Live data from Hacker News

Making sense of the alleged Supermicro motherboard attack

lightbluetouchpaper.org

81–90 of 328 posts

Re: Making sense of the alleged Supermicro motherboard attack

#81

Earlier quoted context omitted.

FTA: https://assets.bwbx.io/images/users/iqjWHBFdfxIU/iWRg56pmx50... > [...] a picture of the alleged implant. This shows a 6-pin silicon chip inside a roughly 1mm x 2mm ceramic package – as often used for capacitors and other so-called ‘passive’ components, which are typically overlooked.

It might be possible to mount an attack from a board location occupied by a legitimate passive component (or a single SOT-23 transistor, something like that). In that case the attacker would only need to replace a reel of legit passives in the PnP machine. Visually they'd be identical.

SOT-23 only has three pins, seems like it would be challenging only having one data pin.

The alleged component in question had six pins, if it were passive it must have been a bank or array of passives since individual passives generally only have two pins each.

Re: Making sense of the alleged Supermicro motherboard attack

#82
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

but where are said chips being made?

Re: Making sense of the alleged Supermicro motherboard attack

#83

Earlier quoted context omitted.

> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.

Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.

[deleted]

Re: Making sense of the alleged Supermicro motherboard attack

#84
post #66

I’m just going to throw this out there: BMCs and ILOMs are for tiny shops where “the IT guy” might have to do something from the beach at Cannes on their vacation. If you are a large operator like Apple you absolutely do not need BMCs.

Well that’s just incorrect.

Re: Making sense of the alleged Supermicro motherboard attack

#85
post #71
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

First guess: not being allowed to admit it due to national security reasons and it being an ongoing investigation. On the same day several Russians were exposed trying to attack OPCW. They were exposed by Dutch military intelligence. At the press briefing the UK ambassador was there. Same day US indicts several Russian spies. This to show that these are major, international events and that proper disclosure towards i…

If they are under a gag order, they would simply not comment on it. Lying about it is never required and puts them at risk for shareholder lawsuits.

Re: Making sense of the alleged Supermicro motherboard attack

#86

Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.

Really, you think it’s easy to spot a few stealthy packets among trillions? You have far too much faith in detection capabilities. Many of the best companies go years without detecting rogue traffic.

Also, just because you don’t know where the boards are does not mean that they don’t exist.

Re: Making sense of the alleged Supermicro motherboard attack

#87
post #65

I think the attacks are real. A year ago, Google announced their Titan firmware security chip[1], which would limit these kinds of attacks. I don't believe they designed and built this chip, and surrounding infrastructure, because of purely theoretical attacks. Besides that, over the last couple years there has also been a lot of work trying to neuter the Intel ME, because of how dangerous it is. Another example is t…

I think the attacks are real and if China is doing it then anyone else may be doing it as well including the US.

Re: Making sense of the alleged Supermicro motherboard attack

#88
post #30

Earlier quoted context omitted.

There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.

Cloud instances are generally firewalled off from each other, usually cross-account, vpc, etc. Two machines can't reach each other just because they're AWS instances. That would be silly.

The attacker and target have VMs on the same hardware. The attacker has a fake presence serving cat pics which is constantly sending “valid” logging traffic to an S3 bucket.

The chip passes the stolen data between the VM instances by DMA. The stolen data hitches a ride inside an otherwise innocuous TCP packet storing log entries in that S3 bucket.

Logs are routine backed up off site.

There would be absolute nothing at the network level to distinguish the infiltrated packets.

Lower latency scenarios could be devised which would be similarly invisible but allow better command & control.

Re: Making sense of the alleged Supermicro motherboard attack

#89
post #3

Earlier quoted context omitted.

EE here, looking at the size of the chip, the weight and power difference is going to be too small to measure. Latency will probably not be affected when the chip is dormant

One of the bloomberg articles claimed that in some cases it was "thin enough that they’d been embedded between the layers of fiberglass" -- like as if it were a passive in a blind/buried via? This seems like a very sophisticated attack.

Passives don't have enough pins to do much of anything, unless it's an array of passives in a single package that happens to be on power, gnd and data lines at once.

But, I'm not sure but it seems like a bit of a red herring. Reading the article the chip in question doesn't sound passive at all: "The Supermicro board here appears to have a QSPI chip, but also a space for an SPI chip as a manufacturing-time option. The alleged implant is mounted in part of the space where the SPI chip would go."

edit: so maybe it was an array of passives that were meant to go across every pin of this protocol in a single package.

Re: Making sense of the alleged Supermicro motherboard attack

#90

Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…

The open questions seem to be:

- Is a legitimate news organization incompetent when it comes to a deeply technical investigation?

- Why are large publicly traded tech companies refuting the article to the point of potentially defrauding investors.

I don't think the power of international players and the maturity of their strategies plays into it very much. I think you can assume they are incredibly powerful/pervasive and still doubt Bloomberg.

Post reply on HN