Ok, that finally makes a bit of sense about "if" this is true, how it might be carried out. And I agree with the author that the simplest action for a chip on the SPI bus would be to hold the MISO line low during power on to suggest to the BMC chip that its QSPI flash isn't programmed (note that QSPI starts up as 'regular' SPI and then switches over[1]). I would guess that the next thing the BMC would do is assume it…
One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?
Making sense of the alleged Supermicro motherboard attack
271–280 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#272Earlier quoted context omitted.
One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?
"Lots of current" in this case would only be about 20mA, generating heat that you can easily dissipate from just the surface of a 0201 resistor. I doubt many microprocessors have pins that can drive higher current than that. Realistically, in order to drive it low you don't have to bring it down to 0V. Most 5V chips will stop registering logic high around 2.5-3.3V for example.
(edit: 88 I/O is a modest size microcontroller sort of chip)
Re: Making sense of the alleged Supermicro motherboard attack
#273Earlier quoted context omitted.
Could they say if they were?
No. But gag orders do not require the recipient to lie about it. Someone who is under a gag order simply doesn't comment one way or the other about it. FWIW this is the principle behind warrant canaries. A warrant canary is the practice of putting a statement such as "we have not received any NSLs" in a regular report, and then omitting it once you have received an NSL. Because you've conditioned people to expect its…
Neither grand juries nor coroners "outrank" the Executive (unlike Congress, who I would assume can just throw out the NSL to get testimony, since they have similar powers, like throwing out a document's top-secret classified status to get it read into the public record.) But in both situations, you can still be found in contempt of court if you just say "no comment."
Re: Making sense of the alleged Supermicro motherboard attack
#274I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
And while it is indeed possible for the government to make you stay quiet, forcing you to lie is considered compelled speech, which is a fundamental aspect of current thinking on the 1st Amendment, and not something that is likely to change. No, not even when a three-letter agency wants it.
Also nobody at the either the NSA nor Apple cares about the sort of everyday world news you're mentioning. Maybe lay of the Tom Clancy for a while?
Re: Making sense of the alleged Supermicro motherboard attack
#275Earlier quoted context omitted.
According to this comment, the BMC is at least capable of working off the real NIC instead, and will do so if you don't hook up the management NIC. https://news.ycombinator.com/item?id=18138411
This is a BIOS setting, and even while the BMC's working over the primary NIC, it retains its independent MAC and IP address (and VLAN if you set it up). Also, even if the NIC is shared with the BMC and the OS, you cannot see the NIC of the BMC on the PCI bus. They are isolated at the hardware level. I manage lots of these servers for a long time, and this is my firsthand experience. :)
Re: Making sense of the alleged Supermicro motherboard attack
#276Earlier quoted context omitted.
I'm not sure where you're reading the Apple denial you're referring to, but this is *incredibly clear, detailed, and leaves no room to wiggle: "Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in l…
Those aren't clear at all. They're clear to you because you don't see the weasel wording. "Apple has never found [...]" So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.…
You’re making up new assertions from whole cloth - the original story claimed Apple found the chips then alerted the FBI. Apple explicitly and clearly denies every single aspect of the BW/Bloomberg story, and your objection to their denial is that they didn’t deny actions never presented in the article?
That’s called a straw man, and it doesn’t pass muster...
Re: Making sense of the alleged Supermicro motherboard attack
#277Earlier quoted context omitted.
One question: how do you hold an existing line low without drawing lots of current, and without cutting that line first?
It's not like the MISO line is tied to a power rail. You just need to sink more current than the output of the chip you are trying to override. So the driver is likely in the single digit milliamp range, and in any case, you don't care if you toast the output driver on that chip. In fact, if you do, bonus!
Re: Making sense of the alleged Supermicro motherboard attack
#278Earlier quoted context omitted.
What’s the difference if that open source risc is manufactured in the same Chinese plant?
More likely a fab in Taiwan than China. You can run your RISC-V cores on an FPGA if you’re really paranoid. Of course, you’d be sacrificing performance.
Re: Making sense of the alleged Supermicro motherboard attack
#279The fact that cursory examination finds the attack is not only entirely feasible, and completely undefended against, but that the hardware shown in the Bloomberg animation is precisely the hardware which would be required to pull off the attack is quite astonishing. Whose “law” is it that the closer you are to an event the more you can see that the reporting on the event is desperately flawed? This has almost always…
idk, but this description of Gell-Mann amnesia seems to touch on that idea
Re: Making sense of the alleged Supermicro motherboard attack
#280The fact that cursory examination finds the attack is not only entirely feasible, and completely undefended against, but that the hardware shown in the Bloomberg animation is precisely the hardware which would be required to pull off the attack is quite astonishing. Whose “law” is it that the closer you are to an event the more you can see that the reporting on the event is desperately flawed? This has almost always…
maybe such a manager would, by doing that in this case, be protecting the top level execs