Earlier quoted context omitted.
Plausible deniability. Wouldn't surprise me if China is getting the blame for a LOT of US hacking.
With the current political climate, that might be the intention. If you undermine international trade though marketing you don't have to fight a tariff war.
New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
231–240 of 379 posts
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#232Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
Personally I'm confident Bloomberg's reporting is accurate to a high degree. Based on prior experience with investigative journalism there's no way they would go all in with a story like this if they weren't standing on firm ground. Every single sentence would've been vetted. For each statement made there would be someone whose job would be to reject it unless you could back it up properly. This is also why you don't see these entities defending their story against random criticism that pops up. Most if not all decisions have already been made by the time it goes public.
The fact that there's now a second story on the same topic is a good sign. The reporting of these things are usually followed up by additional pieces to increase the impact (and revenue of course).
They claim they have 17 independent sources. That's pretty impressive in itself. It also means that they probably worked real hard verifying their sources' claims and inputs. I find it unlikely that they would've acquired all those sources unless the thing was real.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#233It also seems plausible the NSA would prefer techies not to look too closely at their hardware *removes tinfoil hat
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#234Some real doublethink going on here, with Bloomberg continuing to insist that supply chain attacks are real, yet seemingly accepting the denials of each company involved. I am really not sure what to make of this.
This is just a suggestion, but it might be useful to stop thinking about news reports as "the news report says X is real and true", because that's not what most news reports actually say. The text used usually reads like: "An unnamed source says blah blah", and "Joe Smith, a retied auto-worker, says blah blah blah", or "In response, a spokesman for Large Company, Inc. says blah blah blah blah", and so forth. Bloomber…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#235Earlier quoted context omitted.
That raises an interesting question about just how targeted this kind of attack could be. At manufacture time, do the folks on the assembly line (so to speak) know who a particular board is going to? If not, they would have to add the extra chip to all outgoing boards, which means there should be plenty of them in the wild, no?
Or swap the boards out in transit.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#236Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#237Earlier quoted context omitted.
What's the point of classifying national security threats?
I don't necessarily agree with the below, but one could argue that classification is necessary to prevent mass panic/prevent attempted vigilante justice/protect the government's image/buy the government time to investigate/respond appropriately.
If you're attempting to hack me or steal data from me and I know you're trying (specifically as would be the case with this chip if the story holds up) then I'm in a much better position to try to figure out how, or provide misinformation, or try to turn someone in the chain of custody if anything needs to be physically handled. Or at the very least, if it's an espionage or military situation, it makes it easier to know who to kill.
All of that goes out the window if you immediately disclose every threat. Whoever is attacking you will simply use the means you haven't discovered yet and stop using the ones you have.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#238Earlier quoted context omitted.
> China's leadership is calm and not prone to knee-jerk responses Communist China is ruled by a genocidal mafia with a well-known penchant for sudden outbursts of violence. From its bloody inception, through the Great Leap Forward, the TianAnMen Massacre, the persecution of FaLunGong followers and recently Muslims — the regime has shown it's completely incapable of serving its people. When times get tough they invari…
You're not refuting anything the post you're responding says. Murdering people can be a completely non knee-jerk response to domestic issues. They ARE getting away with it, aren't they?
I guess I'm projecting some semblance of humanity onto them. I'd assume even the most evil would usually want to hold off murder till nothing else works. Hopefully karma is about to catch up.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#239Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#240So it is a compromised ethernet adapter. Nobody question the ability of Chinese spies to plant such a thing, but the "Big Hack" story implies that this is used as a mass infiltration tool, which I still find very improbable and lacks any evidence.
The way I interpret it is: since it's being introduced at the manufacturing plant, those installing the devices have no idea where the finished product will end up. Thus, these are not targetted attacks; they could wind up in the servers of a Fortune 500 company, or just as easily in some hobbyist's home lab. You'd need to compromise a large percentage of the products to increase the chances of landing a juicy target…