Live data from Hacker News

Super Micro says review found no malicious chips in motherboards

reuters.com

261–270 of 355 posts

Re: Super Micro says review found no malicious chips in motherboards

#261

Bloomberg got the ads revenue, and people who read Bloomberg won't stop doing that just because of this. The only thing changed is the lower cosine distance between China and hacking in the English corpus, as well as people's minds.

It's much more than that. They have destructed 100's of billions of dollars of capital.

supermicro was not worth that much.

Re: Super Micro says review found no malicious chips in motherboards

#262
post #257
post #255

Earlier quoted context omitted.

>A nation state adversary could trivially miniaturize this to the size and form of an SMT resistor, and use a much more capable uC in the process. And sandwich it between the PCB layers. No way to find even upon close up inspection without Xraying the board itself, and even interpreting the Xray image of modern multilayer board would be a nontrivial task. I dont think Supermicro did it, at least for statistically mea…

Or just replace one of the existing chips on the i2c bus with an identical but malicious one. I don't know how you would even detect that, short of decapping and scanning the die in.

That would be as easy as getting a same sized chip that is, say, an attiny, a bit of sand-papering and a laser to re-etch the package. If you had access to a wire bonding machine, not difficult, you could mount a second die in a de-capped package and cap it up with a bit of black resin. This would not require state level actors. Bunny Huang type of guys could do it.

Re: Super Micro says review found no malicious chips in motherboards

#263

Earlier quoted context omitted.

This is certainly how things ought to work, but it's far from clear that it does. A reporter on an international affairs beat can't possibly dismiss sources as broad as the State Department or CIA - which makes it very possible to rotate through mouthpieces as they're proven unreliable. (And that's usually when clear dishonesty is found, not just plausibly-mistaken claims.) And anonymity is usually protected even whe…

> A reporter on an international affairs beat can't possibly dismiss sources as broad as the State Department or CIA It's actually worse, the power dynamics are completely lopsided: He/she can't disgruntle his governmental sources or else there's the very real possibility of being cut out of the loop/any access at all in the future. Which isn't a great prospect for any journalist because you can't get any "scoops" wh…

> Which isn't a great prospect for any journalist because you can't get any "scoops" when your competitors have privileged access to information.

This is an important part of Herman/Chomsky's "Propaganda Model" of media.

https://en.wikipedia.org/wiki/Propaganda_model

Re: Super Micro says review found no malicious chips in motherboards

#264
post #28

Let's say Super Micro is right and there were no malicious hardware at all for sure. What are the consequences for Bloomberg for this incompetence? I mean, there needs to be something.. Just because you're a news organization, you can't simply escape with "Oh, my bad". This had real implications on stock prices of so many companies and wiped off shareholder value on many of them, including Super Micro. If Bloomberg's…

Why does there need to be something more? Do you trust Bloomberg the same amount you did bebfore the story was published? Are you buying just as many Businessweeks as before?

Are you sure it isn't Bloomberg who was misled? Is that more or less likely than a billion dollar company declining to confirm a story that would cost them hugely? In lieu of proof either way, what punishment do you think is just -- and for whom?

Re: Super Micro says review found no malicious chips in motherboards

#265

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

> Just saying it's a great (black hat) idea, and it works.

How good is the idea while you could be caught with physical evidence?

Re: Super Micro says review found no malicious chips in motherboards

#266

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

Probably a win win for US Megacorp Inc and China that nothing malicious was found. Every company even Apple has a line to draw what threatens their long term prospects if things got out.

Re: Super Micro says review found no malicious chips in motherboards

#267
But did they find malicious chips elsewhere? And what is their definition of motherboard, chips and malicious?

All of these statements seem to be pretty well crafted. It is entirely possible that they found components that don't belong, but don't consider them malicious without the underlying payload that gets uploaded.

Re: Super Micro says review found no malicious chips in motherboards

#268

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

> Just saying it's a great (black hat) idea, and it works. How good is the idea while you could be caught with physical evidence?

if you are a state actor implanting devices on your soil why would you care?

Re: Super Micro says review found no malicious chips in motherboards

#269

Earlier quoted context omitted.

AKA the Reddit Effect. Everyone on Reddit posts as if they know what they're talking about when, in reality, they only have a cursory knowledge of it and yet the entire site is somehow treated as a curated collection of high-quality, factual information.

Don’t think HN is any different.

For whatever reason, HN is different to me because, when discussions center around the things that I actually have expertise in, the information tends to be mostly correct. Every now and then some nonsense slips in but, for the most part, keeping people from being able to downvote and upvote everything eventually leads to a pretty informed view of whatever the topic is. Even in instances where I disagree with something, there's usually a well-reasoned response that includes some support whereas, with Reddit, it's just a bunch of unfounded statements with no backup whatsoever.

Re: Super Micro says review found no malicious chips in motherboards

#270

Earlier quoted context omitted.

The source material is still on Bloomberg's website. Look at it, its a 0402 Decoupling Capacitor: https://www.bloomberg.com/toaster/v2/charts/85c4e100b7ab4a8b... The full article here: https://www.bloomberg.com/news/features/2018-10-04/the-big-h... ------- As for what that thing is... its this (or something like this): https://www.digikey.com/product-detail/en/avx-corporation/W2... That's an 8-pin decoupling capacito…

It literally says, in the very picture you linked to, that the chips were built to disguise as coupling capacitors.

I'm not sure if you understand my point then.

Decoupling capacitors perform a very specific, and very easy to see function. They have two pins: C+ and C-, and the capacitor tries to keep C+ and C- at roughly the same voltage level across time. In particular, Decoupling capacitors are fully passive (non-powered) devices.

Ex: If the C+ and C- pins are 3V (on the average), then a decoupling capacitor will help keep the voltage stay at 3V. The mechanical analogue would be a flywheel: it helps regulate the voltage and prevents voltage spikes.

-------------

It makes NO SENSE for a chip to disguise itself as a decoupling capacitor. There are lots of other chips that would be a better disguise. The fundamental premise and explanation is a joke to begin with.

Like, how are you supposed to hack into a computer at the electrical level using only two pins?

Mind you: an intelligent chip-level hacking device needs... at minimum... Power, and Ground. Bam, you already used up the two pins that a decoupling capacitor has... and you haven't even touched memory or other issues yet.

Clearly, the reporters have gotten something wrong. I can believe that the reporters maybe have a real story here, but they are wandering into technical details that they clearly do NOT understand. Clearly, a mistake or misunderstanding is somewhere in that explanation.

At very least, a chip-level attacker would need... I dunno, maybe 3 or 4 pins, at the minimum. I haven't thought about it much, but its instinctively obvious that the 2-pins of a decoupling capacitor is insufficient to do any kind of hacking.

Post reply on HN