Live data from Hacker News

Supermicro boards were so bug ridden, why would hackers ever need implants?

arstechnica.com

41–50 of 81 posts

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#42
post #7

Earlier quoted context omitted.

But the effect of that would be to cause massive distrust of Chinese suppliers and cause a shift away from electronics being produced there. IC and cyber experts generally identify the Chinese as using intelligence operations for primarily economic purposes, as compared to Russian/Iranian/North Korean objectives being military or political. A Chinese military intelligence agency using cyber espionage to intentionally…

Good point, I agree with that thinking. But the actual execution of such a hardware-based attack would surely be discovered at some point anyway, and risk the same negative outcome. So then that would leave the only possible conclusion that the story just isn't true at all. In the end, none of it makes clear sense...

The difference is two-fold: actively planting a fake story means that first, the espionage is fake and thus no real intelligence can be gathered, so the only benefit is the hypothetical respect you suggested; second, the story will definitely get out, thus the potential for the negative effect is innately 100%. However, as a real intelligence operation the cost/benefit analysis is inverted, because there is a real, tangible benefit to extracting possibly sensitive commercial and national security information. And while an eventual discovery is always a possibility, it seems care was taken to ensure it would only be a small possibility, and that in any case it would be in the future, hopefully after a large amount of useful data is extracted.

So in the planted story hypothesis, there is certainty of negative outcomes with only the potential for positive outcomes, and those only intangible, while in the this-is-real hypothesis, there is near certainty of some tangible benefit with good probability of significant tangible benefit, with only a potential, distant, deniable risk of negative outcome.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#43
post #24
post #13

I don't really see why everyone is calling this implausible. Modchips have been around for at least 15 years. The idea of the clipper chip is 25 years old. At every hacker conference there are people "hacking" devices by various buses or interfaces. If there is anything working against the Bloomberg story it is that it is too plausible. Often reality clashes with imagination, but the Bloomberg story contains almost e…

It isn't implausible because of it being difficult and expensive, its implausible because there already exist much easier, cheaper, and (arguably) harder to detect ways of subverting SuperMicro motherboards. As a bonus, subverting the BMC firmware is much harder to trace to the source since it could be injected by in so many ways by so many different people. Why use a thermonuclear device when a hand grenade accompli…

I just don't think the relationship between those two things you are describing exists. If the Chinese government approaches a Chinese manufacturer with the goal of compromising US software companies adding some sort of chip that reconfigured the hardware would be the most straight forward thing for them to do.

If anything I think the idea that a Chinese manufacturer with complete access to the hardware having to execute some exploit towards the web interface to get access is far fetched. So is that you could pretend to update the firmware (surely no one is going to notice that the new version doesn't have the features you wanted?) and that dumping the firmware would be inconvenient (it would be the first thing you did if you suspected something).

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#45
Very fair article. Raises doubt in a very productive way, not the he-said she-said of previous rebuttals.

I'd go further to say it isn't just about the accuracy of the bloomberg piece, but implies bad things about their journalistic integrity. I mean, get real, Ars doesn't have an investigative journalism team. The one-sidedness of the bloomberg article becomes very apparent.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#46

Earlier quoted context omitted.

Bloomberg's claim is that a miniature device used for RF analog electronics was coopted and inserted into a board that would never have such a part designed in. This requires modifying the board artwork, the pick and place config, any automated inspection and test equipment, and adding a foreign part reel to the supply chain. It is much easier to compromise firmware directly or modify ICs that are already part of the…

This requires [et c.] Or, they could run their own fabrication facilty, where they can exert total control over the production line, in total secrecy, and you'd never know the difference, or notice a sacrifice in the fidelity of replication. Think that's impossible? Not at the nation-state level. Not in communist countries where everything is property of the government by default. Not in capitalist countries like the…

Not in capitalist countries like the United States where you can just contract a manufacturer to produce the board you want. Even parts acquisition becomes a job to be done. As long as the producer dosn't know (or even does know but can be silenced at the right level) then really, once the actual design is in hand and assuming the parts aren't too hard to get there's little to stop someone from producing a board just like a board produced elsewhere.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#47

Okay, crazier lead-foil hat time: what if this story is a crappy hoax intended to discredit/prevent from publication a real story with similar details?

I don't follow. If anything it makes the parallel story easier to publish as a sort of "me too" (no disrespect.)

Maybe it takes away from the firmware hacking version of the story because now folks are looking at components as being the source of hacks and not the firmware on the components, leading to a false sense of security when they invest mightily in analyzing components with X-rays? I could see that outcome as being plausible. If the ultimate outcome is simply to change corporate priority towards futile component verification and away from firmware verification then indeed the firmware verification vector remains safe for the attacker.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#48
post #30

Earlier quoted context omitted.

I don't hear skepticism on plausibility. I just hear skepticism based on lack of actual evidence, as there has been, to date, exactly zero. For a hardware back that could only have been done at a large scale.

This is why I am skeptical. I will not presume to know how Supermicro and Elemental operate but I find it unlikely that this would go unnoticed by both of them. The guys I work with raise hell if CRCs on firmware images don't match, much less a BOM change. There are a lot of QA breakdowns that have to happen after manufacturing for this sort of attack to be successful. Could it happen? Sure, but there should be some…

Eh... it's not quite that simple. Checking the firmware before it goes into the device is not the issue. It's after the firmware is in the (integrated) device that it's an issue. How do you check that? You have to boot the device to calculate the CRC. Now assume that the device's bootloader is compromised and that the device actually has more internal storage than you thought. Now what? Ensuring correctness of firmware to verify the device won't do something you've never seen it do is quite difficult.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#49
post #3

I would guess that large companies are refreshing with known good firmware before deploying servers? So while described approach is easier prob will not get attacker as much.

You would guess wrong because a) large companies are profit motivated and that is a cost that can be cut and b) even if you "refresh" firmware, what actually is happening in there? You don't really know, so the "refresh" may not be as effective at wiping out the attack as you had hoped.

Re: Supermicro boards were so bug ridden, why would hackers ever need implants?

#50
post #47

Okay, crazier lead-foil hat time: what if this story is a crappy hoax intended to discredit/prevent from publication a real story with similar details?

I don't follow. If anything it makes the parallel story easier to publish as a sort of "me too" (no disrespect.) Maybe it takes away from the firmware hacking version of the story because now folks are looking at components as being the source of hacks and not the firmware on the components, leading to a false sense of security when they invest mightily in analyzing components with X-rays? I could see that outcome as…

More like "Oh look, another story about extra components inserted by a big state actor. Bloomberg just got burned for this, I'm not going to risk my/my organization's reputation on the slight chance that this one is real"

Or, "Extra chips on the motherboard? You're about a month behind the news cycle and didn't you hear it was all BS anyway"

But the false sense of security interpretation is plausible too.

I wonder who holds conferences on the cutting edge research of manipulating media

Post reply on HN