Live data from Hacker News

New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

bloomberg.com

71–80 of 379 posts

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#73

So does it really matter if it's true or not? Isn't the sane response to assume it's all true and verify your system integrity? Even if you find nothing you would then have a pile of strong evidence for the null case, eh?

>So does it really matter if it's true or not?

Is this Bloomberg's new slogan?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#74
post #65
post #31

Earlier quoted context omitted.

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

You don't know that. We do know that the USG covertly intercepted fiber communications.

https://www.washingtonpost.com/news/the-switch/wp/2013/11/04...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#75
post #65
post #31

Earlier quoted context omitted.

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.

No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants. They get FISA court orders that force american companies to attach their equipment.

I think they do both.

https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

https://www.washingtonpost.com/world/national-security/nsa-i...

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#76
post #30

Earlier quoted context omitted.

~

Just about anyone on Google's Project Zero team, off the top of my head. They would probably be both competent and enthusiastic. Beyond that Apple, Microsoft, Tesla and probably Amazon have sufficiently capable public (or past public) researchers working for them. But I doubt many would want the publicity one way or the other.

Most any security company would LOVE to get access to the purported hacks and study them.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#77
post #15

Finally a named source, but still no photos and the alleged hacked board is still not in the hands of a public security researcher. The "trojan ethernet connector" paragraph mentions similarity to an NSA implant, which appears to be this: https://en.wikipedia.org/wiki/NSA_ANT_catalog#/media/File:NS... I'm now wondering if someone found an NSA implant and misreported it as Chinese. We're going to end up in the stupid…

I've been looking in detail at three different Supermicro motherboards but so far have not been able to spot anything. Even against a backlight there is no sign of tampering between the layers.

Isn't the idea that the boards weren't tampered with but manufactured by contractors including extras?

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#79

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

My take on this is that it's been fairly obvious for a long time that these kinds of attacks are possible (if not easy) with today's technology. One could design a microcontroller, for example, that was disguised as an 0805 capacitor and functioned like an 0805 capacitor, but also had other functionality.

So why is this suddenly breaking news? It bears resemblance to most of the propaganda stories we have seen in recent years:

- it is based on truth. Supply chain attacks are known to exist

- the US government has a goal of escalating with China over trade and IP practices.

- national security threats justify nearly any form of government action in today's world.

- the story turns out to have been leaked through foreign sources. This is typically the pattern we see because of concerns about propaganda coming directly from US government officials to US news outlets. There is typically a middle layer that is outside of the US where the allegations can originate from until they are broadly accepted as fact.

So Apple and Google are not really lying. Chances are there has not been any sort of major security breach in either of those companies due to supply chain attacks. It is possible that they have been barred from revealing information about it for national security reasons (in this case propaganda reasons).

So I think we can expect the following next steps:

- The story will continue to hover in this slow reveal format until enough laypeople come to understand the key concepts -- circuit assembly, components, trojan horse components, QC processes, subcontractors, etc. Once the stage has been set there will be more revelations and leaks from major companies that corroborate the story.

The goal is to make China the crisis in the buildup to the 2020 election. It's not a coincidence that this strategy is getting underway right after the midterm elections in the US.

Our president has already been attacking China with rhetoric and trade sanctions, and this story is meant to turn public opinion broadly against China.

The supply chain attacks do not have to have been significant (or successful) to make this happen. The very idea that "sneaky" Chinese intelligence agencies and firms would be able to slip this by US firms' quality control measures is enough to inflict paranoia on Americans and help them start to view China as a terrifying adversary that must be stopped.

China's military outnumbers the US military by 20:1 in terms of the number of active duty fighters, and China's economy is approaching first world standards in major cities far faster than the US had ever expected. China dominates scientific publications in the hard sciences, and its top universities are 10x more competitive (or more) than top US universities.

So hawks in the US realize that this may be the last opportunity for some sort of power projection or military driven containment of China's ambitions.

This is foolhardy, because China is led by a group of highly rational people whose policy responses to the administration's trade threats have been masterful and precise, and have conveyed with no uncertainty that China will not be bullied.

So what we're seeing is a short time horizon strategy by the US which is meant to have electoral consequences in 2020 and pave the way for some degree of hostile escalation with China. US weapons systems are still significantly more advanced, but China has likely weaponized many aspects of US infrastructure via these sorts of supply chain attacks. My guess is that the US Government is not aware of many of these, and will panic when they are discovered.

Fortunately for us all, China's leadership is calm and not prone to knee-jerk responses. China is rising to world prominence faster than expected, and the US will not take that lying down. However it is probably too late at this point, as China has a tremendous amount of soft power stemming from its importance to the US supply chain. Because of this there is still much hope for a peaceful, trade-driven equilibrium to emerge.

Re: New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom

#80

It seems like there are two possibilities to me: 1) Bloomberg has a number of sources that are mistaken/misinformed, but this is not necessarily a made-up story, or 2) Bloomberg is nearly correct (minus some technical details) but the US government is forcing these companies to respond as if the story is wrong - possibly because of diplomatic reasons. What is the likelihood that #2 is correct? (there are other altern…

The US cannot force those companies to lie. They can force them to stay silent, in which case they'd just say "No comments". If those companies are lying, they are committing security fraud.

You are right and you are wrong. Legally, you are right. Practically, there is evidence that various elements in the US Government have at times coerced people into making untrue statements.
Post reply on HN