Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

321–328 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#321
post #239

Earlier quoted context omitted.

Those aren't clear at all. They're clear to you because you don't see the weasel wording. "Apple has never found [...]" So what about third parties/reports/partners/contractors? Have they found anything and is Apple aware of those findings? Not disclosed here. Are the QC processes in place sufficient to lead us to believe that Apple would/should have found this issue? etc. If not, who cares if they haven't found it.…

Are the courts not capable of dealing with silly word games?

If they were, you wouldn't spend millions of dollars hiring people like me to play silly word games.

Just for some perspective on how dismissive your comment is imagine the following statement being said in reference to your team: "What do you mean, you had a network breach? Aren't our ops people not capable of dealing with silly 1s and 0s??"

Re: Making sense of the alleged Supermicro motherboard attack

#322
post #320

Earlier quoted context omitted.

The problem with your arguments throughout this thread is simple: if a rebuttal is clearly engineered to be deceptive, the courts will not regard it as a valid defense in any subsequent lawsuits from shareholders and customers. That's why rebuttals and denials are normally so vague. Courts have surprisingly little tolerance for companies who think they're being more clever than their customers, their shareholders, or…

I'd love if that were the reality, but it isn't. A judge will scrutinize a party they believe is acting in bad faith (this is a term of art, but I'm using it in the lay sense here), but you won't show that a party is acting in bad faith because they were linguistically precise during a statement of defense. You'll show they're acting in bad faith if documentary evidence shows they're baddies. The theory behind our co…

     "No one from Apple ever reached out to the FBI about 
     anything like this," Apple writes. "We have never heard 
     from the FBI about an investigation of this kind."
With language like this, it's the very definition of bad faith if they're lying. These are specific assurances that directly contradict the Bloomberg reporters in specific ways, and the companies know that people are likely to rely on them to their detriment.

Re: Making sense of the alleged Supermicro motherboard attack

#323
post #256

Earlier quoted context omitted.

No. But gag orders do not require the recipient to lie about it. Someone who is under a gag order simply doesn't comment one way or the other about it. FWIW this is the principle behind warrant canaries. A warrant canary is the practice of putting a statement such as "we have not received any NSLs" in a regular report, and then omitting it once you have received an NSL. Because you've conditioned people to expect its…

I'm pretty sure that this strategy won't hold up in court. If you have a sign that indicates that a secret event have not happened, the intent of removing the sign is to indicate that the secret event did happen. The intent is particularly obvious to the originator of the secret event, so you won't be able to argue in the court that it was entirely coincidental.

On the other hand, if I actually have a sign indicates that some secret event have not happened, how can I remove that sign if I truely believe I don't wanna keep telling the world that it have not happened?

If I remove the sign just because I no longer want to keep the sign up and someone takes it to mean that the secret event did happen, when it really didn't happen, do they have ground to sue me for fraud or lying?

Re: Making sense of the alleged Supermicro motherboard attack

#324
I don't understand why everybody assumes it must be pulling data over the network autonomously. It could simply compromise the host OS to augment other, targeted attacks. Say, by reintroducing a buffer overflow or race condition. It would be incredibly short-sighted to go to such lengths to compromise these machines just to naively pull from a command+control server, virtually advertising its presence.

Defenders simply do not think like attackers. If you're a defender it's lethal to try to think like an attacker. "I can't imagine how this would be useful therefore it must not be useful" are the famous last words of everybody who has cast doubt on a new and novel attack vector. As a defender you need to first estimate the unknowns and unknown unknowns, which over the last year alone have exploded (e.g. actual and potential Intel microcode vulnerabilities). If you needed this article to convince you of feasibility or even just practicality, please don't pretend to be capable of assessing the security posture of any complex system.

And let's be clear: this is not a new and novel attack vector. There are companies that have existed for quite some time researching and selling products to deal with this sort of attack vector. On the spectrum of hardware based attacks feasible today, this chip isn't at the complex end of the spectrum but rather the simple end of the spectrum. The complex end of the spectrum involves hiding logic deep within existing ICs, and there's ample literature to demonstrate feasibility of both implementation and detection.

The difficulty in pulling off these attacks lies not in the software or hardware, but the political, intelligence, and military apparatus of attacking countries. The economic costs of detection are huge precisely because, at the end of the day, fundamental security relies on trust, not technological hurdles per se.

Re: Making sense of the alleged Supermicro motherboard attack

#325

Earlier quoted context omitted.

Also interesting that Apple recently started to switch from Qualcomm to Intel modems. > The modem represents a milestone for Intel in a couple of ways; it is the first chip to be manufactured solely in-house and it is Intel’s first chip to support CDMA and GSM. > Apple’s original plan for the 2018 iPhones, via Nikkei, was for Intel to have exclusivity on modem orders for the first time — amidst its legal disputes wit…

Qualcomm was trying to milk Apple too hard.

Qualcomm is milking us all too hard.

Re: Making sense of the alleged Supermicro motherboard attack

#326
post #250

> But there’s another trick a bad BMC can do — it can simply read and write main memory once the machine is booted. Doesn't ASLR[0] mitigate this? [0] https://en.wikipedia.org/wiki/Address_space_layout_randomiza...

ASLR is a virtual memory technique, an attack via the BMC would attack physical memory.

Re: Making sense of the alleged Supermicro motherboard attack

#327
post #321

Earlier quoted context omitted.

Are the courts not capable of dealing with silly word games?

If they were, you wouldn't spend millions of dollars hiring people like me to play silly word games. Just for some perspective on how dismissive your comment is imagine the following statement being said in reference to your team: "What do you mean, you had a network breach? Aren't our ops people not capable of dealing with silly 1s and 0s??"

This is scarier & a lot more plausible than the Bloomberg/Supermicro story I think

Re: Making sense of the alleged Supermicro motherboard attack

#328

Earlier quoted context omitted.

I am assuming that the PCB's are contracted out. It would be interesting to see where the PCB's came from. One side of me feels real bad for SuperMicro. The have always been there for the small guys that like to build our own servers and for small OEM shops. Who else are the real server mobo competitors? Gigabyte and AsrockRack from my view and they are a very distant second and third place. If SuperMicro goes down w…

The original Bloomberg article mentions subcontractor use in this paragraph, but not names: “As recently as 2016, according to DigiTimes, a news site specializing in supply chain research, Supermicro had three primary manufacturers constructing its motherboards, two headquartered in Taiwan and one in Shanghai. When such suppliers are choked with big orders, they sometimes parcel out work to subcontractors. In order t…

[deleted]
Post reply on HN