Earlier quoted context omitted.
> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.
Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.
Making sense of the alleged Supermicro motherboard attack
31–40 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#32It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…
That’s my main takeaway from all of this- Elemental is great at their job and didn’t just do a half assed attempt at an audit. They actually did what they were hired to do. I wonder how rare that is.
> ... In late spring of 2015, Elemental’s staff boxed up several servers and sent them to Ontario, Canada, for the third-party security company to test, the person says. Nested on the servers’ motherboards, the testers found a tiny microchip ...
Re: Making sense of the alleged Supermicro motherboard attack
#33Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…
I.e., it's not.
The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done.
China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the future: if you never do it, then you never get the benefit, and if you do do it, you get to do it once, and once is better than never.
Re: Making sense of the alleged Supermicro motherboard attack
#34It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…
Depends on where it was added. Doing it as part of the assembly process would require having access to the pick and place software along with being able to load reels of the implant into the machine. A well placed insider may be able to make that happen, and automated optical inspections would be fed by the modified pick and place program, so checks would pass as the new component is part of the build.
Re: Making sense of the alleged Supermicro motherboard attack
#35Earlier quoted context omitted.
Are you basing this off the photo in the Bloomberg article that shows a small (0402?) SMT package with three terminals? I wonder if that's an actual photo of the chip in question.
FTA: https://assets.bwbx.io/images/users/iqjWHBFdfxIU/iWRg56pmx50... > [...] a picture of the alleged implant. This shows a 6-pin silicon chip inside a roughly 1mm x 2mm ceramic package – as often used for capacitors and other so-called ‘passive’ components, which are typically overlooked.
Re: Making sense of the alleged Supermicro motherboard attack
#36Earlier quoted context omitted.
There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.
The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.
Re: Making sense of the alleged Supermicro motherboard attack
#37Earlier quoted context omitted.
There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.
The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.
Re: Making sense of the alleged Supermicro motherboard attack
#38Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
> notice any of the outbound traffic Outbound traffic is allowed unrestricted in 95% of the deployments, it is just a life fact, people trust their own systems.
Re: Making sense of the alleged Supermicro motherboard attack
#39Earlier quoted context omitted.
EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant
If it replaced a DNP part, it could have been found at a flying probe test. Half the expected impedance on a few of those pins? Also AOI might have picked up a difference.
Re: Making sense of the alleged Supermicro motherboard attack
#40Maybe this will open up more manufacturing jobs in the US.