Supermicro spy chips, the sequel: It happened, insists Bloomberg
theregister.com
theregister.com
open source version of it here:
https://github.com/openbmc/openbmc
If the attack happen on BMC part of server, it is also very easy to detect it. Put the system in a network and start sniff the network connection on its bmc network port if you see any out going connection, one can start investigate it. Linux has a lot of tools to analyse random network connections.I have no proof that BMC is indeed part of the spy ware. I just worked on BMC and know its capabilities.
Not necessarily! At least on some hardware it would be pretty easy for the BMC to cause targeted packet-loss (e.g. by replacing microcode on network controllers).
So if I were a state level attacker, I would get data out by causing a tiny amount (1%) of packet loss based on a secret key-stream and the data I wanted to exfiltrate. (I'd use the sequence numbers to index into a rateless error correcting code or similar.)
Then I just need to be able to surveil a host you're communicating with for long enough to recover the data. This also strong privacy for the destination of the attack if the attack is ever discovered.
If you're just trying to exfiltrate secret keys or the results of complex queries (as the attacker->victim channel can be high bandwidth without being too suspect) then it could be exceptionally difficult to detect this.
What if they didn't know what the chips did and were waiting for them to "make their move" and phone home or whatever.
I also find it hard to believe, I'm just trying to think of ways it could maybe be possible.