Making sense of the alleged Supermicro motherboard attack
141–150 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#142I really hope that this is the straw that breaks the back of all these "management engines" Like seriously, why does my hobby consumer motherboard need that feature? Corp IT only ever deploys to large fleets of OEM machines.
Re: Making sense of the alleged Supermicro motherboard attack
#143Earlier quoted context omitted.
> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.
Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.
> has to travel over wire as TCP/IP,
BTW, this is not the case. If exfil via conventional system networking is too hard to avoid detection, they'll find another channel. RF via LOS, ultrasonic, or some of a million other ideas.
Re: Making sense of the alleged Supermicro motherboard attack
#144Re: Making sense of the alleged Supermicro motherboard attack
#145In the security world, there is always a new attack vector. With the advent of Spectre and Meltdown, I am expecting to see more hardware-based attacks in the future.
Re: Making sense of the alleged Supermicro motherboard attack
#146Earlier quoted context omitted.
Not a sophisticated attack, but a standard industry practice for high value, high density boards. I first saw a buried passive 5 years ago.
Sorry, I didn't mean to suggest that the attack was with a passive. Clearly, this package is shown to have logic. But it was meant to look as if it were a passive. In some cases surface mount, but in truly devious ones it's much better hidden.
Re: Making sense of the alleged Supermicro motherboard attack
#147I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…
Re: Making sense of the alleged Supermicro motherboard attack
#148Earlier quoted context omitted.
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.
Re: Making sense of the alleged Supermicro motherboard attack
#149Earlier quoted context omitted.
I wonder if China is making all these cheap wifi chips (esp8266, esp32) etc as backdoors into US infrastructure.
No more Chinese phones for me either way. It's enough that Google knows everything about me, PLA doesn't have to.
Re: Making sense of the alleged Supermicro motherboard attack
#150Earlier quoted context omitted.
It's as hard to imagine as the NSA's surveillance systems. I.e., it's not. The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done. China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the fu…
Like hiding cameras in Xerox machines: https://electricalstrategies.com/about/in-the-news/spies-in-...