Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

141–150 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#142

I really hope that this is the straw that breaks the back of all these "management engines" Like seriously, why does my hobby consumer motherboard need that feature? Corp IT only ever deploys to large fleets of OEM machines.

Take a look at ASpeed (BMC supplier) stock movement: https://finance.yahoo.com/quote/5274.TWO/chart?p=5274.TWO

Re: Making sense of the alleged Supermicro motherboard attack

#143

Earlier quoted context omitted.

> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.

Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.

Many/most AWS customers use ssh sessions to interact with their allocated nodes. And when it's not ssh traffic, it's often https. What good does it do to detect the bad traffic if you can't distinguish it from legitimate customer traffic?

> has to travel over wire as TCP/IP,

BTW, this is not the case. If exfil via conventional system networking is too hard to avoid detection, they'll find another channel. RF via LOS, ultrasonic, or some of a million other ideas.

Re: Making sense of the alleged Supermicro motherboard attack

#145
post #47

In the security world, there is always a new attack vector. With the advent of Spectre and Meltdown, I am expecting to see more hardware-based attacks in the future.

and subsidies to enrol more students in EE to build up local national talent?

Re: Making sense of the alleged Supermicro motherboard attack

#146
post #55

Earlier quoted context omitted.

Not a sophisticated attack, but a standard industry practice for high value, high density boards. I first saw a buried passive 5 years ago.

Sorry, I didn't mean to suggest that the attack was with a passive. Clearly, this package is shown to have logic. But it was meant to look as if it were a passive. In some cases surface mount, but in truly devious ones it's much better hidden.

Well my own idea was along the lines - if they can burry passives, burying a small IC should also be possible

Re: Making sense of the alleged Supermicro motherboard attack

#147
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

[deleted]

Re: Making sense of the alleged Supermicro motherboard attack

#148
post #71

Earlier quoted context omitted.

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

In all cases? possibly not if it is covered by national security.

Re: Making sense of the alleged Supermicro motherboard attack

#149
post #113

Earlier quoted context omitted.

I wonder if China is making all these cheap wifi chips (esp8266, esp32) etc as backdoors into US infrastructure.

No more Chinese phones for me either way. It's enough that Google knows everything about me, PLA doesn't have to.

What phones do not have Chinese components?

Re: Making sense of the alleged Supermicro motherboard attack

#150

Earlier quoted context omitted.

It's as hard to imagine as the NSA's surveillance systems. I.e., it's not. The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done. China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the fu…

Like hiding cameras in Xerox machines: https://electricalstrategies.com/about/in-the-news/spies-in-...

Thank you so much. That was a wonderful read and I really enjoyed that.
Post reply on HN