Live data from Hacker News

Super Micro says review found no malicious chips in motherboards

reuters.com

21–30 of 355 posts

Re: Super Micro says review found no malicious chips in motherboards

#21

The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?

What bothers me most about this article is that it's based around what "Super Micro says" -- why would I care about what Supermicro says? They are the ones being accused of having backdoors in their chips.

I would've liked to hear this directly from the company doing the audit, without Super Micro's own "interpretation".

The second thing that bothers me about this story is that it was Supermicro that paid for the audit. Maybe there was no one else going to do it, or maybe they just thought to get ahead of anyone else trying to review their chips. I don't know, but it doesn't sit well with me.

Only recently we saw at least two major tech companies skirt FCC's privacy monitoring by paying themselves for the audits: Google and Facebook. Both had multiple major privacy scandals in the past couple of years, but somehow all of these privacy issues were completely missed by the companies auditing them.

Re: Super Micro says review found no malicious chips in motherboards

#22
People worry about malicious chips in instances like this and I mean it's a valid concern but one method of attack I've always thought would be effective and extremely dangerous is strategic placing a component in a circuit that, if it fails, disables the entire device then you simply need a way to activate it.

Radio.

Design a circuit, or better something that appears to be a capacitor and functions as a capacitor but has a small internal compartment at say the top so that it performs at less than what it is rated for but has a small circuit that over-volts via a joule thief and causes a failure. Have the trigger be a small receiver that activates at a certain frequency probably in the ELF or SLF range with just a few bits needed as the activation key.

Put that into the supply chain of whatever industry and when you want to disrupt to cause economic damage, or even as part of causing a bit of chaos preceding a military attack, fire up your ELF station and start pumping out the few bits of data to activate.

ELF will penetrate hundreds of meters of water, it should reach inside most buildings and even if you only had something like a 5% success rate you'd disable a LOT of whatever you'd installed them in. If it's networking hardware, you could likely cripple anything that relies on the internet by causing considerable distributed failures.

Re: Super Micro says review found no malicious chips in motherboards

#23

Has Bloomberg even replied to the "Uhm, WTF you talking about Willis" responses from Apple/Amazon? I don't recall seeing one. I wonder what they will say now.. How can they just make up a story like this and it can slide?

To be super cynical: They got their ad revenue from the story, why would they care?

Re: Super Micro says review found no malicious chips in motherboards

#24

The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?

>is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? Absolutely possible, even somewhat plausible but unlikely. Conspiracies are hard to maintain "2 can keep a secret if 1 of them is dead". You could outright threaten someone with any number of means to get them to comply with your wishes, this is how espionag…

A US intelligence agency nowadays would just issue a National Security Letter and force you to not say anything otherwise you go to jail. Most people really don't want to go to jail. An intelligence agency would really only resort to blackmail or extortion if they were operating in a foreign country where they couldn't outright bribe someone.

Re: Super Micro says review found no malicious chips in motherboards

#25

The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?

It's rather easy for someone to mislead a BP reporter who understands little about the technical details but is very eager to publish something shocking.

The reporter may have emailed a few dozen security researchers to verify the story, but those who don't believe in the story are less likely to reply (and the reporter is more likely to ignore them), leading to a sampling bias.

Re: Super Micro says review found no malicious chips in motherboards

#26

The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?

The media falls for bullshit all the time, Weapons of mass destruction, incubator babies in Kuwait, etc. They are in the business of making money and not getting the story right and since there is hardley any consequences for them why would they care?

Bloomberg here will blame its source and take no responsibility.

Re: Super Micro says review found no malicious chips in motherboards

#27

The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?

An auditor would not have found anything because the alleged attack occurred several years ago and would most likely have been targeted at a limited number of boards, which would have been seized a long time ago.

The result of this audit does not inform about anything related to the allegations published by Bloomberg.

I think it's more about re-building confidence by showing that Supermicro products on sale now can be trusted.

Re: Super Micro says review found no malicious chips in motherboards

#28
Let's say Super Micro is right and there were no malicious hardware at all for sure. What are the consequences for Bloomberg for this incompetence? I mean, there needs to be something..

Just because you're a news organization, you can't simply escape with "Oh, my bad". This had real implications on stock prices of so many companies and wiped off shareholder value on many of them, including Super Micro.

If Bloomberg's story was false, they shouldn't just walk away like that because "it's the free press".

Re: Super Micro says review found no malicious chips in motherboards

#29
post #14

The question I have is: is it possible that there was such an incredible threat to national security that even an auditor could be convinced by a federal agency to give a false report? If it really didn't happen, how could a reputable news agency get a report so wrong? What exactly is going on here?

I think the most likely explanation is that Bloomberg got played by the sources who perhaps wanted to trade on the price action the story would obviously cause. We don't really know anything about Bloomberg's sources we do know the nature of all the parties denying any of this is true.

Nope. The only named source in the article said on Twitter that the journalist reported speculation about possible attacks as facts. The story was fabricated by the journalist. How it got through fact-checking, I don't know.

Re: Super Micro says review found no malicious chips in motherboards

#30

People worry about malicious chips in instances like this and I mean it's a valid concern but one method of attack I've always thought would be effective and extremely dangerous is strategic placing a component in a circuit that, if it fails, disables the entire device then you simply need a way to activate it. Radio. Design a circuit, or better something that appears to be a capacitor and functions as a capacitor bu…

Only problem with LF stuff is that you need a pretty big antenna. You would be better off designing a chip with an RF section that operates in the GHz range so you can get away with a tiny microstrip antenna or with the antenna inside the chip.
Post reply on HN