Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

221–230 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#222

Earlier quoted context omitted.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Could they say if they were?

If they were, and couldn't say so, it's unlikely they would specifically say they aren't, they would say nothing about it.

Re: Making sense of the alleged Supermicro motherboard attack

#223

Ok, that finally makes a bit of sense about "if" this is true, how it might be carried out. And I agree with the author that the simplest action for a chip on the SPI bus would be to hold the MISO line low during power on to suggest to the BMC chip that its QSPI flash isn't programmed (note that QSPI starts up as 'regular' SPI and then switches over[1]). I would guess that the next thing the BMC would do is assume it…

Agreed on finally makes sense. Depending on what article it made it sound like a chip that sat between CPU and RAM or some external cache that was intercepting some pattern of data and real time buffering then modifying the output - which at CPU/RAM speeds made no sense.

A chip holding and SPI line down - makes way more sense.

Re: Making sense of the alleged Supermicro motherboard attack

#224
post #109

Can someone outline some reasons for me why nobody has come up with an actual physical example of a compromised board? I'm not trying to make a point, I just want to get a more complete picture of the issue, and the biggest thing that stands out to me is the lack of physical evidence.

Well according to the original article, the attack was targeted, implying the only way to get such a thing would be from one of the compromised customers, who are probably involved in an investigation into the matter, don't have all of the info themselves, and aren't super eager to release details to the public before a full picture emerges and mitigation procedures are in place.

Further, going back to the original article, the majority of the information comes from alleged government sources, so not the people directly impacted, but rather those just helping deal with the fallout and coordination.

Assuming there is merit to the story, it will likely be some time before more details emerge, unless having the story out there now helps accelerate that process.

Re: Making sense of the alleged Supermicro motherboard attack

#225
post #71

Earlier quoted context omitted.

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

--no. That's not how this works.

Re: Making sense of the alleged Supermicro motherboard attack

#226
post #93
post #46

Earlier quoted context omitted.

It's not at all hard to imagine, especially from a country who is so paranoid about backdoors from other country's operating systems that they have written their own: https://en.wikipedia.org/wiki/Kylin_(operating_system)

This is a Linux distro, not "their own OS". Many countries all over the world have had government-subsidized Linux distro projects, at national, state and city government levels. It's something that happens pretty quickly whenever and whereever a large deployment happens (e.g. LiMux). For that matter, many a CS faculty at many a university have actually created their own OS. Nothing too sensational either.

Pedantry aside, it is the reasoning behind building their own OS distro that is relevant here:

> In 2009, a report presented to the US-China Economic and Security Review Commission stated that the purpose of Kylin is to make Chinese computers impenetrable to competing countries in the cyberwarfare arena. The Washington Post reported that:

> China has developed more secure operating software for its tens of millions of computers and is already installing it on government and military systems, hoping to make Beijing’s networks impenetrable to U.S. military and intelligence agencies.

Re: Making sense of the alleged Supermicro motherboard attack

#227
post #177
post #168

Earlier quoted context omitted.

And if they were, you think they would admit it?

They would not have blatantly lied about it in an official statement. That could not have passed legal.

Most of Apple's "creative image" is one gigantic lie. Why would they suddenly have scruples now?

Re: Making sense of the alleged Supermicro motherboard attack

#228
post #71
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

I think the NSL angle to the denials is bullshit - the denials themselves give you all you need.

Read the denials carefully. They don't say the attacks haven't happened. They say they haven't found a variety of things.

The apple denial in particular is interesting as it indicates that they have been corresponding with Bloomberg about this issue for a YEAR. Yet despite the magnitude of contact they refer to, they do not describe the nature of the vulnerability being discussed or refer to specific material elements they've refuted. Their statement regarding Bloomberg's most recent version of the facts isn't on material elements of the story.

Having been involved in corporate risk responses I can say I've seen more vehement denials penned with perfect factual accuracy in respect of larger allegations, where the allegations turned out to be true. Almost every statement of defense looks exactly like this, with easy-win half-truth rebuttals to facts peppered around liberally to call the competence of your opposites into question.

Edit: inserted a missing word.

Re: Making sense of the alleged Supermicro motherboard attack

#229

QSPI has 4 data lines, a clock and a chip-select line. In order to intercept a QSPI bus, you would therefore need 4+1+1+2xpower lines = 8 pins. This is not sufficient for QSPI. Single SPI on the other hand requires Clock, Data, ChipSelect, Ground & Power = 5 lines, so that would be plausible. (Yes, I know you can potentially get rid of the CS line, but that depends on what else is on the bus).

You need two lines - data/ground, or data/Vdd. Probably whichever gives you voltage when idle. You harvest power when data is idle. CS is irrelevant. The rough clock speed is fixed, and you can match the precise timing from the data line. QSPI actually gets you access to data in both directions with the tradeoff of only getting one quarter of the bits. Logically, you likely only need to recognize a few patterns that…

CS isn't irrelevant if there are multiple devices on the bus, we havent seen a schematic.

Re: Making sense of the alleged Supermicro motherboard attack

#230
post #228
post #71

Earlier quoted context omitted.

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

I think the NSL angle to the denials is bullshit - the denials themselves give you all you need. Read the denials carefully. They don't say the attacks haven't happened . They say they haven't found a variety of things. The apple denial in particular is interesting as it indicates that they have been corresponding with Bloomberg about this issue for a YEAR. Yet despite the magnitude of contact they refer to, they do…

I'm not sure where you're reading the Apple denial you're referring to, but this is *incredibly clear, detailed, and leaves no room to wiggle:

"Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement."

Also:

"If there were ever such an event as Bloomberg News has claimed, we would be forthcoming about it and we would work closely with law enforcement."

And:

"No one from Apple ever reached out to the FBI about anything like this, and we have never heard from the FBI about an investigation of this kind — much less tried to restrict it."

If you read those as not material, then I'm at a loss as to what exactly would convince you.

Post reply on HN