Supermicro hardware weaknesses let researchers backdoor an IBM cloud server
arstechnica.com
arstechnica.com
Boiled down it comes to: Trust absolutely nothing. When a customer finishes with a server, wipe absolutely everything, re-flash every single bit of firmware on every single device in the machine, and don't use the standard flashing mechanisms to do so. It's worth a listen/watch.
I'm not surprised. Unless you pay for their "enterprisey" datacenter management products (which are still relatively new), it's a PITA to perform BIOS and BMC firmware updates. Additionally, Supermicro specifically recommends that you DO NOT flash the firmware unless you are experiencing issues that a new version is suppose to fix -- unlike pretty much every other vendor (like Dell, who makes it fairly easy to do so).
Flashing the Supermicro BIOS, yeah, that's a disaster.
Do people still teach about the Maginot Line in schools?
No.
There are plenty of other opportunities to teach the value of making your adversary (be that adversary man made or natural) work every step of the way and they are missed too. Nobody (for large values of "nobody") gets taught about the value of layered or redundant systems until college and those that do get taught it in college usually only touch on it in their mandatory ethics elective.
FWIW I named the last firewall I configured "Little Maginot".
They should, audit every bit of firmware (indeed it's odd how the researchers changed one bit in the BMC firmware and no checksum flagged it up on boot) and whilst this is daunting, it isn't that hard as they just have to compare and verify it is the same as the known safe image. Sure they could blindly reflash, but then they would miss any attempted expliotations and equally shorted the life of the hardware by increasing the odds of the flash memory failure.
Whilst people see BMC's as one avenue, a server/pc has many components, all with their own firmware and in many cases, own CPU. Be that a network card, graphics card and even keyboards and mice (though the later, not so much a factor in server environments, still a consideration).
Security is and always will be a mindset. You need to think like somebody who wants to break into your environment, and then counter those ways. But so many avenues. Imagine your sat at your desk as an administrator and one morning you get a nice shiny, cool top of the range keyboard sent, dressed up as a gift. How many would think, cool, plug it in and feel all fuzzy? How many would audit the firmware on that keyboard? How many would question the random gift at every level?
I'm sure IBM are not the only ones who would fall foul of this avenue of BMC exploitation, but I'm disappointed that for me, basic sanity checks in their sanitisation process to decommission and recommission a server are being overlooked.
Still, when you hire a car - do they audit the cars management engine firmware? Do they erase previous BT and WIFI connections stored on the radio? Well, from my experience - they don't.
Remember - you can pay an expert all the money in the World, but do check their work.
I've pulled many contact details from cached data on rental vehicles. Always worth checking what the stuff you pair your phone with asks for and keeps.
The industry at large has been pretty sceptical of Bloomberg's claims, and rightly so, but what if they just got the details wrong and it was this (or similar) vulnerability in the BMC software, rather than a dedicated spy chip, that they meant to write about?
0: https://www.bloomberg.com/news/features/2018-10-04/the-big-h...
Either way, this looks terrible for SuperMicro: "Yeah, our servers don't come with built-in backdoors - it's just SuperEasy™ for attackers to add one once shipped -- please buy more now."
It looks like the blame squarely lies with IBM (for not correctly resetting the BMC between users of the machine), or Intel (for a poor design which allows this in the first place)
The Bloomberg article was about a hidden chip being installed on a motherboard that provided a backdoor.
Bloomberg's story was about a (supposed) backdoored chip installed into the server at the factory, this is about flipping a bit in the firmware installed on the existing BMC.