Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

231–240 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#231
post #177

Earlier quoted context omitted.

They would not have blatantly lied about it in an official statement. That could not have passed legal.

Aren't they required to do so in the context of a NSL?

No, they are not required to provide materially false information in direct violation of SarbOx, the SEC, and several other federal agencies and statutes - not to mention the various EU laws surrounding such activity.

If they were under an NSL they would simply not comment on this at all. That would be pretty normal for Apple, so people would probably take it in stride.

Re: Making sense of the alleged Supermicro motherboard attack

#232
post #191
post #154

Earlier quoted context omitted.

What’s the difference if that open source risc is manufactured in the same Chinese plant?

More likely a fab in Taiwan than China. You can run your RISC-V cores on an FPGA if you’re really paranoid. Of course, you’d be sacrificing performance.

It's not the RIC-V cores that would be the concern - 'tis the motherboards, NICs, etc...

Re: Making sense of the alleged Supermicro motherboard attack

#233
post #167
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

> It's hard for me to guess why the companies involved would deny that these exist. My guess is that they know that everyone's confidence in them would crumble. Every business, ever household, everyone, would suddenly be aware that their data is not safe, even in the hands of the ones who say "trust us, we'll keep it safe".

> My guess is that they know that everyone's confidence in them would crumble.

Why? Even if this were all true, the sum total of the accusation is that a small number of servers 4 years ago were compromised and Apple's security chops are so good they found a completely never-before-seen hardware attack and stopped it with the help of the FBI - all without any customer data being at risk.

Re: Making sense of the alleged Supermicro motherboard attack

#234

Earlier quoted context omitted.

Apple specifically states that they are not under any form of gag/confidentiality order/conditions: > Finally, in response to questions we have received from other news organisations since Businessweek published its story, we are not under any kind of gag order or other confidentiality obligations.

Could they say if they were?

No. But gag orders do not require the recipient to lie about it. Someone who is under a gag order simply doesn't comment one way or the other about it.

FWIW this is the principle behind warrant canaries. A warrant canary is the practice of putting a statement such as "we have not received any NSLs" in a regular report, and then omitting it once you have received an NSL. Because you've conditioned people to expect its presence, its absence then serves as a signal that you likely have received one (though not proof, as there are other reasons you may have removed it, such as being advised by your lawyer that it's a bad idea as the courts may not look favorably on the idea that, no, you weren't actually violating your gag order, you were technically saying nothing, given that you set up the conditions yourself such that saying nothing is in fact saying something).

Re: Making sense of the alleged Supermicro motherboard attack

#235
post #163

Earlier quoted context omitted.

What phones do not have Chinese components?

Not only that, which base stations don't have Chinese components? But cpu, baseband, ram etc is certainly more serious consideration... And I don't see how you can get around that. Unless you plan to build a dumb phone around a Motorola 68k or something?

Ericsson for one.

Re: Making sense of the alleged Supermicro motherboard attack

#236
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

I think these attacks are theoretically real. I don't think these specific instances of the attack as described by Bloomberg are real.

The only plausible scenario in which none of Bloomberg, Apple, and Amazon are knowingly lying is one in which only a select few employees at Apple/Amazon knew about this and were talking to the FBI, as you suggested. Except this doesn't make sense. The only way in which a select few employees would know about this and nobody else is if these employees are subject to a gag order. But the only way they could be subject to a gag order is if the government came to them in the first place, said "here's a gag order, now that you have it I'll tell you about the attack". But according to Bloomberg, a random spot check by Apple employees found the chip, and IIRC they said a third-party security audit ordered by Amazon found the chip on the Elemental servers. In both cases, this attack would have been immediately reported up to the highest levels at the company prior to even beginning talks with the FBI. There's no scenario in which an employee at Apple or Amazon was made aware of the attack, reached out to the FBI, and received a gag order, prior to notifying their superiors and having the information make it all the way up to the executive level.

Of course, you could claim that Bloomberg was wrong about how the chip was found and right about everything else, but that's not really plausible. Why would they be wrong about that and right about everything else? How would it even be possible for the government to have determined that Apple and Amazon had their hardware compromised without Apple and Amazon's knowing cooperation? The government doesn't have access to these servers, only Apple and Amazon do.

Re: Making sense of the alleged Supermicro motherboard attack

#237
post #155

Earlier quoted context omitted.

Some manufacturers do X-ray boards. Typically this is done to check that BGA devices ( https://en.wikipedia.org/wiki/Ball_grid_array ) are soldered properly. Usually not done on every board, but only if there's a problem suspected. When it happens they tend to focus only on particular BGA components or suspect copper traces rather than the whole PCB.

I'm guessing the answer is obviously yes that this type of x-ray would easily be able to discover / distinguish something the size of what's been described? (1mm x 2mm from what I've seen thus far?)

The x-ray picture would contain information sufficient to detect that thing, but it's quite plausible that the process/procedure of analyzing that x-ray would not find it. If they're looking for extra hardware, they're going to detect it, but if they're looking for bad solder joints, they're going to detect bad solder joints but not extra harware.

Re: Making sense of the alleged Supermicro motherboard attack

#238
post #177

Earlier quoted context omitted.

They would not have blatantly lied about it in an official statement. That could not have passed legal.

Aren't they required to do so in the context of a NSL?

No. THere's plenty of case law establishing that you cannot be compelled to outright lie.

Re: Making sense of the alleged Supermicro motherboard attack

#239
post #228

Earlier quoted context omitted.

I think the NSL angle to the denials is bullshit - the denials themselves give you all you need. Read the denials carefully. They don't say the attacks haven't happened . They say they haven't found a variety of things. The apple denial in particular is interesting as it indicates that they have been corresponding with Bloomberg about this issue for a YEAR. Yet despite the magnitude of contact they refer to, they do…

I'm not sure where you're reading the Apple denial you're referring to, but this is *incredibly clear, detailed, and leaves no room to wiggle: "Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in l…

Those aren't clear at all. They're clear to you because you don't see the weasel wording.

"Apple has never found [...]"

So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here.

Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.

Before you complain about the semantics, Apple specifically uses the phrasing "We are not aware of any" in respect of investigations, yet they don't use that all-encompassing language in reference to attacks.

"malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server"

What is a malicious chip - could the inserted piece be classified as non-malicious or simply not a chip? What is a hardware manipulation - are they saying they've literally never found any deviation between spec and what they've received? Why place 'purposely planted' as a qualifying requirement there?

"If there were ever such an event as Bloomberg News has claimed, we would be forthcoming about it and we would work closely with law enforcement."

They don't indicate what was claimed. They reference a volume of correspondence with a variety of claims instead of the claims. We assume, contextually, that they're referring to the specific chip insertion, but that's not borne out by their statement.

"No one from Apple ever reached out to the FBI about anything like this, and we have never heard from the FBI about an investigation of this kind — much less tried to restrict it."

This is fully plausible and means nothing. They restrict their denial of contact with the FBI to outgoing, indicate they haven't received notice of an investigation of some kind, which doesn't mean there's no investigation - collaborating with the FBI specifically on this point wouldn't involve the FBI disclosing the full scope of the investigation to them.

None of these statements actually deal with the issues claimed. They look like they do, but they don't.

Want a real statement? "Upon being notified of the potential issue by Bloomberg this past year, we have analyzed all of the SuperMicro boards referenced to determine if any unauthorized chip insertion occurred and have found none of the alleged inserted chips or any evidence of associated suspicious network activity."

Re: Making sense of the alleged Supermicro motherboard attack

#240
post #71

Earlier quoted context omitted.

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

not being allowed to admit it due to national security reasons Came here to say this. When I read Amazon’s rebuttal my gut said “what if these folks had to respond but weren’t allowed to tell the truth?”. If the allegations went unanswered it could be damaging to Amazon and tip the hand of the spooks. If they answered and said they did find the devices the story could run away from them, the internet mob is good at w…

Bloomberg specifically says some of their sources are senior national security officials from the Obama administration, and the conversations date back to the Obama administration. It doesn't make sense they would have been planning this leak for years in anticipation of Trump winning and a trade war with China.
Post reply on HN