Bloomberg got the ads revenue, and people who read Bloomberg won't stop doing that just because of this. The only thing changed is the lower cosine distance between China and hacking in the English corpus, as well as people's minds.
It's much more than that. They have destructed 100's of billions of dollars of capital.
Super Micro says review found no malicious chips in motherboards
261–270 of 355 posts
Re: Super Micro says review found no malicious chips in motherboards
#262Earlier quoted context omitted.
>A nation state adversary could trivially miniaturize this to the size and form of an SMT resistor, and use a much more capable uC in the process. And sandwich it between the PCB layers. No way to find even upon close up inspection without Xraying the board itself, and even interpreting the Xray image of modern multilayer board would be a nontrivial task. I dont think Supermicro did it, at least for statistically mea…
Or just replace one of the existing chips on the i2c bus with an identical but malicious one. I don't know how you would even detect that, short of decapping and scanning the die in.
Re: Super Micro says review found no malicious chips in motherboards
#263Earlier quoted context omitted.
This is certainly how things ought to work, but it's far from clear that it does. A reporter on an international affairs beat can't possibly dismiss sources as broad as the State Department or CIA - which makes it very possible to rotate through mouthpieces as they're proven unreliable. (And that's usually when clear dishonesty is found, not just plausibly-mistaken claims.) And anonymity is usually protected even whe…
> A reporter on an international affairs beat can't possibly dismiss sources as broad as the State Department or CIA It's actually worse, the power dynamics are completely lopsided: He/she can't disgruntle his governmental sources or else there's the very real possibility of being cut out of the loop/any access at all in the future. Which isn't a great prospect for any journalist because you can't get any "scoops" wh…
This is an important part of Herman/Chomsky's "Propaganda Model" of media.
Re: Super Micro says review found no malicious chips in motherboards
#264Let's say Super Micro is right and there were no malicious hardware at all for sure. What are the consequences for Bloomberg for this incompetence? I mean, there needs to be something.. Just because you're a news organization, you can't simply escape with "Oh, my bad". This had real implications on stock prices of so many companies and wiped off shareholder value on many of them, including Super Micro. If Bloomberg's…
Are you sure it isn't Bloomberg who was misled? Is that more or less likely than a billion dollar company declining to confirm a story that would cost them hugely? In lieu of proof either way, what punishment do you think is just -- and for whom?
Re: Super Micro says review found no malicious chips in motherboards
#265From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…
How good is the idea while you could be caught with physical evidence?
Re: Super Micro says review found no malicious chips in motherboards
#266From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…
Re: Super Micro says review found no malicious chips in motherboards
#267All of these statements seem to be pretty well crafted. It is entirely possible that they found components that don't belong, but don't consider them malicious without the underlying payload that gets uploaded.
Re: Super Micro says review found no malicious chips in motherboards
#268From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…
> Just saying it's a great (black hat) idea, and it works. How good is the idea while you could be caught with physical evidence?
Re: Super Micro says review found no malicious chips in motherboards
#269Earlier quoted context omitted.
AKA the Reddit Effect. Everyone on Reddit posts as if they know what they're talking about when, in reality, they only have a cursory knowledge of it and yet the entire site is somehow treated as a curated collection of high-quality, factual information.
Don’t think HN is any different.
Re: Super Micro says review found no malicious chips in motherboards
#270Earlier quoted context omitted.
The source material is still on Bloomberg's website. Look at it, its a 0402 Decoupling Capacitor: https://www.bloomberg.com/toaster/v2/charts/85c4e100b7ab4a8b... The full article here: https://www.bloomberg.com/news/features/2018-10-04/the-big-h... ------- As for what that thing is... its this (or something like this): https://www.digikey.com/product-detail/en/avx-corporation/W2... That's an 8-pin decoupling capacito…
It literally says, in the very picture you linked to, that the chips were built to disguise as coupling capacitors.
Decoupling capacitors perform a very specific, and very easy to see function. They have two pins: C+ and C-, and the capacitor tries to keep C+ and C- at roughly the same voltage level across time. In particular, Decoupling capacitors are fully passive (non-powered) devices.
Ex: If the C+ and C- pins are 3V (on the average), then a decoupling capacitor will help keep the voltage stay at 3V. The mechanical analogue would be a flywheel: it helps regulate the voltage and prevents voltage spikes.
-------------
It makes NO SENSE for a chip to disguise itself as a decoupling capacitor. There are lots of other chips that would be a better disguise. The fundamental premise and explanation is a joke to begin with.
Like, how are you supposed to hack into a computer at the electrical level using only two pins?
Mind you: an intelligent chip-level hacking device needs... at minimum... Power, and Ground. Bam, you already used up the two pins that a decoupling capacitor has... and you haven't even touched memory or other issues yet.
Clearly, the reporters have gotten something wrong. I can believe that the reporters maybe have a real story here, but they are wandering into technical details that they clearly do NOT understand. Clearly, a mistake or misunderstanding is somewhere in that explanation.
At very least, a chip-level attacker would need... I dunno, maybe 3 or 4 pins, at the minimum. I haven't thought about it much, but its instinctively obvious that the 2-pins of a decoupling capacitor is insufficient to do any kind of hacking.