Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

101–110 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#101
What's interesting to me in all this is not the immediate response but what the medium- to long-term impact will be.

Does anyone doubt that semiconductor/electronics manufacturing will become a strategic industry in the same realm as uranium refining?

I think we'll see electronics supply chain integrity play a growing role in major project delivery in the years to come.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#103

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

My understanding is that certain parts on the PCB were swapped out for malicous parts. If that's the case, it's probably not something that could be uncovered by a purley visual inspection. The 'spy' chips were likely made to look identical to the original parts.

That’s not what the BW/Bloomberg story claimed - it specifically called out a chip that wasn’t on the official BOM and had been added to the build.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#104
post #38

Earlier quoted context omitted.

and if it is correct?

Following the first story it was reported that Amazon had already ditched Supermicro as a supplier.

Given Amazon's scale, I would be very surprised if they're not either leveraging Open Compute designs or doing something similar with custom designs similar to open compute. Supermicro makes nice motherboards and servers, but they definitely are addressing general purposes, and something tuned more towards the specific needs of Amazon could be a lot more cost effective; even if that just means getting hardware that runs OpenBMC so the BMC firmware isn't complete trash.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#105
post #17

I find it hard to believe, that Bloomberg would publish an extremely detailed story involving some of the largest public companies in the world, knowing that it is entirely false. The cost of reputation is just too high.

You can read this story as a CYA because they overstepped in the first story. The have good details here. But in the Apple rebuttal, they note Bloomberg only had a single source for the Apple claims.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#106
post #26

Earlier quoted context omitted.

I'm not sure I believe this one as much, just based on the part you quoted. I can see a chip manipulating the BMC/IPMI flash to make it do things it shouldn't. I don't see how an ethernet port could be modified to be interesting. They're typically after the magnetics, or contain the magnetics themselves, so the only source of power would be the activity LEDs, or something, or maybe we assume a custom PCB as well. You…

You could easily DoS obviously, but beyond that I agree that it seems tricky to do anything worthwhile.

It could just be a sort of beacon to help identify where hardware went after the manufacturing process. If the same company is building the same hardware, the agent can slip in something more nefarious to make sure they target the right company. Servers are commodity products but they aren't manufactured in mass quantities like phones are. If a company orders thousands of them, that's likely thousands that will need to be made. A chinese manufacturing plant gets contracted to spin up production and an implant is slipped into some of the first boards just to see where they go. You don't want an expensive hardware trojan to end up in a Fortnite server; you want to hit Apple, Google, Lockheed Martin, Spacex, anyone with valuable IP or information. The more beacon implants you throw out there, the more likely someone will find one and you don't want to get caught too early in the game. Once those implants come online and phone home, you have a better idea where the remaining boards are going and slip in the real deal implants, the ones that will actually get you a backdoor.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#107

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

But they probably can force a handful of engineers to tell nothing to their employer, who would be vehemently denying in good faith.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#108
post #9

They don’t say what the hack was and definitely do not say it was one of their pins. Probably some truth here, but as hard as they try, does not seem supportive of their “chinese pin” theory. Very suspicious that this is related, I’m guessing they’re trying to do anything to cover their asses.

Sounds like the Ethernet connector module was not from the, ahem, correct manufacturer: “Appleboum said one key sign of the implant is that the manipulated Ethernet connector has metal sides instead of the usual plastic ones. The metal is necessary to diffuse heat from the chip hidden inside, which acts like a mini computer. "The module looks really innocent, high quality and 'original' but it was added as part of a…

I've never seen an onboard Ethernet jack that doesn't have metal sides. The only places I've seen all-plastic Ethernet jacks are consumer networking gear and really ancient add-on cards. That makes me wonder if their source actually knows what he's talking about, especially given the lack of technical details about how this works.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#109
post #57

Could be due to losses in "translation", but this paragraph seems odd: > Three security experts who have analyzed foreign hardware implants for the U.S. Department of Defense confirmed that the way Sepio's software detected the implant is sound. One of the few ways to identify suspicious hardware is by looking at the lowest levels of network traffic. Those include not only normal network transmissions, but also analo…

If you look at the activity in the frequency domain, you might find a clock that's present in adulterated hardware that's missing in the nominal hardware. > exposed power consumption of random periphery parts Sampling these analog signals is done outside of the computer itself. Even if it were exposed via i2c, you couldn't trust anything that it would tell you.

To me the article reads like it's a purely software solution, thus my confusion, but that might be misinterpretation.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#110
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

You would recognize what looks like an extra resistor?
Post reply on HN