Live data from Hacker News

Super Micro says review found no malicious chips in motherboards

reuters.com

341–350 of 355 posts

Re: Super Micro says review found no malicious chips in motherboards

#341

There has to be more to this story that we don't know. Bloomberg has a lot to lose by publishing such a harsh claim that's not extremely fact-checked. Reliable newspapers generally don't throw around anonymous government sources without doing background checks on these people. I have little doubt that they got the information from who they say they did. At this point I wonder if they should stop protecting their sour…

I don't see why people discard the scenario where both the sources and supermicro are right, but there's been a misunderstanding.

This could happen, for example, with a tabletop exercise. I know the military does these, so it's not unlikely the CIA does them too. The CIA dreamt up a scenario where a US company's hardware was compromised by China, and simulated their response for training. Since it's just an exercise, it obviously wasn't as secret, so employees would have probably not feared to talk about it loudly at e.g. lunch break. Someone overhears, it, runs to bloomberg and we have the situation we have now.

Not the only scenario, but something along these lines is my theory.

Re: Super Micro says review found no malicious chips in motherboards

#342
post #328
post #288

Earlier quoted context omitted.

« Basically, I'm wondering how the attiny85 was powered » You guys are overthinking this. Server motherboard PCBs are usually 4-8 layers with GND and VCC planes available near any component. The hackers, according to Bloomberg, modified the motherboards, so presumably they would simply add vias to the GND and VCC planes to power their rogue chip. You don't gain much by going the trouble of making the chip self-powere…

The assembler still has to put a special SKU 5k resistor (with our BMC modifying framework burnt in to it) on the modified PCB without anyone noticing though. I don't follow your conclusion that only the PCBs would have to be swapped.

The attackers supposedly installed the tiny rogue chip, sandwiched between the layers of the PCB (which is unusual and the main innovation of this whole attack), before the PCBs reached the assembler. The assembler start soldering components without knowing one is already hidden in there...

Re: Super Micro says review found no malicious chips in motherboards

#343

Earlier quoted context omitted.

Or maybe a start to the democratic process to encourage lawmakers to discover nuance and legislate. Or maybe a good place for someone with knowledge to show why it's a bad idea and what the arguments are that have been struggled with. One person getting irked because another happily destroys reputation without any consequence is natural. Reputation is too important. A single person wanting to see consequence does not…

I feel like there's an argument to be made that every firebombing mob started with a single person wishing some consequence. An idea has to start somewhere.

Well yes.

But that doesn't mean we should outlaw speech... Because speech leads to good things a lot more often than firebombing mobs.

Those people we can put in jail. Only those.

The rest are helpful or neutral, even if you don't agree with them. Democracy (in any form) grows stronger with dissent/speech.

Re: Super Micro says review found no malicious chips in motherboards

#344
post #28

Let's say Super Micro is right and there were no malicious hardware at all for sure. What are the consequences for Bloomberg for this incompetence? I mean, there needs to be something.. Just because you're a news organization, you can't simply escape with "Oh, my bad". This had real implications on stock prices of so many companies and wiped off shareholder value on many of them, including Super Micro. If Bloomberg's…

Thats all the shorts were doing to tesla.. create fake news to affect the stock price.. whats the difference? (Serious question)

Re: Super Micro says review found no malicious chips in motherboards

#345

Evaluating this is tricky. On the one hand, Bloomberg claims it's a well sourced article, not a single person's unsubstantiated claim. On the other, Super Micro claims an audit showed nothing, but then they have an incentive to be less than honest, or to have performed a very superficial check. And couldn't an audit simply miss the issue if the malicious functionality were embedded in an otherwise legitimate chip? Ei…

Super Micro didn't perform the audit of themselves (that would be silly), it was done by Nardello & Co as per the article.

Yes, but the level of detail requested for the audit would be dictated by Super Micro. For example, if the request was to audit boards against the design specs, the audit would never catch something inserted during the design phase. Nor would it catch malicious functionality inserted as part of a legitimate chip. It seems like the potential number of attack vectors is extremely high if the design &/or manufacture process has been subverted.

Alternatively, if there was no attack, it becomes exceedingly difficult to prove the negative. But that also leaves us with the perplexing situation of multiple sources-- 17 from different companies and NSA-- deceiving Bloomberg reporters. Or Bloomberg reporters themselves deceiving everyone. In the later case the motives are clear. It's a career-making story that can't easily be disproved. In the former case the motives are less clear: a desire to smear Super Micro? Who benefits? A desire to stoke anti-China fear? It's all very strange.

Re: Super Micro says review found no malicious chips in motherboards

#346

Earlier quoted context omitted.

Nothing, just like nothing will happen to the outlets who are currently pushing this "Huwai is spying on everybody" narrative with not an ounce of evidence for it except for unfounded and unsourced claims by FiveEyes intelligence services [0]. Afaik that whole Bloomberg/Super Micro thing was similarly set up, referring to "anonymous intelligence/industry services", not even naming the company that supposedly did the…

Not that Huawei is the only and surely some other brands are even worse, but still Huawei phones are full of spyware, just open NetGuard or another example here : https://mobile.twitter.com/fs0c131y/status/10515681807480135... But once again surely other brands, Western companies included, are also spying, but it doesn't change the fact that Huawei does it too.

Please notice that there also are requests to suspicious Western sites like Google as well, which were caught for collecting data before.

I have examined network traffic from my Chinese noname phone, and it also sends data to Chinese servers and to Google.

Also when you visit most websites, there will be a request to Google's data collector service.

Re: Super Micro says review found no malicious chips in motherboards

#347

Earlier quoted context omitted.

If it's a national security risk they might not have needed to be compelled to lie at all, but decided to do so themselves. This would be big enough to damage their entire supply chain if they did publicly verify it as truth.

You're claiming they'd commit fraud.

who would prosecute them for it if it is national security related?

Re: Super Micro says review found no malicious chips in motherboards

#348
post #98

Earlier quoted context omitted.

Even if Bloomberg's story is completely true, Apple / Amazon / Super Micro might have no other choice, but to firmly deny it. Because in that case, it's United States vs. China, not just some publisher vs. a few publicly traded companies. When national security interests and international relationships between two largest economies in the world are at stake, it's not Tim Cook or Jeff Bezos, who get to decide, what ca…

Not correct. Instead of denying it, they could either confirm it, or non-denial deny it. They would not knowingly issue specific and categorical denials that are lies.

In the cases as this, if you don't firmly deny everything, you basically confirm that it's true. And people responsible for issuing categorical denials might have had no awareness of any vulnerabilities, even if they actually existed.

Re: Super Micro says review found no malicious chips in motherboards

#349
post #295

Earlier quoted context omitted.

Hardware hacks are easy for anyone who works in that industry. What's hard is making software that runs on that hardware do anything useful -- it would need to communicate with external command&control and know how to read interesting data or send interesting effectful commands to the mainboard. Making the main board fail arbitrarily would be easy, but controlling the board or exfiltrating data is hard.

I have the entirely opposite opinion - once you have managed to attack the supply chain and covertly deploy, say, some hardware can write a few hundred arbitrary bytes to the firmware (which was described as the attack vector by Bloomberg), then that's essentially game over. Perhaps designing the hardware hack is easy, but getting the malicious chip on the devices shipping to your targets and keeping it a secret is n…

I just can't imagine anyone exfiltrating the data on a corporate level at any scale without raising alarms. It's just not realistic, once it leaves the board it's pretty easy to see over a network.

Now specific targeted attacks is more believable, at that point though I'd think a one off MITM hardware swap would be more likely.

Re: Super Micro says review found no malicious chips in motherboards

#350
post #331

From a technical perspective I found this story compelling, so I tried out a simple hack to see if it were "possible". Using an attiny85 uC, a couple resistors, a cap, and a couple diodes I had laying around, I was able to wire up a two terminal "device" that pretty much acts like a 5k pull up resistor on a I2C line.... But when you pass data through the signal line (SDA) wire it can read and modify it. It is crude a…

I am having trouble understanding and believing. How did you get an ostensible power terminal (for pull up) and two terminals for MiTM (input and output) from two terminals? Assuming a situation where there are other pullups on the wire, how did you assert the low state (short to ground) without a connection to ground?

Yeah I didn't think so.
Post reply on HN