Seems insufficient that the conclusion is just to check the received board against the schematic and BOM.
It is not, but having access to schematics, bom and description of how it works would mean more people looking at it and probing it. This would be helpful in preventing large scale attacks to go for a long time but would not prevent directed attacks (like infecting a single shipment to a single customer). Also, I always thought bypass capacitors an excellent way to inject malicious hardware. Everybody is practically…
Call me jaded but the fact that Bloomberg essentially made a fake report about this type of attack made me completely disinterested in this type of attack. It's just some sensationalist crap that is meant to destroy the reputation of a company. It was never about the practicality of the attack. Just replace an entire IC and be done with it.
It's easy to image an Amazon seller replacing a microcontroller with one that contains ransomware. If you try to do the same thing with a bypass capacitor then you massively increase the amount of effort needed to execute the attack. The microcontroller attack could be as simple as emulating a keyboard and opening a virus site in internet explorer.
I don't know how many people actually pay the ransom but lets say 5% of the buyers end up paying a $500 ransom. That would be $25 extra profit per mainboard. If your mainboard is $10 cheaper than the competition customers will flock to your products and you can easily scale out your operation.