Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…
It's as hard to imagine as the NSA's surveillance systems. I.e., it's not. The lesson of the Snowden leaks is clearly this: if it can be imagined, and it can be useful, and they have the budget, and it's remotely doable, then it's been done. China almost certainly did this because they could. You only get one chance to do something like this, so you have to do it even if it risks losing the ability to do it in the fu…
Making sense of the alleged Supermicro motherboard attack
61–70 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#62It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…
The routine audit could have uncovered hackers in Elemental's corporate network doing things like ensure certain machines go to certain customers, etc.
Re: Making sense of the alleged Supermicro motherboard attack
#63Earlier quoted context omitted.
You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.
Or just reflash the firmware. They should, but most people don't reflash the bios and BMC firmware when they install a new server. In fact I routinely encounter servers that are 5+ years in service that have never been reflashed.
[1] https://www.apple.com/au/newsroom/2018/10/what-businessweek-...
Re: Making sense of the alleged Supermicro motherboard attack
#64So the point of the attack was to subvert the BMC firmware in a way that was resistant to firmware re-flashing, but not resistant to firmware integrity checks. But there are no firmware integrity checks?
Re: Making sense of the alleged Supermicro motherboard attack
#65A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks.
Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is that Google had also done work to replace the EFI/Intel ME with a Linux kernel [2]. This has limited usefulness against the most recent attack, but it is related (since it's still a chip that has more privileges than the primary CPU).
I suspect that there are a very small number of people in these big companies who are aware of these attacks. It's hard for me to guess why the companies involved would deny that these exist.
1. https://www.zdnet.com/article/google-opens-up-on-titan-secur...
2. https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit...
Re: Making sense of the alleged Supermicro motherboard attack
#66Re: Making sense of the alleged Supermicro motherboard attack
#67It was reported that the security auditor used during Elemental's acquisition detected this compromise. I assume they found it in a randomly selected board. Either they were very lucky, or hundreds of boards were compromised. Now, I think all motherboard manufacturers - and especially high end server manufacturers like SM - use sophisticated automated tests and quality control on boards. Under what circumstances is i…
> what circumstances is it possible that SM's QC missed this out Rogue insider, paid or patriotic, likely both. > affect things like the power budget, weight, and latency All three would have no measurable change, falling into measurement error margin. Its a death sentence for Supermicro, nothing will help to restore trust. They should publish a detailed post-mortem analysis, though.
Re: Making sense of the alleged Supermicro motherboard attack
#68So the point of the attack was to subvert the BMC firmware in a way that was resistant to firmware re-flashing, but not resistant to firmware integrity checks. But there are no firmware integrity checks?
Re: Making sense of the alleged Supermicro motherboard attack
#69While it's practically certain that hacking attempts do happen from both state- and non-state actors, this particular instance is so "alleged" that it's practically theoretical. Where's the actual hardware? Why didn't someone decap the tiny chip and probe it? Its design should be well within today's reverse engineering labs' capabilities.
These things literally take time, and there's no indication of how widespread the targeting was.
Re: Making sense of the alleged Supermicro motherboard attack
#70Earlier quoted context omitted.
> what circumstances is it possible that SM's QC missed this out Rogue insider, paid or patriotic, likely both. > affect things like the power budget, weight, and latency All three would have no measurable change, falling into measurement error margin. Its a death sentence for Supermicro, nothing will help to restore trust. They should publish a detailed post-mortem analysis, though.
They took pains to say that this was happening with sub-contractors in China building motherboards in excess of what Taiwan could handle. So to build trust they can pull back on that extra manufacturing capacity and move it elsewhere maybe South Korea.
You can't put the toothpaste back in the tube