Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

61–70 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#61

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

It's as hard to imagine as the NSA's surveillance systems. I.e., it's not. The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done. China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the fu…

It's not that you get one chance to do something like this, it's that there is one total chance to do something like this. After it's been discovered, it's much harder to do it again for everyone - so if you never do it, then you don't get the benefit and Russia or USA or someone else does that and gets the benefit and you still lose the ability to do it in the future.

Re: Making sense of the alleged Supermicro motherboard attack

#62

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

The Bloomberg article says suspicions were raised during a routine audit that resulted in a deeper audit.

The routine audit could have uncovered hackers in Elemental's corporate network doing things like ensure certain machines go to certain customers, etc.

Re: Making sense of the alleged Supermicro motherboard attack

#63
post #26

Earlier quoted context omitted.

You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.

Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.

Apple, at least, claims they do[1]: "As a matter of practice, before servers are put into production at Apple they are inspected for security vulnerabilities and we update all firmware and software with the latest protections."

[1] https://www.apple.com/au/newsroom/2018/10/what-businessweek-...

Re: Making sense of the alleged Supermicro motherboard attack

#64

So the point of the attack was to subvert the BMC firmware in a way that was resistant to firmware re-flashing, but not resistant to firmware integrity checks. But there are no firmware integrity checks?

What is likely: they connected their own flash in place of recovery flash, that was not soldered on on that particular board version, that for what that soic8 or tsop8 pad is on photos; the chip will boot from the recovery, but if someone were to read the main flash, it would output the correct content. Only if somebody specifically poked the recovery, would the bug be revealed.

Re: Making sense of the alleged Supermicro motherboard attack

#65
I think the attacks are real.

A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks.

Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is that Google had also done work to replace the EFI/Intel ME with a Linux kernel [2]. This has limited usefulness against the most recent attack, but it is related (since it's still a chip that has more privileges than the primary CPU).

I suspect that there are a very small number of people in these big companies who are aware of these attacks. It's hard for me to guess why the companies involved would deny that these exist.

1. https://www.zdnet.com/article/google-opens-up-on-titan-secur...

2. https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit...

Re: Making sense of the alleged Supermicro motherboard attack

#67

It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…

> what circumstances is it possible that SM's QC missed this out Rogue insider, paid or patriotic, likely both. > affect things like the power budget, weight, and latency All three would have no measurable change, falling into measurement error margin. Its a death sentence for Supermicro, nothing will help to restore trust. They should publish a detailed post-mortem analysis, though.

Yeah, SM has the most to lose here. Regardless of whether the compromise is true or non-existent, they really should consider becoming more transparent about their QC, I think.

Re: Making sense of the alleged Supermicro motherboard attack

#68

So the point of the attack was to subvert the BMC firmware in a way that was resistant to firmware re-flashing, but not resistant to firmware integrity checks. But there are no firmware integrity checks?

Why would an integrity check show you anything different? It's all the same code running on the actual BMC, it'd be identical. That's the entire point of having an external package do all the malicious stuff -- reflash/dump/check will come up clean every time.

Re: Making sense of the alleged Supermicro motherboard attack

#69
post #41

While it's practically certain that hacking attempts do happen from both state- and non-state actors, this particular instance is so "alleged" that it's practically theoretical. Where's the actual hardware? Why didn't someone decap the tiny chip and probe it? Its design should be well within today's reverse engineering labs' capabilities.

What makes you think that people aren't going through they're POs and server farms and looking today? Just because a couple huge players told prior to publication, doesn't mean everyone was.

These things literally take time, and there's no indication of how widespread the targeting was.

Re: Making sense of the alleged Supermicro motherboard attack

#70
post #60

Earlier quoted context omitted.

> what circumstances is it possible that SM's QC missed this out Rogue insider, paid or patriotic, likely both. > affect things like the power budget, weight, and latency All three would have no measurable change, falling into measurement error margin. Its a death sentence for Supermicro, nothing will help to restore trust. They should publish a detailed post-mortem analysis, though.

They took pains to say that this was happening with sub-contractors in China building motherboards in excess of what Taiwan could handle. So to build trust they can pull back on that extra manufacturing capacity and move it elsewhere maybe South Korea.

> So to build trust they can

You can't put the toothpaste back in the tube

Post reply on HN