I really hope that this is the straw that breaks the back of all these "management engines" Like seriously, why does my hobby consumer motherboard need that feature? Corp IT only ever deploys to large fleets of OEM machines.
Making sense of the alleged Supermicro motherboard attack
131–140 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#132Earlier quoted context omitted.
Passives don't have enough pins to do much of anything, unless it's an array of passives in a single package that happens to be on power, gnd and data lines at once. But, I'm not sure but it seems like a bit of a red herring. Reading the article the chip in question doesn't sound passive at all: "The Supermicro board here appears to have a QSPI chip, but also a space for an SPI chip as a manufacturing-time option. Th…
Did you see the comment above that QSPI boots up as SPI and then switches over to QSPI?
Re: Making sense of the alleged Supermicro motherboard attack
#133Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
> Why wouldn’t a company notice any of the outbound traffic using firewalls? This is telling you that your experience is limited, not that the story is wrong. Trying to do egress filtering at scale is extremely hard for all but the most basic threats. If they open a socket to data-collector.pla.cn, yes, probably a majority of large shops would notice that within a few months but what if it's just a connection to S3/E…
There is no way that any large tech company security operation misses this traffic phoning home from a management vlan.
Re: Making sense of the alleged Supermicro motherboard attack
#134Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…
It's as hard to imagine as the NSA's surveillance systems. I.e., it's not. The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done. China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the fu…
Re: Making sense of the alleged Supermicro motherboard attack
#135It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…
> ... high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. MFG test guy here (not supermicro!) Not necessarily. Automated production tests are there to configure and exercise the system and confirm it works as specified. Such tests are good at things like finding bad solder joints, pick-and-place mishaps, misconfiguration of firmware and weeding out product that fai…
However, if the source files already had the component(s) on it, it would pass all tests and QC.
Re: Making sense of the alleged Supermicro motherboard attack
#136I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…
Re: Making sense of the alleged Supermicro motherboard attack
#137I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…
Re: Making sense of the alleged Supermicro motherboard attack
#138Earlier quoted context omitted.
The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.
Unless, just to provide a nightmare scenario, the routers that would detect it are also compromised.
Or you can just use the default credentials Cisco is addicted to leaving in their code.
Re: Making sense of the alleged Supermicro motherboard attack
#139> Let’s assume an implant was added to the motherboard at manufacture time. This needed modification of both the board design, and the robotic component installation process. It intercepts the SPI lines between the flash and the BMC controller Circuit wise, you don't really need to "intercept" (place in series with) the SPI lines. Two parallel drivers [0] will generally fight it out quietly, and you can guarantee you…
Post author here. That was what I was thinking of - simply overdriving the lines to drag them high or low in opposition to the 'official' driver. That's pretty much all you can do with 6 pins. I was trying not to overcomplicate the explanation, since the material is already complicated enough! Fair point about hand soldering, however it would be more obvious to the manufacturing employees for an entire production bat…
Thank you for writing your article! I'm currently a bit out of the security headspace and reading the Bloomberg article had me scratching my head like what are the actual details here.
Re: Making sense of the alleged Supermicro motherboard attack
#140Earlier quoted context omitted.
One of the bloomberg articles claimed that in some cases it was "thin enough that they’d been embedded between the layers of fiberglass" -- like as if it were a passive in a blind/buried via? This seems like a very sophisticated attack.
Not a sophisticated attack, but a standard industry practice for high value, high density boards. I first saw a buried passive 5 years ago.