Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

191–200 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#191
post #154

Earlier quoted context omitted.

I would really hope that this will give all the RISC-V open source effort some traction in the server / DC market. Certainly big corporations like Google, Facebook, Amazon and others could pull it off.

What’s the difference if that open source risc is manufactured in the same Chinese plant?

More likely a fab in Taiwan than China.

You can run your RISC-V cores on an FPGA if you’re really paranoid. Of course, you’d be sacrificing performance.

Re: Making sense of the alleged Supermicro motherboard attack

#192

QSPI has 4 data lines, a clock and a chip-select line. In order to intercept a QSPI bus, you would therefore need 4+1+1+2xpower lines = 8 pins. This is not sufficient for QSPI. Single SPI on the other hand requires Clock, Data, ChipSelect, Ground & Power = 5 lines, so that would be plausible. (Yes, I know you can potentially get rid of the CS line, but that depends on what else is on the bus).

Most QSPI flash chips start up in an SPI mode for interrogation of parameters and then are commanded to switch to QSPI once the correct parameters are established.

If your flash chip simply doesn't return the correct responses to switch to QSPI, most systems will happily continue communicating with SPI.

Re: Making sense of the alleged Supermicro motherboard attack

#194
post #172

A decade ago when I worked at Microsoft I shopped around the idea of using XBox as a basis for secure computing. XBox was designed to function in the hands of the adversary, to be robust against peripheral attacks and even motherboard mods. Even the main memory was encrypted by the on-CPU controller. Obviously, no open JTAGs. A lot of expertise there. In my fantasies it would form the basis of the DoD infrastructure…

Are you referring to the original Xbox? Modchips hit the scene for that in ~ 2 years after release. It's not exactly what I would consider a basis for secure computing. Or maybe you are just referencing the procedures "main memory was encrypted by the on-CPU controller. Obviously, no open JTAGs" should be ratified to create a basis for secure computing, a checklist of things to do/prevent before considering a device…

XBox 360 had the on-CPU memory controller with encryption, and it was very tamper-resistant overall. A good model to follow.

Re: Making sense of the alleged Supermicro motherboard attack

#195
post #63
post #26

Earlier quoted context omitted.

Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.

Apple, at least, claims they do[1]: "As a matter of practice, before servers are put into production at Apple they are inspected for security vulnerabilities and we update all firmware and software with the latest protections." [1] https://www.apple.com/au/newsroom/2018/10/what-businessweek-...

They surely don't write their own firmware for Supermicro boards? So "update firmware .. with the latest protections" means update from the hardware vendor?

Re: Making sense of the alleged Supermicro motherboard attack

#196
Regardless if someone of the details turn out to be true, there's a couple of really important network security takeaways here.

First you need to run an air gapped network or at least switch enforced vnet for your bmcs. Three firmware on these is only updated every few years anyway, so they're likely full of security holes anyway.

Second, in general, outbound connections need to be monitored everywhere in your data center.

Re: Making sense of the alleged Supermicro motherboard attack

#197

Earlier quoted context omitted.

Thank you for the insight. I was rather naively imagining that every board is subject to some kind of x-ray image matching with the original PCB design to find differences. Not that simple, I see.

Some manufacturers do X-ray boards. Typically this is done to check that BGA devices ( https://en.wikipedia.org/wiki/Ball_grid_array ) are soldered properly. Usually not done on every board, but only if there's a problem suspected. When it happens they tend to focus only on particular BGA components or suspect copper traces rather than the whole PCB.

I've only seen X-ray as a destructive test. AOI is pretty commonplace on a per-unit base, but whether it could or could not detect some modification depends on lots of details we don't have.

Re: Making sense of the alleged Supermicro motherboard attack

#198
If this attack vector is true, it seems overly complicated to me. Why not have the assembly house load the normal SPI flash with firmware you've altered to control the main CPU the way you want? That is WAY easier than hardware changes to the PCB design and installing a part which isn't on the approved Bill of Materials.

Re: Making sense of the alleged Supermicro motherboard attack

#199
post #185

Earlier quoted context omitted.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Apple cannot do anything bad to China or their manufacturing stops. Apple would have to move tens of thousands of highly specific CNC machines from China to somewhere else, set them up, and get their line moving again. This is why I find the idea that Apple phones are "secure" to laughable on its face. China could kill years of Apple revenue if they ever did something truly offensive to the ruling party. Apple would…

China could cause huge harm to Apple, but the reverse is also true - how would the US government, other corporations, consumers and investors react to such a news?

The ultimate source of most Chinese factory equipment is Europe and US anyway, under extreme political/consumer pressure electronics factories can be setup in a matter of months in US.

Re: Making sense of the alleged Supermicro motherboard attack

#200
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

Also interesting that Apple recently started to switch from Qualcomm to Intel modems. > The modem represents a milestone for Intel in a couple of ways; it is the first chip to be manufactured solely in-house and it is Intel’s first chip to support CDMA and GSM. > Apple’s original plan for the 2018 iPhones, via Nikkei, was for Intel to have exclusivity on modem orders for the first time — amidst its legal disputes wit…

Qualcomm was trying to milk Apple too hard.
Post reply on HN