Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

311–320 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#311

Earlier quoted context omitted.

You could move every CNC machine from the manufacturing line and it would not matter. These sneaky chips were embedded in the PCB. So this is a supplier trust issue. Plus they probably did not implant every board, So somebody inside FoxConn had to slip in these 'special' pcb's in known Apple mobo orders..

I am assuming that the PCB's are contracted out. It would be interesting to see where the PCB's came from. One side of me feels real bad for SuperMicro. The have always been there for the small guys that like to build our own servers and for small OEM shops. Who else are the real server mobo competitors? Gigabyte and AsrockRack from my view and they are a very distant second and third place. If SuperMicro goes down w…

The original Bloomberg article mentions subcontractor use in this paragraph, but not names:

“As recently as 2016, according to DigiTimes, a news site specializing in supply chain research, Supermicro had three primary manufacturers constructing its motherboards, two headquartered in Taiwan and one in Shanghai. When such suppliers are choked with big orders, they sometimes parcel out work to subcontractors. In order to get further down the trail, U.S. spy agencies drew on the prodigious tools at their disposal. They sifted through communications intercepts, tapped informants in Taiwan and China, even tracked key individuals through their phones, according to the person briefed on evidence gathered during the probe. Eventually, that person says, they traced the malicious chips to four subcontracting factories that had been building Supermicro motherboards for at least two years.”

Re: Making sense of the alleged Supermicro motherboard attack

#312
post #262

Earlier quoted context omitted.

It's not the RIC-V cores that would be the concern - 'tis the motherboards, NICs, etc...

Yeah, so everything would need to be open and manufactured in the US.

What if the NSA pressures the manufacturer?

Re: Making sense of the alleged Supermicro motherboard attack

#313
post #239

Earlier quoted context omitted.

Those aren't clear at all. They're clear to you because you don't see the weasel wording. "Apple has never found [...]" So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.…

> So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it. You’re making up new assertions from whole cloth - the original story claimed Apple found the chips then alerted the F…

If the chip was found by a contractor of Apple then Bloomberg has indeed asserted something that is factually wrong. But it is not a materially important error, and calling it a "new assertion from whole cloth" is severely overstating the magnitude of the error.

If someone that is talking about bash called linux for "a unix", I don't think most people would support your stance that they made completely baseless statement.

Re: Making sense of the alleged Supermicro motherboard attack

#314
post #306

Earlier quoted context omitted.

every FPGA is far more closed and secretive about its internals than Intel ever has been about its CPUs.

Because an FPGA’s internals is secret sauce... Xilinx et al. are open enough about how their chips work imo. You are not going to find something like Intel ME on an FPGA.

They don't even let you use anything except their IDE tools, and even then they are tightly controlled, you have absolutely no idea if they contain an intel ME style firmware.

Re: Making sense of the alleged Supermicro motherboard attack

#315
post #118

Earlier quoted context omitted.

Uh no. Having worked around those sorts of datacenters, the larger you are the more you're going to need the BMC and the iLO. Going to the server physically is almost never the answer at scale. The rack/data center guys generally don't know much at all.

I've spent many years working for the #1 and the #2 largest installations of computers on earth and neither of them use BMC or ILOMs. So there's definitely a disconnect here between your expectations and my reality.

UFC 229: Khabib vs McGregor | The World is Watching https://twitter.com/ufcfn

Re: Making sense of the alleged Supermicro motherboard attack

#316

Earlier quoted context omitted.

I think these attacks are theoretically real. I don't think these specific instances of the attack as described by Bloomberg are real. The only plausible scenario in which none of Bloomberg, Apple, and Amazon are knowingly lying is one in which only a select few employees at Apple/Amazon knew about this and were talking to the FBI, as you suggested. Except this doesn't make sense. The only way in which a select few e…

>How would it even be possible for the government to have determined that Apple and Amazon had their hardware compromised without Apple and Amazon's knowing cooperation? By having a spy in Chinese intelligence who sells it, then doing inspection when hardware goes through customs.

Super Micro is a US company. The finished product didn't go through customs. And any individual components that did would have been going to Super Micro, not to Apple or Amazon or any one of the 30 allegedly affected companies.

Re: Making sense of the alleged Supermicro motherboard attack

#317
post #155

Earlier quoted context omitted.

I'm guessing the answer is obviously yes that this type of x-ray would easily be able to discover / distinguish something the size of what's been described? (1mm x 2mm from what I've seen thus far?)

The x-ray picture would contain information sufficient to detect that thing, but it's quite plausible that the process/procedure of analyzing that x-ray would not find it. If they're looking for extra hardware, they're going to detect it, but if they're looking for bad solder joints, they're going to detect bad solder joints but not extra harware.

Right. It doesn't exactly align with what a normal auditor would be looking out for, I suppose. Thanks, I appreciate it.

Re: Making sense of the alleged Supermicro motherboard attack

#318
This story is ridiculous. I believe the arguments made int eh article didn’t happen. Apple, amazon, and SMCI have all rebuffed. The Bloomberg journalist was duped. SMCI did nothing wrong and their business remains strong as we speaker. They will shortly: 1) Issue a detailed rebuttal with QC procedures and 2) become current with their audited financials by the end of October. As a result, the stock will revisit $30 per share within 3-6 months which is a triple from today’s price. Who remembers the Johnson and Johnson Tylenol scar? Someone posiomed Tylenol and the stock cratered. This is no different, except the “poisoning” never happened. And even if it did, it was 3 years ago and was discovered.

Re: Making sense of the alleged Supermicro motherboard attack

#319
every supermicro motherboard that I have dealt with (several 100s) always has a jumper which can enable(shorted)/disable the bmc/ipmi. i’ve been surprised at how many we have bought used off eBay/surplus that had the jumper open (ie bmc disabled). wouldn’t having this disabled physically (jumper open), thwart this attack?

(i’m asking not suggesting)

and I do realize the majority of people do have the BMC enabled, including me)

also the fact that supermicro still offers this jumper to disable the BMC might speak to the fact that they (sm) are not in nor had any knowledge of this issue (ie they were not “In on it”)

Re: Making sense of the alleged Supermicro motherboard attack

#320
post #254

Earlier quoted context omitted.

You don't need to blatantly lie to author a rebuttal that doesn't actual rebut the claims against you. You accuse me of selling pink and purple unicorns to gangsters. I reply that "I have no knowledge of any contracts or agreements relating to the sale of unicorns, horses or horse-related animals from my firm, regardless of the colour, breed or condition of the animals. I categorically also deny having any business d…

The problem with your arguments throughout this thread is simple: if a rebuttal is clearly engineered to be deceptive, the courts will not regard it as a valid defense in any subsequent lawsuits from shareholders and customers. That's why rebuttals and denials are normally so vague. Courts have surprisingly little tolerance for companies who think they're being more clever than their customers, their shareholders, or…

I'd love if that were the reality, but it isn't. A judge will scrutinize a party they believe is acting in bad faith (this is a term of art, but I'm using it in the lay sense here), but you won't show that a party is acting in bad faith because they were linguistically precise during a statement of defense.

You'll show they're acting in bad faith if documentary evidence shows they're baddies.

The theory behind our court system is one thing. The reality is another.

Post reply on HN