Supermicro servers are extremely popular in data centers. Yet no one has noticed anything and no one has found any malicious chips in them. Unless the Chinese secret services also hacked all of the firewalls, someone would have picked up some outgoing packets that are going to Chinese C&C servers. And those would have been scrutinized and chased down. A company I interned at this past summer was scrutinizing every client on their internal network. They would have easily detected a machine that was connecting to an IP outside the subnet, for example.
This whole story is just fishy and every company mentioned in that Bloomberg piece is not only denying it, but strongly denying it ever happened. And Bloomberg reporters have zero evidence... except for some stories from "anonymous sources".
Now the article may or may not be a hoax, but a few years ago the NSA was exposed doing exactly that. So at the very least it is credible.
As for detection, I’d rather expect this devices to be activated on demand, like creating a backdoor, rather than sending streams of data from all servers, most of which (per the article) will be owned by an adult website or a mormon church which aren’t exactly strategic activities.
--- NSM is aware of the issues with Supermicro.
"- We know about this, but can neither deny nor confirm it is correct. We register that this is being denied by the companies", says Monica Strom Arnoy, communication director in NSM to VG.
NSM has, however, been aware that Supermicro may have been compromised, long before Bloomberg's article.
"- We have known about this since June", says Strom Arnoy, who does not wish to further explain from where they have this information. ---
My reading is that they suspect Supermicro. Further, that they are familiar with the claims about Apple and Amazon but won't confirm or deny whether they are correct. Damming for Supermicro, less clear for Apple and Amazon
In case of military war, it could DoS many servers at once from the inside.
It could also be used to prematurely break the motherboards, and sell new ones.
There could just be there to ping C&C upon activation in order to locate datacenters, including military ones maybe (information that could be useful in that case of war too).
We can think of a few use cases than just spying on network packets.
Obviously could be many factors, but does strike me as odd.
Would be nice to quantify this.
At least for Amazon, having jepardiced servers, this goes strait to the core of their business namely customer trust. Until now Amazon did not have any data breaches of customer data which they did pride themselves a lot for. If the Bloomberg story is true, this ould be at risk. So, yeah, a strong denial is exactly what one could expect. I'm curious to see that story unfold.