Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...
Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
11–20 of 30 posts
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#12> Bloomberg says it is in line with memory to CPUs to intercept some password validation code I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wire…
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#13>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.
We’re seeing a lot of anti Chinese and anti Russian news. I have a tendency to believe them but at the same time there’s of course never going to be reported in the US what we are doing.
That doesn't square with all the reports on US domestic and international spying, much of it in the NY Times, not to mention The Intercept and others. How do you think we know about it? Not from Chinese and Russian newspapers.
> We’re seeing a lot of anti Chinese and anti Russian news
Hmmm ... maybe we're seeing a lot of Chinese and Russian activity. If you look at coverage of the current US President, you might notice a lot of 'anti-US' news also. Under the prior administration, there was a lot of that on Fox News and in the Wall Street Journal.
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#14>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#15Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#16Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...
As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#17Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...
As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#18Couldn't this all be easily thwarted with a relatively basic firewall and network analysis of traffic emanating from a data-center? Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...
As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#19Earlier quoted context omitted.
As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…
If the rogue firmware was indeed loaded from this chip, the "bridge mode" could have been forcefully activated.
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#20> Bloomberg says it is in line with memory to CPUs to intercept some password validation code I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wire…
I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.
And I believe that once you control the BIOS image you control the boot chain of trust.