Making sense of the alleged Supermicro motherboard attack
221–230 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#222Earlier quoted context omitted.
Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.
Could they say if they were?
Re: Making sense of the alleged Supermicro motherboard attack
#223Ok, that finally makes a bit of sense about "if" this is true, how it might be carried out. And I agree with the author that the simplest action for a chip on the SPI bus would be to hold the MISO line low during power on to suggest to the BMC chip that its QSPI flash isn't programmed (note that QSPI starts up as 'regular' SPI and then switches over[1]). I would guess that the next thing the BMC would do is assume it…
A chip holding and SPI line down - makes way more sense.
Re: Making sense of the alleged Supermicro motherboard attack
#224Can someone outline some reasons for me why nobody has come up with an actual physical example of a compromised board? I'm not trying to make a point, I just want to get a more complete picture of the issue, and the biggest thing that stands out to me is the lack of physical evidence.
Further, going back to the original article, the majority of the information comes from alleged government sources, so not the people directly impacted, but rather those just helping deal with the fallout and coordination.
Assuming there is merit to the story, it will likely be some time before more details emerge, unless having the story out there now helps accelerate that process.
Re: Making sense of the alleged Supermicro motherboard attack
#225Earlier quoted context omitted.
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.
Re: Making sense of the alleged Supermicro motherboard attack
#226Earlier quoted context omitted.
It's not at all hard to imagine, especially from a country who is so paranoid about backdoors from other country's operating systems that they have written their own: https://en.wikipedia.org/wiki/Kylin_(operating_system)
This is a Linux distro, not "their own OS". Many countries all over the world have had government-subsidized Linux distro projects, at national, state and city government levels. It's something that happens pretty quickly whenever and whereever a large deployment happens (e.g. LiMux). For that matter, many a CS faculty at many a university have actually created their own OS. Nothing too sensational either.
> In 2009, a report presented to the US-China Economic and Security Review Commission stated that the purpose of Kylin is to make Chinese computers impenetrable to competing countries in the cyberwarfare arena. The Washington Post reported that:
> China has developed more secure operating software for its tens of millions of computers and is already installing it on government and military systems, hoping to make Beijing’s networks impenetrable to U.S. military and intelligence agencies.
Re: Making sense of the alleged Supermicro motherboard attack
#227Earlier quoted context omitted.
And if they were, you think they would admit it?
They would not have blatantly lied about it in an official statement. That could not have passed legal.
Re: Making sense of the alleged Supermicro motherboard attack
#228I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
Read the denials carefully. They don't say the attacks haven't happened. They say they haven't found a variety of things.
The apple denial in particular is interesting as it indicates that they have been corresponding with Bloomberg about this issue for a YEAR. Yet despite the magnitude of contact they refer to, they do not describe the nature of the vulnerability being discussed or refer to specific material elements they've refuted. Their statement regarding Bloomberg's most recent version of the facts isn't on material elements of the story.
Having been involved in corporate risk responses I can say I've seen more vehement denials penned with perfect factual accuracy in respect of larger allegations, where the allegations turned out to be true. Almost every statement of defense looks exactly like this, with easy-win half-truth rebuttals to facts peppered around liberally to call the competence of your opposites into question.
Edit: inserted a missing word.
Re: Making sense of the alleged Supermicro motherboard attack
#229QSPI has 4 data lines, a clock and a chip-select line. In order to intercept a QSPI bus, you would therefore need 4+1+1+2xpower lines = 8 pins. This is not sufficient for QSPI. Single SPI on the other hand requires Clock, Data, ChipSelect, Ground & Power = 5 lines, so that would be plausible. (Yes, I know you can potentially get rid of the CS line, but that depends on what else is on the bus).
You need two lines - data/ground, or data/Vdd. Probably whichever gives you voltage when idle. You harvest power when data is idle. CS is irrelevant. The rough clock speed is fixed, and you can match the precise timing from the data line. QSPI actually gets you access to data in both directions with the tradeoff of only getting one quarter of the bits. Logically, you likely only need to recognize a few patterns that…
Re: Making sense of the alleged Supermicro motherboard attack
#230Earlier quoted context omitted.
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
I think the NSL angle to the denials is bullshit - the denials themselves give you all you need. Read the denials carefully. They don't say the attacks haven't happened . They say they haven't found a variety of things. The apple denial in particular is interesting as it indicates that they have been corresponding with Bloomberg about this issue for a YEAR. Yet despite the magnitude of contact they refer to, they do…
"Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement."
Also:
"If there were ever such an event as Bloomberg News has claimed, we would be forthcoming about it and we would work closely with law enforcement."
And:
"No one from Apple ever reached out to the FBI about anything like this, and we have never heard from the FBI about an investigation of this kind — much less tried to restrict it."
If you read those as not material, then I'm at a loss as to what exactly would convince you.