Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

171–180 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#171

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

You would recognize what looks like an extra resistor?

It has more terminals that a resistor, it's a pretty unusual package and it would stand out enough for me to spot it knowing that it is there. The area of the PCB that you could expect that thing to live in is about 5x5 cm square.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#172
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

The lack of (publicly available) evidence is annoying, since there are a lot of people who'd love to check their own servers. As this is an attack directed at high profile targets it's unlikely the average size company will have ended up with one of those, but it's still a fun exercise IMO.

It would also be great to know what the attribution is based on. Just the fact that they're manufactured in China? Who else might get their hands on these devices in the shipping chain? What kind of traffic did they monitor? I guess just observing it's talking to a Chinese address doesn't tell much. I mean, just take an S3 bucket and dump your stuff in there. Setting up your own server in your home country pretty much screams "we're here!"

> I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid situation where people are afraid to report foreign intelligence attacks because it's illegal to report an attack by US intelligence agencies, aren't we?

That's pretty tinfoily, but it'd be a cool way to still report on it. "Whoopsie, I totally thought it wasn't you guys, sorry for disclosing"

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#173
post #152

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

What's the point of classifying national security threats?

I don't necessarily agree with the below, but one could argue that classification is necessary to prevent mass panic/prevent attempted vigilante justice/protect the government's image/buy the government time to investigate/respond appropriately.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#175

Earlier quoted context omitted.

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Isn't the idea that the boards weren't tampered with but manufactured by contractors including extras?

Well, that depends on your definition of tampering, but if you want to exclude manufacturing something that is not what was specced then I am fine with that but please do supply a new term.

I would definitely spot that device if it were on these boards because it was described in detail and there were some pictures of what it supposedly looked like.

A device like that is not on either side of the board and it isn't in between the outer board layers (where it would be much harder to spot, especially if the cavity would be covered by a ground plane on one side).

I am not saying it is impossible, it is just very hard to hide something like that once you know it is there. The only candidate spots left that I can not check without destruction is underneath some of the devices or inside some of the devices. That would be a different level of sophistication than the original article alluded to.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#176
post #124

Earlier quoted context omitted.

I can see where the Navy/Military/Government could compartmentalize a hack like this. How could a company like Apple or Amazon keep this under wraps? How could they keep the knowledge of such a hack within the TS/SCI employees?

If it is classified and a cleared employee at Amazon/Apple/etc. blabbled there would be life altering consequences for them.

Then there will be? As someone apparently/allegedly blabbed to Bloomberg?

I say again to Bloomberg: picture (x-Ray) or it didn't happen.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#177
post #152

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

What's the point of classifying national security threats?

To not give away other nation that their capabilities are mitigated.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#178
post #48
post #8

OK so this is a different hack than Bloomberg reported before: ethernet jack piggyback instead of bmc. I'm not sure this adds credibility to the allegations in the other story. The details that Bloomberg related previously are so different that this couldnt be what they originally were reporting on. This adds to the China hacking server board narrative, but it does nothing to prove the Bloomberg reporting actually tr…

Read it more carefully. The ethernet jack is a tactic used by US intelligence years ago. That was mentioned in the story to explain the history of supply chain attacks.

If it is well known... can't imagine others wouldn't follow if it works.

Hard to imagine it remains an exclusive method by one actor.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#179
post #8

OK so this is a different hack than Bloomberg reported before: ethernet jack piggyback instead of bmc. I'm not sure this adds credibility to the allegations in the other story. The details that Bloomberg related previously are so different that this couldnt be what they originally were reporting on. This adds to the China hacking server board narrative, but it does nothing to prove the Bloomberg reporting actually tr…

Note that BMCs can also piggyback on ethernet ports; I've seen some vendors use a shared ethernet port for OOB and ethernet.

Which is fun because you can accidentally put a super important insecure oob service on the same jack as an internet exposed web service.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#180
post #152

I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…

What's the point of classifying national security threats?

If you know that something is compromised, you can use that knowledge to feed misinformation. You don't want them to know that you know.
Post reply on HN