Earlier quoted context omitted.
More likely a fab in Taiwan than China. You can run your RISC-V cores on an FPGA if you’re really paranoid. Of course, you’d be sacrificing performance.
every FPGA is far more closed and secretive about its internals than Intel ever has been about its CPUs.
Making sense of the alleged Supermicro motherboard attack
301–310 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#302In another thread Walterbell points out: From 2016, https://arstechnica.com/information-technology/2016/03/repor... . > Apple has begun designing its own servers partly because of suspicions that hardware is being intercepted before it gets delivered to Apple, according to a report yesterday from The Information. "Apple has long suspected that servers it ordered from the traditional supply chain were intercepted duri…
Re: Making sense of the alleged Supermicro motherboard attack
#303Earlier quoted context omitted.
First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…
I think the NSL angle to the denials is bullshit - the denials themselves give you all you need. Read the denials carefully. They don't say the attacks haven't happened . They say they haven't found a variety of things. The apple denial in particular is interesting as it indicates that they have been corresponding with Bloomberg about this issue for a YEAR. Yet despite the magnitude of contact they refer to, they do…
It almost feels like Apple tried to bait more information from Bloomberg to identify the person who spilled the beans.
Re: Making sense of the alleged Supermicro motherboard attack
#304Earlier quoted context omitted.
This is a BIOS setting, and even while the BMC's working over the primary NIC, it retains its independent MAC and IP address (and VLAN if you set it up). Also, even if the NIC is shared with the BMC and the OS, you cannot see the NIC of the BMC on the PCI bus. They are isolated at the hardware level. I manage lots of these servers for a long time, and this is my firsthand experience. :)
The BMC using the correct MAC and IP address is entirely down to the honesty of the software running on the BMC.
Attacks involving writing to / reading from memory & exfiltrating that data needs proof of concept code now. Hope someone with comparable hardware and BMC modifies OpenBMC's code to steal some stuff from the OS for research purposes.
If it can be proved, the results will be relatively fun and certainly revolutionary.
Re: Making sense of the alleged Supermicro motherboard attack
#305Re: Making sense of the alleged Supermicro motherboard attack
#306Earlier quoted context omitted.
More likely a fab in Taiwan than China. You can run your RISC-V cores on an FPGA if you’re really paranoid. Of course, you’d be sacrificing performance.
every FPGA is far more closed and secretive about its internals than Intel ever has been about its CPUs.
Xilinx et al. are open enough about how their chips work imo. You are not going to find something like Intel ME on an FPGA.
Re: Making sense of the alleged Supermicro motherboard attack
#307Earlier quoted context omitted.
Anyone else literally can't because they don't have supply chain advantage that China has.
Not anyone else, but there certainly are other nations with similar capabilities. USA is one of them - China is best suited for inserting "extra hardware" on a board as in this example, but if you'd want to insert similar functionality as some extra stuff in an existing chip, then USA could arguably do it easier than China. Also, South Korea and Taiwan have immense role in the supply chain and can do similar large sc…
USA would be easier to modify servers shipping to US, target specifically at datacenters.
China needs to guess which batch of the contract manufacturing motherboard would go. It would be risky to leak the board tamper to everyone.
Re: Making sense of the alleged Supermicro motherboard attack
#308Can someone outline some reasons for me why nobody has come up with an actual physical example of a compromised board? I'm not trying to make a point, I just want to get a more complete picture of the issue, and the biggest thing that stands out to me is the lack of physical evidence.
Well according to the original article, the attack was targeted, implying the only way to get such a thing would be from one of the compromised customers, who are probably involved in an investigation into the matter, don't have all of the info themselves, and aren't super eager to release details to the public before a full picture emerges and mitigation procedures are in place. Further, going back to the original a…
Supermicro assemble their products in US/Taiwan.
So in theory China need to accurately predict the pattern of how non-China factories install batches of the motherboard. I think it's extremely difficult to pull this off.
Re: Making sense of the alleged Supermicro motherboard attack
#309Earlier quoted context omitted.
Not only that, which base stations don't have Chinese components? But cpu, baseband, ram etc is certainly more serious consideration... And I don't see how you can get around that. Unless you plan to build a dumb phone around a Motorola 68k or something?
Ericsson for one.
Re: Making sense of the alleged Supermicro motherboard attack
#310In another thread Walterbell points out: From 2016, https://arstechnica.com/information-technology/2016/03/repor... . > Apple has begun designing its own servers partly because of suspicions that hardware is being intercepted before it gets delivered to Apple, according to a report yesterday from The Information. "Apple has long suspected that servers it ordered from the traditional supply chain were intercepted duri…
From 2013: “NSA reportedly intercepting laptops purchased online to install spy malware”
https://www.theverge.com/2013/12/29/5253226/nsa-cia-fbi-lapt...