I mean, honestly, hats off if that's the case. That would be pretty cool. But you need actual evidence for such a tale.
I mean, honestly, hats off if that's the case. That would be pretty cool. But you need actual evidence for such a tale.
I'm not sure why you're implying that you need a super-spy to pull this off. If this was done at the factory level they likely had access to the same manufacturing equipment used to make the motherboards, so there's no need to manually solder anything. The implant was alleged to be a surface-mount component so it could be as simple as reprogramming the pick-and-place machine or swaping out the reels. Given that this is china enlisting a couple of technicians to your cause wouldn't be too hard[1]. From there once they figure out a particular order is going to a juicy target they can ship the bugged boards in place of the untampered boards.
> But you need actual evidence for such a tale.
Agreed. My main takeway from the article is that this hack could happen, not necessarily that it has happened.
[1] it's not unlike the concerns that there are NSA backdoors in intel cpus (eg. AMT/vpro, or RDRAND), or windows (NSAKEY).
The factory doesn't have assembly lines marked like 'for apple', 'for the nsa'. It's just an assembly line making a bunch of identical boards. You'd have to identify a specific board way after it's left the assembly line, and probably after being integrated into a chassis to put your spy chip on it if it's targeted at a specific customer.
2. Wait for an order from apple
3. Add the bugged boards
If the warehouses and manufacturing lines are all in China (as is the case with just in time manufacturing) I don't see why this is difficult to pull off.
Is that not how it works? If so, I'd like to know why.
It's not some giant leap of the imagination.
That's pretty much it (if the story is not bullshit). That, or cooperation from Supermicro or whoever was their distributor to the target.