Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
servethehome.com
servethehome.com
From the perspective of someone who merely reads what experts write, that isn't true at all. If you have information on your enemy's operations and they are unaware, you have the information advantage and you don't give it up. You use it to monitor them, trace their activities: For example, where does the connection go? And where does the information go from there? Plant malware in whatever is sent back in order to trace who accesses it and maybe give you a backdoor, or if you can't do that plant false information and see where it turns up. Also, who is physically planting the PCB? Mine them, their activities, and social network for more intel.
Also undermine your enemy with false information and by shutting them down not now, reactively, but at the worst possible time for them - when the crisis hits in the South China Sea or Taiwan, pull the plug on their intel or start feeding it false info. And in the meantime, avoid giving them anything too valuable.
On one hand, undoubtedly I have massive blinds spots in my knowledge and the details are probably somehow wrong. On the other, I'm somewhat confident that many times, an intelligence agency would not reveal what they know and would do the kinds of things I'm discussing.
This is obvious. This article is annoying to read.
> The illicit chips could do all this because they were connected to the baseboard management controller, a kind of superchip that administrators use to remotely log in to problematic servers
The discussion of DRAM only really seems necessary if that _isn't_ plausible.
This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.
That doesn't square with all the reports on US domestic and international spying, much of it in the NY Times, not to mention The Intercept and others. How do you think we know about it? Not from Chinese and Russian newspapers.
> We’re seeing a lot of anti Chinese and anti Russian news
Hmmm ... maybe we're seeing a lot of Chinese and Russian activity. If you look at coverage of the current US President, you might notice a lot of 'anti-US' news also. Under the prior administration, there was a lot of that on Fox News and in the Wall Street Journal.
I think that's a misreading of their article. They were not claiming that's what was actually done, they just provided that as an example of what a HW attacker could do. Later on I remember them saying that the malicious part was connected to the BMC, not the main CPU. If there's a serious USB vuln in the BMC, then four wires could be enough to compromise it and gain God Mode over the early x86 SW environment.
And I believe that once you control the BIOS image you control the boot chain of trust.
Presuming you can get control of the BMC and transmit arbitrary network traffic, you'd have to limit it somehow. At least some of the compromised servers would be installed in places where any unexpected outgoing network traffic would be noticed and investigated. Large amounts of detectable traffic could be generated too if these things are all pinging away at something. You'd have to trigger it somehow I suppose. But what kind of trigger can you set up on a server running an unknown OS in unknown configuration that may be behind lots of firewalls? Are we sending some kind of weird magic packet to the server? If I was Google or something, I'd have dumb filtering firewalls set up in front of my servers that drop anything that doesn't look like normal network traffic, just to keep any random person from fuzzing the server and triggering some weird unknown bug.
Also - I found it funny that the "horrific exploit" was just piggybacking on a mgmt engine vuln...
This caused a small stink a while back but I doubt if anything's changed.