Live data from Hacker News

Super Micro says review found no malicious chips in motherboards

reuters.com

271–280 of 355 posts

Re: Super Micro says review found no malicious chips in motherboards

#271

Earlier quoted context omitted.

Nothing, just like nothing will happen to the outlets who are currently pushing this "Huwai is spying on everybody" narrative with not an ounce of evidence for it except for unfounded and unsourced claims by FiveEyes intelligence services [0]. Afaik that whole Bloomberg/Super Micro thing was similarly set up, referring to "anonymous intelligence/industry services", not even naming the company that supposedly did the…

Not that Huawei is the only and surely some other brands are even worse, but still Huawei phones are full of spyware, just open NetGuard or another example here : https://mobile.twitter.com/fs0c131y/status/10515681807480135... But once again surely other brands, Western companies included, are also spying, but it doesn't change the fact that Huawei does it too.

I see people say this a lot, but I'm using an Honor 10 and have spent a bit of time this week alternately MITM proxying connections from the phone and capturing DNS at the router.

I found very infrequent calls to HiCloud (Huawei's cloud service), almost always using a HiCloud enabled app where it would make perfect sense to communicate with the service.

On the other hand, I seen third party apps (none of which were pre installed) almost constantly firing requests to analytics and ad services. Microsoft Edge was the worst culprit - virtually every action I took (opening menus, tabs, etc) triggered a request to vortex.data.microsoft.com. Spotify calls Scorecard Research in the background often, even if it appears not to be running. Google calls the connectivity check service very frequently (even when network conditions aren't changing). The BBC iplayer apps (when ostensibly not running) refresh channel and config data frequently in the background.

I see a lot of rhetoric calling out Huawei phones for being spyware ridden trash, but honestly my own research this week suggests that the privacy controls on the phone work well and that third party apps are more of a privacy threat.

Re: Super Micro says review found no malicious chips in motherboards

#272
post #162

Earlier quoted context omitted.

Regarding the five eyes sources, are we really expecting that intelligence agencies will give sources/proof?

If they want their claims to be taken seriously, then they really should. Without that, it's just hearsay, hearsay by agencies who have deceit as part of their job description and as such should be taken with a massive grain of salt. Imho they've also become shy about openly sharing sources because it allows them plausible deniability, they don't want an Iraq style curveball [0] all over again, where the attribution…

I dunno, maybe they've (who is "they" anyway?) become shy because when their claims are examined, they so often turn out to be nonsense? When was the last time anonymous "government sources" or even "five eyes official" told us something which is demonstrably true? Cuban missile crisis?

Re: Super Micro says review found no malicious chips in motherboards

#273

Earlier quoted context omitted.

Can't open the link because of rate limiting - hn effect? Anyway, is any phone-home spying? What if it phones US servers, say Google's? Unfortunately I can't think of a popular brand that doesn't spy on its users (no matter what the reasons are).

It's not just a phone-home. It's sending your entire browsing history (unencrypted!): every web request you make gets sent back to servers in China.

That's interesting. Links please?

Re: Super Micro says review found no malicious chips in motherboards

#274
post #28

Let's say Super Micro is right and there were no malicious hardware at all for sure. What are the consequences for Bloomberg for this incompetence? I mean, there needs to be something.. Just because you're a news organization, you can't simply escape with "Oh, my bad". This had real implications on stock prices of so many companies and wiped off shareholder value on many of them, including Super Micro. If Bloomberg's…

>What are the consequences for Bloomberg for this incompetence? You, not the general concept of the reader, but you personally neya. You stop trusting Bloomberg's reporting. That's the consequence. Their reputation suffers. Why do threads like this on HN always have such a desire for retribution?

> Why do threads like this on HN always have such a desire for retribution?

I, personally, am sick of being lied to. Single source reportage violates journalism 101; they really should suffer some consequences, just as someone should pay for the 2008 bubble, the Iraq war (Bill Kristol ... finally losing one of his platforms) and any number of other examples of the managerial class' screw ups from the last 20 years.

Re: Super Micro says review found no malicious chips in motherboards

#275

Earlier quoted context omitted.

Don’t think HN is any different.

For whatever reason, HN is different to me because, when discussions center around the things that I actually have expertise in, the information tends to be mostly correct. Every now and then some nonsense slips in but, for the most part, keeping people from being able to downvote and upvote everything eventually leads to a pretty informed view of whatever the topic is. Even in instances where I disagree with somethi…

HN is generally correct about established computer science and tech stuff. Anything frontier or controversial (e.g. bitcoin) or outside the narrow domain of typical Silicon Valley startups gets the exact same ignorant herd response. The point is that when the topic aligns with the expertise of the community you get quality, whereas when the topic varies you get ignorance and BS spoken just as authoritatively. Always be aware of the latter outcome!

Re: Super Micro says review found no malicious chips in motherboards

#276
post #271

Earlier quoted context omitted.

Not that Huawei is the only and surely some other brands are even worse, but still Huawei phones are full of spyware, just open NetGuard or another example here : https://mobile.twitter.com/fs0c131y/status/10515681807480135... But once again surely other brands, Western companies included, are also spying, but it doesn't change the fact that Huawei does it too.

I see people say this a lot, but I'm using an Honor 10 and have spent a bit of time this week alternately MITM proxying connections from the phone and capturing DNS at the router. I found very infrequent calls to HiCloud (Huawei's cloud service), almost always using a HiCloud enabled app where it would make perfect sense to communicate with the service. On the other hand, I seen third party apps (none of which were p…

Don't worry, no one will ever notice that or they just don't care, but anything from China is evil. I'm not Chinese but I feel poor for them.

Re: Super Micro says review found no malicious chips in motherboards

#277
post #28

Let's say Super Micro is right and there were no malicious hardware at all for sure. What are the consequences for Bloomberg for this incompetence? I mean, there needs to be something.. Just because you're a news organization, you can't simply escape with "Oh, my bad". This had real implications on stock prices of so many companies and wiped off shareholder value on many of them, including Super Micro. If Bloomberg's…

Using the press to manipulate stock prices has been the standard practice for as long as these two institutions exist. You can go way back to the last years of the 19th century and will find that there was already a thriving business going on between stock manipulators and the press.

Re: Super Micro says review found no malicious chips in motherboards

#278

Earlier quoted context omitted.

Nothing, just like nothing will happen to the outlets who are currently pushing this "Huwai is spying on everybody" narrative with not an ounce of evidence for it except for unfounded and unsourced claims by FiveEyes intelligence services [0]. Afaik that whole Bloomberg/Super Micro thing was similarly set up, referring to "anonymous intelligence/industry services", not even naming the company that supposedly did the…

Seems like anonymous sources inside the intelligence agencies is how a lot of the news gets generated these days. Anonymous figures don't have to worry about their reputation or credibility and can just leak occasionally true information to keep getting published.

When it comes to information on traded companies, people should always consider that anonymous sources are 99% of the time biased. Nobody goes out giving information about a public company for nothing, and when the information is true they will be open and present documents proving it.

Re: Super Micro says review found no malicious chips in motherboards

#279

Earlier quoted context omitted.

For whatever reason, HN is different to me because, when discussions center around the things that I actually have expertise in, the information tends to be mostly correct. Every now and then some nonsense slips in but, for the most part, keeping people from being able to downvote and upvote everything eventually leads to a pretty informed view of whatever the topic is. Even in instances where I disagree with somethi…

HN is generally correct about established computer science and tech stuff. Anything frontier or controversial (e.g. bitcoin) or outside the narrow domain of typical Silicon Valley startups gets the exact same ignorant herd response. The point is that when the topic aligns with the expertise of the community you get quality, whereas when the topic varies you get ignorance and BS spoken just as authoritatively. Always…

Good point. I think it's probably the case when a community is self-selected vs. when it's open for anyone to both create and contribute.

Re: Super Micro says review found no malicious chips in motherboards

#280

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

This is very interesting. Can you be a bit more specific about the design?

When you say you created a two terminal device; do you mean you have a PCB (or equivalent) with two IO pads which you soldered to the pads which would normally be occupied by I2C pull-up R, but on a different PCB.

Basically, I'm wondering how the attiny85 was powered.

Given your description, I'm guessing you made a local power well which floated on the SDA line similar to how a boost cap works in a buck regulator (or more generally a charge pump). This is also approximately how a one-wire device works, like say the DS28E07.

To turn a 0->1 strengthen the pull-up equivalent which is in parallel to the uC circuit. I could probably add a simple feedback circuit to make sure the pull-up is just strong enough to keep SDA above VOH_min which should help prevent the I2C driver from getting damaged. To turn 1->0 open the pull-up equivelent and let the bit leak down.

Assuming standard I2C, I just need to make sure by uC is fully booted and ready to go by the end of the start bit. Should be doable.

I think I mostly convinced myself I could build one too. Of course any board I want to attack probably uses a SPI ROM, so roughly the same idea, but in a series termination resistor. :)

Post reply on HN