web interface to get access is far fetched. So is that you could pretend to update the firmware (surely no one is going to notice that the new version doesn't have the features you wanted?) and that dumping the firmware would be inconvenient (it would be the first thing you did if you suspected something).
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#44Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#45I'd go further to say it isn't just about the accuracy of the bloomberg piece, but implies bad things about their journalistic integrity. I mean, get real, Ars doesn't have an investigative journalism team. The one-sidedness of the bloomberg article becomes very apparent.
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#46Earlier quoted context omitted.
Bloomberg's claim is that a miniature device used for RF analog electronics was coopted and inserted into a board that would never have such a part designed in. This requires modifying the board artwork, the pick and place config, any automated inspection and test equipment, and adding a foreign part reel to the supply chain. It is much easier to compromise firmware directly or modify ICs that are already part of the…
This requires [et c.] Or, they could run their own fabrication facilty, where they can exert total control over the production line, in total secrecy, and you'd never know the difference, or notice a sacrifice in the fidelity of replication. Think that's impossible? Not at the nation-state level. Not in communist countries where everything is property of the government by default. Not in capitalist countries like the…
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#47Okay, crazier lead-foil hat time: what if this story is a crappy hoax intended to discredit/prevent from publication a real story with similar details?
Maybe it takes away from the firmware hacking version of the story because now folks are looking at components as being the source of hacks and not the firmware on the components, leading to a false sense of security when they invest mightily in analyzing components with X-rays? I could see that outcome as being plausible. If the ultimate outcome is simply to change corporate priority towards futile component verification and away from firmware verification then indeed the firmware verification vector remains safe for the attacker.
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#48Earlier quoted context omitted.
I don't hear skepticism on plausibility. I just hear skepticism based on lack of actual evidence, as there has been, to date, exactly zero. For a hardware back that could only have been done at a large scale.
This is why I am skeptical. I will not presume to know how Supermicro and Elemental operate but I find it unlikely that this would go unnoticed by both of them. The guys I work with raise hell if CRCs on firmware images don't match, much less a BOM change. There are a lot of QA breakdowns that have to happen after manufacturing for this sort of attack to be successful. Could it happen? Sure, but there should be some…
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#49I would guess that large companies are refreshing with known good firmware before deploying servers? So while described approach is easier prob will not get attacker as much.
Re: Supermicro boards were so bug ridden, why would hackers ever need implants?
#50Okay, crazier lead-foil hat time: what if this story is a crappy hoax intended to discredit/prevent from publication a real story with similar details?
I don't follow. If anything it makes the parallel story easier to publish as a sort of "me too" (no disrespect.) Maybe it takes away from the firmware hacking version of the story because now folks are looking at components as being the source of hacks and not the firmware on the components, leading to a false sense of security when they invest mightily in analyzing components with X-rays? I could see that outcome as…
Or, "Extra chips on the motherboard? You're about a month behind the news cycle and didn't you hear it was all BS anyway"
But the false sense of security interpretation is plausible too.
I wonder who holds conferences on the cutting edge research of manipulating media