Live data from Hacker News

What Businessweek got wrong about Apple

apple.com

81–90 of 183 posts

Re: What Businessweek got wrong about Apple

#81
post #12

Both Apple and Amazon have released VERY STRONG denial statements that bring the whole Bloomberg narrative into question. It's also convenient that no one has yet been able to verify or find any of these mysterious Chinese chips on any of the Supermicro servers in the wild. So what is the real story here? Did Bloomberg reporters deliberately deceive everyone or were they deceived by the US IC ("intelligence community…

Remember when Clapper gave the "least untruthful answer possible" about domestic bulk collection? [0] It's naive to think Apple and Amazon couldn't lie in response to the article, if the intelligence was highly-classified. They may be under extremely strict gag orders (e.g. "give no response whatsoever, including silence, other than denial") and protected by promises of indemnity, as telcos were in the wake of the NS…

> ...every hardware pentesting shop will be going after these boards like they're looking for golden tickets.

The way the original story was written, it suggested that four subcontractors were identified, and almost 30 targets selected, with the implied suggestion that either the boards were custom special order boards, or destined for a specific lot order made by a customer. If true, then it is unlikely these boards will be found in the wild except by slipping through those almost 30 targets into the used market.

Supermicro has about 600 board SKUs, so finding these needles in the haystack is likely more feasible by approaching data centers offering to help find the boards for free, in return for allowing the pentesting firms to take physical possession of such found boards.

The story did reveal that the original "tell" that gave away the chip was odd but not obviously malicious at first glance network traffic, and that the suspected intent was implementing an Advanced Persistent Threat model. The article also mentioned the chips were connected with the BMC, but it wasn't specified in the article whether or not the chips got out onto the Net.

So finding the boards in the wild probably will focus upon finding them in the same manner, over the network. Power down the server, let the BMC stay powered on, and watch for unwarranted network activity. Or boot a Linux on a stick that deliberately does as little as possible and premises networking allows it to do just enough routing out to the Net to capture traces of what unauthorized network traffic is trying to do, and watch for unwarranted network activity, in case the chip design is clever, and hides its activity until it detects the mainboard is already running before trying to inject its network payloads onto the mainboard's network interfaces.

What are others' thoughts on how to find these "golden ticket" boards?

Re: What Businessweek got wrong about Apple

#82
post #52

This article sounded a bit weird to me from the technical level, but I just assumed it could be lack of clear understanding on the nitty-gritty from the journalist, or just me not knowing about hardware enough to know what's possible and how. Given this is all getting a little fishy I'll share what had me thinking: 1. The article mentions "they were capable of doing two very important things: telling the device to co…

If this is actually true (and I have doubts), the reporting will explode in the next few days/weeks with all the detail you could wish for.

A few pins can be enough to write to memory, if there's an interface for it (SPI, I2C, but I'd be surprised to see those unprotectedly lying around on a server board ...). It's be very slow, but I think networking could work as well. With efficient software the resources needed on the chip itself could be held very low and eventually offloaded to the main processor.

I don't think it has any wireless or DSP stuff.

I don't know enough about processors, memory, networking and low level software security to know how difficult it is to compromise a computer with such a chip on the main board, but the chip itself certainly seems feasible.

But: It must be really expensive to manufacture the compromised devices. It just seems stupid to manufacture every device with such a chip. 1/1000 seems reasonable. The larger companies have (had?) lots of them anyway.

Re: What Businessweek got wrong about Apple

#83
post #74

Companies don’t give vehement denials like this unless they’re telling the truth. People claiming gag orders are crazy, mostly for thinking that Apple, or anyone else for that matter, would ever sign a document forcing them to lie to their customers (I’m not saying they wouldn’t lie, just that they wouldn’t sign anything that would force them to do so).

That makes no sense. What do you think is the difference in "denial levels"? Kind of like Dragonball-Z power levels? Does a "vehement denial" cost the one making it any more than a "meek denial"? If making "vehement denials", coming at exactly the same cost as less strong denials, are more effective, you would just have made all PR companies/people extremely happy - they get a stringer weapon for free. All the have to do is issue "vehement denials" instead of just "denials" and a larger share of the population believes them (for no valid reason). Especially when the public has no way to get the "real truth" but can only watch a Dragonball-Z style "strong statement" vs "incredibly strong statement" showdown.

> People claiming gag orders are crazy, mostly for thinking that Apple, or anyone else for that matter, would ever sign a document forcing them to lie to their customers

Why do you think a "gag order" is something that has to be signed off on by the one getting it? That too does not make any sense. An order is issued by someone who has more power, here, the government. You don't have to sign anything for the order to exist. "Gag order" has "order" right in the name.

Re: What Businessweek got wrong about Apple

#84
post #72
post #15

The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…

« Firstly, why would you add a new chip to a board, rather than alter an existing one? » Altering the flash chip would be too obvious. Looking at the flash image (dumping it) or chip (x-raying it) would be the first thing anyone would do if they suspected something fishy. Swapping a flash chip with a compromised one is a textbook 101 supply chain attack... However a small rogue chip sitting on the SPI link (between t…

Great insight. Thank you.

Re: What Businessweek got wrong about Apple

#85
post #15

The cynic in me wonders about the plausibility of all this. Firstly, why would you add a new chip to a board, rather than alter an existing one? That would be essentially undetectable. Secondly, why Bloomberg? It's an odd organisation to get a scoop on something like this. Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the…

I don't think Blomberg is politically motivated. Maybe their sources are. Bloomberg is traditionally anti-Trump.

Re: What Businessweek got wrong about Apple

#86
post #52

This article sounded a bit weird to me from the technical level, but I just assumed it could be lack of clear understanding on the nitty-gritty from the journalist, or just me not knowing about hardware enough to know what's possible and how. Given this is all getting a little fishy I'll share what had me thinking: 1. The article mentions "they were capable of doing two very important things: telling the device to co…

About halfway down, the Bloomberg article mentions a BMC, a baseboard management controller. This is an existing part of mainboard design that has been around for just under a couple of decades. Read up about IPMI and BMCs, what they do and what their capabilities are. Then consider the threat, explained elsewhere on Hacker News several times, of simply supplying an extra ROM chip containing different firmware for that processor to run.

Focussing on the technical is focussing on the wrong thing. Bloomberg's point was not that BMCs can do this, nor that they can be made to do this. People have discussed these on-board systems and their problematic natures rather widely. It was that the supply chain is vulnerable, and that (on the assumption that Bloomberg is right) this problem with the supply chain is no longer a hypothetical case of what an attacker government could do, but is now a documented case of what one government has done, a few years ago.

Re: What Businessweek got wrong about Apple

#87
post #71
post #18

Earlier quoted context omitted.

> Thirdly, they talk of the PLA approaching plant owners and such; to do all this, a lot of people would need to know about it, from the top to the bottom. I imagine that would be very difficult to keep secret. Well the bloomberg article said that intelligence sources knew that those boards were going to Apple and Amazon, so presumably (if the story is true) someone did speak, maybe

But why would anyone do this knowing that at some point they were practically guaranteed to get caught?

Because "getting caught"'s only consequence is that you have to use a new method. There is no punishment, no negative cost to be applied retroactively to compare it to the received benefits. The net effect still is highly positive since while it worked you got what you wanted. Same as in every spy operation, ever.

Re: What Businessweek got wrong about Apple

#88
It's hard to say what the truth is here, but what I will say is if that Bloomberg reporter doesn't have substantial evidence to prove that claim he could be in serious trouble. SuperMicro's stock was down 50% straight after that articles release, and it's not looking so hot right now either. He could be looking down the barrel of an SEC investigation very soon.

Re: What Businessweek got wrong about Apple

#89
post #29
post #23

The Norwegian National Security Authority ( https://nsm.stat.no/english/ ) is quoted in a norwegian paper today saying they knew about problems with Super Micro since at least june. https://www.vg.no/nyheter/i/xRkLep/storavis-hevder-kina-inst...

What exactly did they know? Did they check anything themselves or did they hear the same story from the US IC that Bloomberg also heard? Supermicro servers are extremely popular in data centers. Yet no one has noticed anything and no one has found any malicious chips in them. Unless the Chinese secret services also hacked all of the firewalls, someone would have picked up some outgoing packets that are going to Chine…

If it's real, it could be part of a bigger persistent threat. Maybe those chips would react to some signals, start to heat and fry the motherboard.

In case of military war, it could DoS many servers at once from the inside.

It could also be used to prematurely break the motherboards, and sell new ones.

There could just be there to ping C&C upon activation in order to locate datacenters, including military ones maybe (information that could be useful in that case of war too).

We can think of a few use cases than just spying on network packets.

Re: What Businessweek got wrong about Apple

#90
post #64

Earlier quoted context omitted.

The reason Bloomberg is so sure about this is because chips/'infected' Supermicro boards were originally found at Bloomberg. They noticed odd web traffic coming from a server, took a look, found nothing, looked closer, and finally found a hardware exploit. What you're seeing in the Bloomberg piece is a bunch of half-truths backed by soild data. It is a BMC exploit, and they are doing it through the BMC EPROM, and eve…

This also illustrates why hardware implants do not work as a mass infiltration tool. The idea is not getting caught, otherwise risking the whole operation. Implementing a threat like this is counterproductive.

Intel ME seems pretty successful though.
Post reply on HN