Live data from Hacker News

Super Micro says review found no malicious chips in motherboards

reuters.com

301–310 of 355 posts

Re: Super Micro says review found no malicious chips in motherboards

#301

Earlier quoted context omitted.

Can't open the link because of rate limiting - hn effect? Anyway, is any phone-home spying? What if it phones US servers, say Google's? Unfortunately I can't think of a popular brand that doesn't spy on its users (no matter what the reasons are).

It's not just a phone-home. It's sending your entire browsing history (unencrypted!): every web request you make gets sent back to servers in China.

I am having a very hard time believing this statement is in any way true. If you have a link to details, now is the time to provide it.

Re: Super Micro says review found no malicious chips in motherboards

#302
What are the odds that Bloomberg ran this story under pressure/collusion from Supermicro competitor(s) in Taiwan, US fed govt or other business actors trying to tarnish China's image? That they would knowingly run such a big story without commensurate easily verified evidence and reliable sources is irrationally foolish for such a large news shop.

Re: Super Micro says review found no malicious chips in motherboards

#303
post #295

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

Hardware hacks are easy for anyone who works in that industry. What's hard is making software that runs on that hardware do anything useful -- it would need to communicate with external command&control and know how to read interesting data or send interesting effectful commands to the mainboard. Making the main board fail arbitrarily would be easy, but controlling the board or exfiltrating data is hard.

I have the entirely opposite opinion - once you have managed to attack the supply chain and covertly deploy, say, some hardware can write a few hundred arbitrary bytes to the firmware (which was described as the attack vector by Bloomberg), then that's essentially game over. Perhaps designing the hardware hack is easy, but getting the malicious chip on the devices shipping to your targets and keeping it a secret is not trivial.

"communicate with external command&control and know how to read interesting data or send interesting effectful commands to the mainboard." is hard only in the sense that it takes some effort, however, this requires pretty much the same capabilities and skills as every engineered malware we've encountered, so you can assume that every serious adversary can do it, not only nation state adversaries but many serious commercial pentesting companies and cybercrime teams have demonstrated such capabilities.

I can imagine an attacker that can make the "hard" software required but doesn't have the capability to insert that modified hardware within a supply chain - as in, it's not even assumption, for pretty much every intelligence agency it's known that they can easily do software which "would need to communicate with external command&control and know how to read interesting data or send interesting effectful commands to the mainboard" - even just counting things that have failed (because we've detected and analyzed and attributed them), there's clear evidence that they can do it because they've done it many times.

I literally can't imagine an agency that can pull off the supply chain attack but doesn't have the capability to write software to control the board and exfiltrate data.

Re: Super Micro says review found no malicious chips in motherboards

#304
post #271

Earlier quoted context omitted.

Not that Huawei is the only and surely some other brands are even worse, but still Huawei phones are full of spyware, just open NetGuard or another example here : https://mobile.twitter.com/fs0c131y/status/10515681807480135... But once again surely other brands, Western companies included, are also spying, but it doesn't change the fact that Huawei does it too.

I see people say this a lot, but I'm using an Honor 10 and have spent a bit of time this week alternately MITM proxying connections from the phone and capturing DNS at the router. I found very infrequent calls to HiCloud (Huawei's cloud service), almost always using a HiCloud enabled app where it would make perfect sense to communicate with the service. On the other hand, I seen third party apps (none of which were p…

I worked for several US-based handset manufacturers as a consultant. It's common to have the handset mfgr host features on its own cloud such that the phone is entirely dependent on it to function: the cloud goes away, large swaths of phone functionality breaks. It sucks but it's true.

Re: Super Micro says review found no malicious chips in motherboards

#306
post #204

Earlier quoted context omitted.

You're claiming they can be compelled to lie.

If the story was true, only a few people in each company would have been aware of these vulnerabilities, and they might not have been allowed to talk to anyone about them by FBI. Then, even if others were informed, they would have to pretend, that they were not.

same can be said for "bush did 911" lmao

Re: Super Micro says review found no malicious chips in motherboards

#308
post #295

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

Hardware hacks are easy for anyone who works in that industry. What's hard is making software that runs on that hardware do anything useful -- it would need to communicate with external command&control and know how to read interesting data or send interesting effectful commands to the mainboard. Making the main board fail arbitrarily would be easy, but controlling the board or exfiltrating data is hard.

You don't need to exfiltrate data, just detect if some crypto workload was occurring and weaken it in a way known to you.

Re: Super Micro says review found no malicious chips in motherboards

#309

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

I would really love to see some photos and a schematic if you're willing to share, that sounds awesome.

Re: Super Micro says review found no malicious chips in motherboards

#310

Earlier quoted context omitted.

WRT the how could they get it so wrong question, I guess it's time for the obligatory link to Michael Crichton's essay "Why Speculate?" and his discussion of the "Murray Gell-Mann Amnesia Effect" [1] Money quote: "You open the newspaper to an article on some subject you know well. In Murray's case, physics. In mine, show business. You read the article and see the journalist has absolutely no understanding of either t…

AKA the Reddit Effect. Everyone on Reddit posts as if they know what they're talking about when, in reality, they only have a cursory knowledge of it and yet the entire site is somehow treated as a curated collection of high-quality, factual information.

I saw AskHistorians and thought that it was exactly that. I thought I would put together a small collection of subreddits that produce similar quality content. Little did I know that the rest of the website is memes and the same flavor-of-the- month jokes recycled on every post...
Post reply on HN