The Big Hack: Statements From Amazon, Apple, Supermicro, Chinese Government
bloomberg.com
bloomberg.com
It's either a giant conspiracy by the FBI and multiple mega-corporations to blatantly lie, on public record, about a matter that if happened would most likely come up in the future again. Furthermore if apple and amazon were both notified for comments, there is good reason to suspect that the FBI would hear of the article and try to censor such an article for national security reasons, especially so if they made apple and amazon lie about it.
Or ... Bloomberg didn't do their due diligence and were too eager to be duped by agents who wanted to push an agenda to move manufacturing away from china or something similar.
If it's made up, it's more realistic to believe the publication is complicit in the fabrication.
Could it be a conspiracy to deceive Bloomberg? From all the conspiracies, that seems the most likely to me.
Also, these companies want to continue to do business in China, and likely do not want to be on the record accusing the government of a massive criminal conspiracy.
Outright lying is financial suicide. Shareholders can and will sue the company.
"Apple never had any contact with the FBI or any other agency about such an incident." If Incident was being handled by 3d party private entity which was in contact with some gov entity this would hold true.
"We are not aware of any investigation by the FBI, nor are our contacts in law enforcement." If it was contacted by entity other than FBI this would hold true.
The vigorous denials from Apple and Amazon are suspiciously against the grain in these situations.
If you compare to MSFT etc whenever there is a "global cyber incident" the story is the same and correlates with the governments etc which is business as usual.
This is not business as usual.
They've also had accounting irregularities that caused their stock to be delisted from NASDAQ: https://www.theregister.co.uk/2018/08/22/supermicro_facing_n...
> "The delay primarily relates to the magnitude of work that the company must still perform in order to review the company's accounting judgements, estimates and records for transactions that occurred during fiscal year 2015 through 2017, as well as the assessments and conclusions on the effectiveness of its internal control over financial reporting."
It's interesting that the irregularities started in 2015.
Like, say, the matter of secret surveillance on the mass scale? I mean, the track record here is not exactly pristine.
> Bloomberg didn't do their due diligence and were too eager
That is a distinct possibility too. But I think we are now beyond the point where we could say "major tech companies would never lie together with the US security apparatus on a matter of public importance". They would, if they think it's worth it.
Furthermore, the argument against this would be that (from the denials PRs) Bloomberg has been approaching the involved parties for "several years."
Why would they decide to pull the trigger now simply from haste?
The PRISM denials were not vague and were perfectly true. PRISM was a system for handling subpoenas, and nobody denies getting subpoenas. If you ask e.g. Facebook they also won't deny proactively reporting child abuse to the FBI, which is another real US legal requirement.
This is just conspiracy theory thinking. You offer no evidence for this incredible assertion. Some companies have previously collaborated with the government, generally without explicitly lying, but we cannot jump to the conclusion that all companies would voluntarily lie in a coverup conspiracy -- which, by the way, opens them up to investor lawsuits and risks destroying their branding, for no good reason. We also do know that the government cannot legally compel companies to lie, only to remain silent.
> You offer no evidence for this incredible assertion.
The evidence to the above is publicly available and has been discussed to death. If you somehow managed to miss all of it, start with https://en.wikipedia.org/wiki/Mass_surveillance_in_the_Unite... and go on the links from there, it will take you some time.
> Some companies have previously collaborated with the government, generally without explicitly lying,
Yes, saying "we do not conduct this particular kind of surveillance ordered by this particular person" while knowing they conduct a slightly different kind of surveillance, ordered by different set of persons - is not explicitly lying. Just like saying "we don't have surveillance technology installed by FBI" if it's installed by NSA instead. There are many ways of lying without "explicitly lying".
> but we cannot jump to the conclusion that all companies would voluntarily lie in a coverup conspiracy
We can not and we do not. We do not know whether any specific company would lie - we just know this option is now very much on the table.
> which, by the way, opens them up to investor lawsuits and risks destroying their branding, for no good reason.
Being on good terms with somebody as powerful as US federal government is a very, very good reason. And I don't see anybody's branding being destroyed so far by the revelation of mass surveillance. We know about https://en.wikipedia.org/wiki/Room_641A and https://en.wikipedia.org/wiki/Hemisphere_Project - has AT&T brand been destroyed? Not in the least. And the government granted them immunity from lawsuits related to this.
There remains no evidence that any companies lied about secret surveillance on a mass scale.
They describe a microcontroller the size of a decoupling capacitor that is installed between the main CPU and main memory (as far as I can tell from the vague description).
I assume this would have to be done without layout changes. On a part of the board that is quite sensitive to layout changes. It just doesn’t seem likely that you’d do a hack like this. You’d need a micro controller or ASIC that was running as fast as main memory. You’d need to make it cope with different kernels... and edit memory such that remote servers could reliablely be contacted.
Why not just swap out some other part? Like the IPMI controller? Or the Ethernet controller? Something that has access to main memory, that would hide the functionality even better, and that would give the attacker more space to work with?
I don’t get it.
If the chip is inserted on the serial data line between the SPI flash memory and the BMC CPU, then, as an ex-InfoSec engineer, the whole thing sounds very plausible and even easy IMHO...
You have to expect that any article about intricate tech details written for a general audience will get parts of their descriptions wrong. Like you I was raising my eyebrows when I started reading. But when they mentioned the BMC, I believed. The author did not make a vague mistake when mentioning this very specific technical term.
In fact, the BMC is the perfect target for such a hardware hack: low-speed SPI flash memory interface easy to man-in-the-middle, BMC more privileged than the OS (can virtualize storage, keyboard, etc), BMC code independent of the OS (infect both Linux and Windows at once), BMC code changes so rarely that a backdoor making assumptions about the code layout and content would still work after many years of updates, etc.
Edit: I checked Supermicro servers from the 2015 era. Most used the AST2400 BMC. It boots from SPI flash so this backdoor chip only has to intercept and modify bytes on the data out (DO) line to inject malicious code.
AST2400 has option for two spi memories, one overrides the other by default. They simply put a microscopic spi flash in place of the second "recovery" flash.
I heard before the rumors of Chinese server mobos "talking" some gibberish on ICMP, so that must be it.
It might be interesting to try and reach out to that person, they may still have the hardware.
[1] https://communities.intel.com/thread/123362
Edit: the mobo in that post is the X11SPH-nCTF, which has the AST2500 BMC
The rest of your post aside, the FBI cannot do that. It wouldn't matter if it was secret. It's not even a close call, it's been explicitly and repeatedly slammed down by courts even in extreme cases like classified information being illegitimately leaked, for example with the Pentagon Papers (SCOTUS ruling [1] against prior restraint). It just came up again a few months ago when a federal judge tried to use prior restraint and depublishing against the LA Times over their publication of information about a confidential informant and bargain that was accidentally published in full on PACER. A rung bell cannot be unrung.
Now, if the FBI could find a leaker who had signed an agreement with the Federal government they could go after them in person. If a newspaper broke the law to obtain a story then that separate violation could independently be prosecutable (in public). But none of that means the publicly released information can then be taken back. And even if some random blogger might be intimidated illegally and not find the resources to fight back, that wouldn't be an issue for a major publication.
I don't take issue with your skepticism in general but it's not helpful to ascribe special powers to government that it doesn't actually have either.
-----
1: https://www.law.cornell.edu/supremecourt/text/403/713#writin...
Control the media conglomerates, lobby as control over the internet, control the sentiment.
Silence would be perceived as confirmation, and claiming to not know would be terrifying to their customers. Confirming it would risk their entire supply chain.
Sure, maybe it's not true... but the only move here is to deny it even if it were true. The corporations involved have a massive amount to lose here.
If China did this, kudos to them, in the sense that that's their job. Just like it is NSA's to do the same to them.
Apple, Google, Microsoft, Intel, FB and a few other companies can probably match China's expertise and expenditure. What about the rest?
>It’s untrue that AWS knew about a supply chain compromise
and Apple:
>we have conducted rigorous internal investigations based on their inquiries and each time we have found absolutely no evidence to support any of them.
There's no in "between the lines" or ambiguous wording there, they flat out deny it. Unless this small set of "TS/SCI cleared employees" worked completely on their own without reporting to anybody else in the company this means that they are lying in these statements.
It's possible that they do just that but it's a bit strange to me that they wouldn't find an easier way to deflect the issue without using such a strong and explicit language. Something vague like "we've been working with the authorities and have no reason to believe that any sensitive information has been leaked etc..." would be easier to spin if it turns out that somebody can prove that these attacks took place.
Surely if the scale of the attack was as large as reported by Bloomberg in their article it should be possible to find one of these backdoored boards in the wild? Or at least have testimonies by employees in these company that could testify that batches of motherboards were suddenly replaced for no obvious reasons?
And if trade war is the reason why deny it now? What do they have to gain from that, they're the victims in this story as far as I can tell.
In this case, if a cleared employee is asked: is this information true, is there such an investigation? Then simply by saying they can't comment on the question, they reveal the info to be true.
I think most people with high-level clearances would play it safe in such situations and just deny any knowledge of the situation.
I worked at Defense Science & Technology for a year, and there were levels of classification I wasn't even cleared to know about.
It was very common for someone to be working on something they could not tell their direct boss about, because their boss was not cleared for it.
The existence of it is important. I can't tell the content of x letter sent from China's Amb to the mother ship but I can tell you that we intercepted the letter. How was it intercepted? That in itself means a lot.
Funny they didn't deny that it happened, just said AWS didn't know about it.
> We’ve found no evidence to support claims of malicious chips or hardware modifications.
That's about as good a denial as you'll get from somebody with a lawyer.
This is fun.
> We did not uncover any unusual vulnerabilities in the servers we purchased from Super Micro when we updated the firmware and software according to our standard procedures.
Does that mean they did uncover some "usual" vulnerabilities?
Similarly no security team is going to say "There are no vulnerabilities in the servers we purchased." It's just not true, they're always there and expected.
In this context, "unusual" vulnerabilities would be evidence of a deliberate attack, rather than just common security mistakes.
These companies churn out some truly horrible software with little consideration for security.
It's often difficult to automate firmware updates, so they tend to stay vulnerable.
It's a similar situation to webcams: https://youtu.be/B8DjTcANBx0
The original article directly addressed this: "The companies’ denials are countered by six current and former senior national security officials, who—in conversations that began during the Obama administration and continued under the Trump administration—detailed the discovery of the chips and the government’s investigation. One of those officials and two people inside AWS provided extensive information on how the attack played out at Elemental and Amazon; the official and one of the insiders also described Amazon’s cooperation with the government investigation. In addition to the three Apple insiders, four of the six U.S. officials confirmed that Apple was a victim. In all, 17 people confirmed the manipulation of Supermicro’s hardware and other elements of the attacks. The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."
It is entirely likely that the companies affected were directed by the IC agencies working on this not to discuss or reveal their knowledge of the hack. Often in intelligence operations it is important and useful to not alert your adversary that you are aware of their intrusions until you are fully ready to take action against them, or have fully removed the danger.
I don't see any reason to take the companies' categorical denials as evidence that this did not happen or that they were not targeted. Those statements are what one would expect in a national security incident and investigation of this magnitude, with such serious implications.
Cyberwar with China is the current equivalent of the old Cold War scuffles with the USSR in third countries. How many lies were told back then, to cover up the worst mishaps? And then they were "uncovered" when it was safer or more convenient to do so.
If these companies are caught red handed lying on behalf of the Chinese or US governments it would set an absolutely terrible precedent, I don't see why they would risk it when they have so little to gain.
The richest and most powerful American companies, some of whom are critical to national security and/or make their operational security as a critical selling point (the CIA among others), would be found not to be in fundamental control of the essential infrastructure powering their core business. It would trigger expensive large-scale review of every server in the world, and investors would run for the hills. This would be massive, and have heavy repercussions in the markets. FAANG are not protecting the Chinese, they are protecting their own finances - and the authorities will let them get away with it because the alternative is unpalatable.
If you keep it as a denied rumour, there is an official excuse for people to just get on with business as usual - nobody wants to deal with a market crash, not even most traders, and after all newspapers say many things, not all of them true. Maybe Supermicro is compromised, and maybe if you really care about hardware security you should buy elsewhere <wink-wink>; but it's not official, so most people can just pretend nothing is happening and go about their day, until a solution can be found.
> I don't see why they would risk it when they have so little to gain.
They have everything to lose, though.
I'd like try to boil things down a little further for people:
1) Most things in the modern world require high degrees of trust. Once a significant portion of people begin to question the system, it fails.
2) The main goal of most organizations/governments, in general sense, who find themselves in a favorable position is to keep the game going.
3) Though it's impossible to control for all variables, 'we' believe we can manage most common ones. The uncommon (foreseen and unforeseen) often arise in times of crisis (panic behavior) and often are unwieldy.
So... the veracity of the story is generally less important than is managing reactions to it.
4) IANAL, but I worked w/them for many years and have crafted many statements. Communication is an art form open to interpretation.
5) I've long suspected that such "tampering" was standard practice, for any global power. Why? See point 2.
I encourage anyone skeptical about any portion of the story, to don his/her 'megalomania'-cap for a bit. Then everything, at least conceptually, should make sense.
Cheers!
This whole thing wreaks. Is it fake news? Are the statements from Amazon and Apple expertly crafted to fool people who aren't very good at reading comprehension (most people)?
So one must think about "Where did this information come from?"
It is at least a plausible theory that the story is largely true (though as I posted in another thread, I'd bet money it's not all entirely true), and that the denials are either made by people who are unaware of the truth, or are being made deliberately. (Actually, the people who literally prepared those statements almost certainly believe the truth of the statements. One of the most plausible ways for a group of people to lie is for all communication to come from individuals who genuinely believe the lies; no body language tells or any other such leakage about it not being true.)
It is also plausible that the denials are in fact true, in which case one is left with the very interesting question of "Where did all that information come from and why is it wrong?"
As a couple of people have also said, there's also the option that the story is largely true, and the denials are true if you parse and read them like a lawyer, but meant to mislead anybody who doesn't. I can't say I've examined them for that, but it's definitely a possibility to consider.
I'd actually suggest "propaganda" isn't a great explanation; propaganda does not generally depend on making lots of specific, refutable claims, and certainly not followed up by refutations immediately. It is usually designed to speak directly to people's emotions and fan pre-existing flames in ways specifically designed to not be refutable. If this really was government propaganda (note how that is more specific than my previous unqualified "propaganda", because anybody can propagandize, not just governments), I would expect the American companies would be strong-armed into agreeing with the story for the propaganda's purposes, or that the story would never run at all if they couldn't be sure the companies weren't going to back them.
An alternate theory that might fit all the facts is industrial espionage. Let's say the story is completely untrue, the denials completely true. What is the result of this story? Supermicro in particular stands to lose some business. Perhaps someone who benefits from that planted this story.
Another alternative is stock market shenanigans. As I write this, the delayed feeds aren't showing it yet, but Supermicro stock (SMCI) just took a 31% bath overnight. Who benefits? Short sellers, put option traders.
I have no idea myself. "Unknown unknown" is still a pretty large chunk of my personal probability estimates.
EDIT: I read the volume amount incorrectly - it's more like 6m of volume which is not too bad. Someone could probably make money shorting it but again since its delisted already it would be difficult/risky to do so.
Whatever is going on with whatever stock is being traded is now visible even in the delayed listings; you can see it on https://finance.yahoo.com/quote/SMCI?p=SMCI&.tsrc=fin-srch or your choice of provider.
PR departments don't vehemently deny, on point, an article from a major newspaper without consulting the higher apps.
There is literally no chance that this happened and the response was made in ignorance.
Either Apple and Amazon are lying or Bloomberg is wrong.
Apple and Amazon are compelled to lie. It's a classified investigation and likely only cleared employees are aware of it, and they have to deny its existence or stand to lose their clearance (worth $$$).
I mean, think of your own company's PR team. If you've worked for a large company, you've likely had interaction with a PR team that was pretty ignorant about the inner workings of the company. Now, add to that the fact that this is a classified investigation being run by FBI counterintelligence, and interfacing only with cleared employees (none of whom work for the PR team).
Do you release a press release denying everything without asking the guys who are supposed to know about it? Would those guys say to you it's all fabricated and urge you to deny it or will they evade answering it (or even more likely they'll go up the chain)?
This is a CEO level incident.
And as the article describes, the CEOs were summoned to DC, briefed, and at that point almost certainly asked to keep the investigation under wraps.
What I'm trying to get at is, it is possible for an agreement to be created for someone internally to know some "important" information in a company, and for it to not be known by others, even those higher than the employee.
For those who are wondering:
TS: Top Secret: https://en.wikipedia.org/w/index.php?title=Classified_inform...
SCI: Sensitive Compartmented Information: https://en.wikipedia.org/w/index.php?title=Sensitive_Compart...
[1]https://www.businessinsider.com/trump-zte-order-after-china-...
Bloomberg's article and Apple's statement can't both be right.
>"Three senior insiders at Apple say that in the summer of 2015, it, too, found malicious chips on Supermicro motherboards. Apple severed ties with Supermicro the following year, for what it described as unrelated reasons."
[1]: https://www.bloomberg.com/news/features/2018-10-04/the-big-h...
Possible that Apple employees with security clearance are the only ones with this knowledge i.e. it's fully possible that even Tim Cook doesn't know about this
So which is more likely: that multiple intelligence officials are making this up, or that Apple/Amazon/Supermicro feel obligated to lie because this is an ongoing classified counterintel investigation?
It's simply too early to tell who's telling the truth, who's mistaken, and who's lying here.
The language of the Apple refute is so strong, to the point of directly attacking Bloomberg and calling them irresponsible. So yes, in this case there are at least a few lies being peddled by the Bloomberg intelligence contacts
"Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not."
...which did not.
Conspiracy theorists aside, the main new thing that came out of the Snowden revelations was that Google’s physical security for data-center-to-data-center traffic was compromised by the NSA, which Google never denied, and responded by hardening server to server traffic.
At what point do such denials constitute a deceptive trade practive, enabling the Federal Trade Commission to bring action?
You can't lie in a privacy policy, or a TV commercial. Where is the line?
It almost makes you wonder if there is a process for ensuring companies comply with secret investigations and are forced to act publicly and privately as if they have never happened.
https://en.wikipedia.org/wiki/United_States_Foreign_Intellig...
Did Bloomberg, a widely renowned and distributed news outlet with immense resources, sacrifice hard evidence for sensationalism and clicks?
Or are these companies, all widely renowned with immense resources, bound to silence due to any multitude of shady reasons?
No matter the facts behind the story and these denials, this whole thing reeks of FUD.
It's not called "global capital" because it cares where to reproduce.
This is the system working as intended.
Who's next, Vietnamese?
Did you see the pattern here?
There are zero Supermicro factories in Mainland China AFAIK.
It is missing the word "offender" somewhere.
I think the question simply comes down to this; Can the Chinese Government be trusted?
The US Government can trust the Chinese Government as much as the Chinese Government can trust the US Government. ;)
The spy game has been played for 4,000 years...
I mean Chinese govn't literally buys intel from Chinese hackers. It's encouraged business until the Obama deal.
Or is it simply a matter of their shareholders having lofty expectations about tapping the biggest market in the world (China) and saying anything that angers China is the worst thing you could possibly do from a PR perspective?
"The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."
It would be whole lot harder to find these modifications if this was on the silicon itself.
Intel ME is well know to be on the chip itself. When you're really good you hide exploits in plain sight.
(a) the design process was infiltrated, which would have been done US side thus the nationality of the actors is debatable.
(b) the manufacturing process was infiltrated, which SHOULD have been picked up during design validation and production sampling.
(c) this whole thing is a load of rubbish.
Lots of questions here. This is not a tinfoil hat measure as well; genuine questions from someone who HAS worked in the EE side of things.
I wonder if this is a bunch of pre-emptive finger pointing and ass covering for an implant closer to home?
I don't trust either side of the fence if I'm honest.
> In one case, the malicious chips were thin enough that they’d been embedded between the layers of fiberglass onto which the other components were attached, according to one person who saw pictures of the chips. That generation of chips was smaller than a sharpened pencil tip, the person says. (Amazon denies that AWS knew of servers found in China containing malicious chips.)
There's plenty of precedent for missing things hidden away in stuff: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
Also stuff like this tends to show up on boundary scans. It's not that easy to cock around with signal integrity on these sorts of boards and get away with it.
I find the whole thing infeasible from a cost and logic perspective. The SMbus firmware and Aspeed sub-vendor are so much easier to hit and don't leave any corpses around to find after the fact.
Perhaps the lesson is not to underestimate the resources of a determined nation state with an economy the size of the USA's (or China's).
I don't find that method feasible.
Infiltration of supermicro IS but then you have to ask the question: who really did it as they are on US soil.
Remember the furore when Zenith was the last domestic manufacturer of TVs in the USA? We've come a long way since then..
Also does anyone have information about the "baseboard management controller" mentioned? I would like to understand the complexity required to MiTM a ROM or FLASH memory read by such a controller before concluding the feasibility and number of players in manufacturing chain required for it to work.
The problem is that it would require compromised people in several places at the subcontractors, because the design files for the PCB must be replaced wherever the PCB is made and in another place, at the PCB assembly, the pick & place document must be replaced and an extra reel with the backdoor component must be mounted on the equipment and that reel must come from somewhere else than from the normal suppliers of the assembly line without raising suspicions.
It can be done, but many accomplices are required. Because most of the time the backdoor component will pass the SPI data signals transparently, it will not be detected at any electrical testing and the usual optical inspections are unlikely to detect such a small change.
I am using many Supermicro motherboards, so I am wondering if this story is true. If it were true, it would not be much of a surprise, because they did not do something really novel but they just matched what USA also did, e.g. in the Cisco case.
[1] https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
On top of that Apple, Amazon and Super Micro are flat out denying this - I suspect Bloomberg messed up here.
I could be wayy of base here, but if its not illegal, than it would be pretty obvious what is going on.
Thus you wonder why more production isn't being shifted from China to, say, Thailand, Indonesia or India. Steve Jobs once said the industrial capacity to do the work simply isn't available outside of China, in terms of skilled people and supply chains, and that may be a big reason why.
Remember the "The telephone companies are routing all our calls and internet data to the NSA" conspiracy.
A bunch of people said that was fake, and there was no way this could happen.
Then more evidence came out, and the same people said there was no way that could happen, its too big of conspiracy and it would have leaked way before then.
Then the government gave the telco's retroactive immunity for spying on the public.
Though judging by the replies, I think Bloomberg needs some really solid sources, so there is probably nothing to it.
I know a commercially viable way to detect hardware attacks.
Standardized hardware designs, such as the "x86 standard," ARM IP licenses, and more recently, RISC-V, decentralizes manufacturing and drives the cost to commodity levels. I'm specifically proposing that the U.S. Government appropriate the patents on whichever hardware design and declare them a National Security asset, and then guarantee royalty-free licenses to any company that wants to use them.
When it's no longer a big profit center, China is no longer as interested in owning a monopoly on it.
And presto: there's no longer a monopoly on the hardware. Thus it's no longer a guarantee that your hardware is being bent to the will of a single nation-state. Hardware attacks can be detected as variations between the hardware made by one nation vs. the hardware made by another nation.
The downside is that Apple can't have the same profit margins that come from closed, proprietary hardware.
The upside is that manufacturing and process innovation (such as Intel used to do) becomes extremely desirable. It becomes so valuable that we saw Intel reluctant to offshore their best processes.
There: economic solution and political points, to boot!
Apparently one of the big factors in Supermicro success is that it has over 900 different motherboard designs, and hundreds of hardware specialists which can customize them further to client wishes.
Apparently one of the big factors in Supermicro success is that it has over 900 different motherboard designs, and hundreds of hardware specialists which can customize them further to client wishes.
How is that a sequitur arguing about "a few open-hardware motherboard designs" and the projections of them being "commercially succesful"?It is only used in 1 server. And given Elemental is mentioned, it must be a blade
So that matches nicely.
[1]: https://news.ycombinator.com/item?id=18146438 [2]: https://news.ycombinator.com/item?id=18138328 [3]: https://news.ycombinator.com/item?id=18145645 [4]: https://news.ycombinator.com/item?id=18138990 [5]: https://news.ycombinator.com/item?id=18141328
> Read: Statements from Amazon, Apple, Supermicro and Beijing
> The companies’ denials are countered by six current and former senior national security officials, who—in conversations that began during the Obama administration and continued under the Trump administration—detailed the discovery of the chips and the government’s investigation.
>"Somewhere in the Linux operating system, which runs in many servers, is code that authorizes a user by verifying a typed password against a stored encrypted one. An implanted chip can alter part of that code so the server won’t check for a password—and presto! A secure machine is open to any and all users."
I realize the intended audience for this article is not a technical crowd but can someone walk me through in practical terms how such a chip might subvert the /bin/login binary?
> Another common feature is virtual USB disk media, which can be used to infiltrate or exfiltrate files or to provide new boot media. The combination of these capabilities and remote power cycling would allow an attacker to seize control of most common server configurations. For instance, they could restart the system and boot from a virtual live CD, then directly copy or modify data on the host’s storage devices
If the IPMI has write access to disc and/or main memory, you can do it more directly - drop a new /bin/login on the disc, or patch it in memory (similar to the LoJax attack: https://news.ycombinator.com/item?id=18090651)
> Two of Elemental’s biggest early clients were the Mormon church, which used the technology to beam sermons to congregations around the world, and the adult film industry, which did not.
Surely one of them could show the world/researchers an infected motherboard?