Earlier quoted context omitted.
Maybe you are not a high value target?
No comment.
New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
301–310 of 379 posts
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#302Earlier quoted context omitted.
Well, that depends on your definition of tampering, but if you want to exclude manufacturing something that is not what was specced then I am fine with that but please do supply a new term. I would definitely spot that device if it were on these boards because it was described in detail and there were some pictures of what it supposedly looked like. A device like that is not on either side of the board and it isn't i…
> I would definitely spot that device if it were on these boards because it was described in detail and there were some pictures of what it supposedly looked like. In case you missed it, there is an article posted today [0] that has this quote from "Hardware security expert Joe Fitzpatrick", one of the Bloomberg sources, regarding "the supposed spy chip": > In September when he asked me like, “Okay, hey, we think it…
The original article has now dropped into the real of SF for me until they show a detailed shot of an actual board with a parasitic device on it. Until then this is a wild goose chase.
Thank you for pointing this out.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#303Earlier quoted context omitted.
> But Bloomberg is a serious news organization and they are holding strong on this story as well. So what to think? Are they? The authors of this story published an unverified and in corroborated story about Heartbleed a few years ago, claiming that the NSA knew about it and was exploiting it ( https://www.washingtonpost.com/blogs/erik-wemple/wp/2014/04/... ).
And here's someone else calling out Bloomberg for an "unethical hatchet job" when reporting on a technical issue: https://www.semiaccurate.com/2012/10/08/bloomberg-wrong-abou...
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#304Earlier quoted context omitted.
This claim seems like a big dilemma for US white-hat security researchers: 1. As a white-hat security researcher, you have an ethical responsibility to publicly disclose vulnerabilities after doing the necessary due diligence (informing the affected parties privately, and giving them the necessary time to respond, investigate, and come up with an acceptable solution). 2. As a US citizen, you can't report attacks carr…
> As a US citizen, you can't report attacks carried out by US intelligence agencies. Sure you can. Short of a gag order (and maybe not even then) you can report intrusions all you like. In any event, how does one determine the nationality of hardware that shouldn't be there? It's not like there's going to be a snarky "Designed by the NSA in Fort Meade" logo on the chips in question.
You also abide by a whole slew of laws regarding sensitive, secret, top secret, or SCIF information. If I knowingly, or even suspect, some information if classified, and I transmit it to anyone else than my federal assigned contact, I'm breaking major federal laws.
A lot of security professionals in the US have such clearances. So finding a NSA implant or such proof makes it dangerous to talk about by default.
So yeah, a gag order by profession.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#305I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#306I've seen several comments regarding whether or not Apple, Amazon etc. would deny the hacking if its true and if that is fraud or not. I work at Amazon now and previously was in the Navy, holding a TS/SCI. My firm belief is if such a hack happened, it would not be disclosed to anyone without a clearance, and the organizations that are denying it have no knowledge that it occurred. Furthermore if there truly was a com…
> the organizations that are denying it have no knowledge that it occurred Are you saying that Steve Schmidt, the AWS chief infosec officer didn't know about the hack? Or that his article [0] was published to purposely hide it? If only one person in Amazon knew about it, it would be Schmidt. And if Schmidt knew, I don't think he'd write an article so strongly claiming Amazon doesn't know anything about it. The only t…
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#307Earlier quoted context omitted.
The cleared department is handled the same way as in the military in terms of security. Amazon has SCIF's etc. So unless a disgruntled employee steps forward who doesn't care about there life, I imagine its easily contained (and symptoms of an employee being disgruntled are highly monitored when they hold a clearance)
I’m thinking about the non cleared data center folk, the sys admins and developers who use the servers for their applications. How do a bunch of Supermicro servers vanish wintout anyone noticing? I’d expect quite a few people would be involved that do not have any clearances. Apple is known for their secrecy but a few other companies named are not.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#308Earlier quoted context omitted.
You don't know that. We do know that the USG covertly intercepted fiber communications. https://www.washingtonpost.com/news/the-switch/wp/2013/11/04...
The story literally quotes the general of the NSA, saying they go though the FBI to get a FISA court order to compel the company.. Additionally, the story quoted talks about how the UK obtained the data and gave it to the NSA. Nowhere is the NSA installing covert implants. They just don't do that. The CIA does that :)
You are taking the word of a spy? Did he say it wittingly?
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#309Earlier quoted context omitted.
German telecom employee here. I've seen a number of sneaky backdoors and intercepting devices at all levels in my career. The most interesting thing was a server where TCP connections that were about to close (TCP FIN) were suddenly intercepted to dump additional (encrypted) data that was't part of the original flow. Obviously there was something out there that was seeing both sides of the flow and intercepted parts…
> Based on prior experience with investigative journalism there's no way they would go all in with a story like this if they weren't standing on firm ground. Every single sentence would've been vetted. And based on my prior experience I would make the exact opposite conclusion. Technical writers are rarely technical, and they seem to be happy to make stuff up and mislead - even if unintentionally - so long as they ma…
I think a contributing factor is that it's generally hard to write about things you don't fully understand with the correct nomenclature. Especially when you might not be able to talk/ask for help about specifics with people more knowledgeable because of the secretive process.
Things could've been dumbed down, intentionally or unintentionally, by those involved. It wouldn't be hard to imagine a conversation like: "-So it was sort of a coupler thing? -You could say that, yes". Or what if the technical detail came from a Chinese source and Google translate mangled it?
The coupler thing is dumb and so is the picture (assuming it was a random product picture) but at least they might serve as a way of communicating the big picture: a hard to spot electronic "coupler" thing.
Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
#310Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…
A named source, but not a named victim, in this case. I would not call this verification. This is a really hard story to know what to think about. On the one hand, yes, hardware implants are a major risk. And having so many of our electronics manufactured in a country with massive state control over its economy and with which we have an adversarial political relationship is definitely a big concern. On the other hand…