Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

131–140 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#131

I really hope that this is the straw that breaks the back of all these "management engines" Like seriously, why does my hobby consumer motherboard need that feature? Corp IT only ever deploys to large fleets of OEM machines.

The management engine in question is an ASpeed standalone part which is only used in large-scale server deployments, not the CPU MEs that you're forced into.

Re: Making sense of the alleged Supermicro motherboard attack

#132

Earlier quoted context omitted.

Passives don't have enough pins to do much of anything, unless it's an array of passives in a single package that happens to be on power, gnd and data lines at once. But, I'm not sure but it seems like a bit of a red herring. Reading the article the chip in question doesn't sound passive at all: "The Supermicro board here appears to have a QSPI chip, but also a space for an SPI chip as a manufacturing-time option. Th…

Did you see the comment above that QSPI boots up as SPI and then switches over to QSPI?

It can't be QSPI, he's forgetting the clock and (potentially) chip-select lines.

Re: Making sense of the alleged Supermicro motherboard attack

#133
post #94

Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.

> Why wouldn’t a company notice any of the outbound traffic using firewalls? This is telling you that your experience is limited, not that the story is wrong. Trying to do egress filtering at scale is extremely hard for all but the most basic threats. If they open a socket to data-collector.pla.cn, yes, probably a majority of large shops would notice that within a few months but what if it's just a connection to S3/E…

General practice for things like BMC and other out of band control systems is to put them on isolated vlans and default deny any non-approved traffic.

There is no way that any large tech company security operation misses this traffic phoning home from a management vlan.

Re: Making sense of the alleged Supermicro motherboard attack

#134

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It's as hard to imagine as the NSA's surveillance systems. I.e., it's not. The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done. China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the fu…

Like hiding cameras in Xerox machines: https://electricalstrategies.com/about/in-the-news/spies-in-...

Re: Making sense of the alleged Supermicro motherboard attack

#135

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

> ... high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. MFG test guy here (not supermicro!) Not necessarily. Automated production tests are there to configure and exercise the system and confirm it works as specified. Such tests are good at things like finding bad solder joints, pick-and-place mishaps, misconfiguration of firmware and weeding out product that fai…

They would be able to detect rogue component(s) if AOI, Automated Optical Inspection, was done.

However, if the source files already had the component(s) on it, it would pass all tests and QC.

Re: Making sense of the alleged Supermicro motherboard attack

#136
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

I would really hope that this will give all the RISC-V open source effort some traction in the server / DC market. Certainly big corporations like Google, Facebook, Amazon and others could pull it off.

Re: Making sense of the alleged Supermicro motherboard attack

#137
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

It's just my opinion, and so I held off saying, yesterday, but: The immediate economic outfall (co-morbid with institutional panic) would be so severe that this aspect alone would represent a national security issue.

Re: Making sense of the alleged Supermicro motherboard attack

#138

Earlier quoted context omitted.

The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.

Unless, just to provide a nightmare scenario, the routers that would detect it are also compromised.

The NSA did that, they literally intercepted routers en route. I'm guessing other agencies have too.

Or you can just use the default credentials Cisco is addicted to leaving in their code.

Re: Making sense of the alleged Supermicro motherboard attack

#139

> Let’s assume an implant was added to the motherboard at manufacture time. This needed modification of both the board design, and the robotic component installation process. It intercepts the SPI lines between the flash and the BMC controller Circuit wise, you don't really need to "intercept" (place in series with) the SPI lines. Two parallel drivers [0] will generally fight it out quietly, and you can guarantee you…

Post author here. That was what I was thinking of - simply overdriving the lines to drag them high or low in opposition to the 'official' driver. That's pretty much all you can do with 6 pins. I was trying not to overcomplicate the explanation, since the material is already complicated enough! Fair point about hand soldering, however it would be more obvious to the manufacturing employees for an entire production bat…

I just thought that was phrased as if it were a necessary requirement for the attack, rather than a description of a likely approach. I could also see a scenario where only the occasional unit was bugged, and then an agent at the distributor made sure the right customers received the bugged units.

Thank you for writing your article! I'm currently a bit out of the security headspace and reading the Bloomberg article had me scratching my head like what are the actual details here.

Re: Making sense of the alleged Supermicro motherboard attack

#140
post #55

Earlier quoted context omitted.

One of the bloomberg articles claimed that in some cases it was "thin enough that they’d been embedded between the layers of fiberglass" -- like as if it were a passive in a blind/buried via? This seems like a very sophisticated attack.

Not a sophisticated attack, but a standard industry practice for high value, high density boards. I first saw a buried passive 5 years ago.

Sorry, I didn't mean to suggest that the attack was with a passive. Clearly, this package is shown to have logic. But it was meant to look as if it were a passive. In some cases surface mount, but in truly devious ones it's much better hidden.
Post reply on HN