Live data from Hacker News

Servers can be backdoored by exploiting buggy motherboard controll

arstechnica.com

1–10 of 10 posts

Re: Servers can be backdoored by exploiting buggy motherboard controll

#3
Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

Re: Servers can be backdoored by exploiting buggy motherboard controll

#5

*controllers Too bad Oxide's non-BMC[0] service processor or something similar isn't available on all servers. [0] https://oxide.computer/faq-friday/is-the-oxide-service-proce...

If you just don't plug in the BMC network port, you effectively have this. But people do plug in the BMC network port because it's extremely useful.

Re: Servers can be backdoored by exploiting buggy motherboard controll

#6

Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

> defense-in-depth and proper network design Damn, we're all doomed then

Re: Servers can be backdoored by exploiting buggy motherboard controll

#7

Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

There is a a server I have whose host provides a VPN for customers onto the BMC network. I don't know if they are checking which IP address I access through the VPN, and I don't really want to find out lest I get terminated.

There's another one from a host that just has it open to the internet. I bet you'd find a bunch by scanning the internet.

Re: Servers can be backdoored by exploiting buggy motherboard controll

#8
post #5

*controllers Too bad Oxide's non-BMC[0] service processor or something similar isn't available on all servers. [0] https://oxide.computer/faq-friday/is-the-oxide-service-proce...

If you just don't plug in the BMC network port, you effectively have this. But people do plug in the BMC network port because it's extremely useful.

And then you have firmwares which switch to 'in-band-management' for convenience, if they detect that.

If you don't disable that, and sometimes even then.

Making that shit available on your general uplink.

Re: Servers can be backdoored by exploiting buggy motherboard controll

#9
post #7

Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

There is a a server I have whose host provides a VPN for customers onto the BMC network. I don't know if they are checking which IP address I access through the VPN, and I don't really want to find out lest I get terminated. There's another one from a host that just has it open to the internet. I bet you'd find a bunch by scanning the internet.

This isn't the way. If you're in an engineering role, you have an ethical professional responsibility to do what's reasonably secure and pushback against unreasonable insecurity.

I was once fired (forced to "resign") from a full-time job at a major university because I refused to rush weakening the security of a credit card processing network covered by PCI-DSS because a vendor couldn't figure out how a VPN works.

Re: Servers can be backdoored by exploiting buggy motherboard controll

#10
post #7

Earlier quoted context omitted.

There is a a server I have whose host provides a VPN for customers onto the BMC network. I don't know if they are checking which IP address I access through the VPN, and I don't really want to find out lest I get terminated. There's another one from a host that just has it open to the internet. I bet you'd find a bunch by scanning the internet.

This isn't the way. If you're in an engineering role, you have an ethical professional responsibility to do what's reasonably secure and pushback against unreasonable insecurity. I was once fired (forced to "resign") from a full-time job at a major university because I refused to rush weakening the security of a credit card processing network covered by PCI-DSS because a vendor couldn't figure out how a VPN works.

Firing was the correct move. You may be protected for refusing to commit a crime, but violating PCI-DSS isn't a crime. Businesses are free to choose which of their contracts to violate and accept the risk attached to that. You could have anonymously reported the violation to the bank.