I don't doubt there are highly-targeted supply chain attacks that happen at the whims of state level actors but the specifics presented by this and its previous reporting still are difficult at best to believe with the reporting as it is presented.
I don't doubt there are highly-targeted supply chain attacks that happen at the whims of state level actors but the specifics presented by this and its previous reporting still are difficult at best to believe with the reporting as it is presented.
I do, and based on that it feels perfectly reasonable to believe that every other superpower probably has an equivalent. It also feels perfectly reasonable that server BMCs would be a common target for all such units considering the ludicrous access they provide, e.g. remote BIOS flashing, continuous screen recording, etc.
So based on motive, means, and some circumstantial evidence, we can estimate that this is likely happening. Enough truth, at least, to guide purchasing choices away from SuperMicro.
1) The US and China have lots of espionage going both ways and both countries are always trying to do something like this.
2) The Bloomberg story had no evidence whatsoever for any of the specific claims they made, not even "the nice NSA man told me to trust him".
And for a bonus, 3), there are probably other stories that happened and didn't get reported in media.
Agreed 100%, that's why it feels so weird that conversation around this story always seems to drift toward reasons it must not have happened instead of looking for the islands of truth in a story that's probably way way way worse than any of us realize.
You’re shifting the burden of proof.
We're talking about data centre servers here, that's what the Bloomberg story is about. For a backdoor like this to work it has to be able to phone home, and that means getting transmissions out of the DC network. This would require knowledge about the target network infrastructure (which isn't impossible if there are specific targets) but there's no way to do that without the transmissions being visible. I think a hack like this is much more likely to be viable against consumer and mobile devices.
Given that this is all a genuine risk, the Bloomberg story is particularly harmful. It creates the real risk that reports of genuine hacks or vulnerabilities will be sidelined due to reporting on issues like this being tarnished by association. Crying wolf is not good preparation for dealing with real wolves.
I don't think knowledge about the target network is required, just the ability to detect what default route is used by the OS. It also wouldn't need to "phone home", just phone into a controlled network. It wouldn't be a complete fantasy to assume that some software telemetry/update endpoints are compromised.
And steganography using TCP sequence numbers is a real possibility, so once a link to a friendly endpoint is established, the backdoor wouldn't even need to generate its own packets.
If you find an ethernet connector with a tiny SoC inside it, I'd say it's pretty bad.
State actors are constantly doing this to each other. Never trust a nice wooden sculpture the boy scouts give you.
Except that isn't what happens in practice, rather the island is taken as confirmation of the rest of the theory.
That doesn't make sense.
We should care what irrational players use to draw their own conclusions when we are drawing OUR OWN conclusions.
Rather, most purportedly rational or logical decisions are instead rationalized ones, and it is rational to acknowledge this.
I'm not suggesting throwing the baby out with the bathwater, just awareness that as decision makers our ability to apply logic is limited (in economic terms 'bounded').
In fact, perhaps our limited ability to reason is best imagined as a baby: full of endless potential, yet weak and fragile, easily perturbed, and requiring near constant care, attention, even vigilance.
> You can't just ignore the huge numbers of things in this story which straight up don't add up
The rebukes can boil down to: a) companies involved denied it; b) nobody else confirmed it; c) the picture in the story didn't seem to be legit.
Perhaps I miss other rebukes, as I didn't follow it very closely, but none of the above is convincing enough to dismiss the original story.
What is asserted without evidence can be dismissed without evidence. There is no evidence here. And it's not even a case of not being able to produce it, you could literally just get your hands on a compromised board and x-ray it. People do that all the time.
Falling back on "you can't prove it isn't happening" is a really weak defense. If they have stronger evidence, they should either present it or stop talking about it.
Not do we even know what their evidence actually is.
All we are left with is ‘trust bloomberg’.
Many many classified information didn't see the light decades after they happened. I don't see why this isn't such a case.
This is nothing like a pre-Snowden talk about NSA where someone theorised what was happening. This would be like if Snowden was quoted anonymously in an article and proof that was clearly fake was shown as actual leaks. Sure hardware modifications like this is happening (we know NSA does so) but this particular article (well, two now) is pure fluff and FUD pretending to have real proof. There's an interesting discussion to be had about this topic but those articles would make anyone a laughingstock if used as facts in the discussion.
There was something visceral about seeing a picture[1] of the NSA giving an intercepted Cisco router a hardware "upgrade" (beacon) in the Snowden files. Bloomberg tried to something similar for their story, but with fake pictures - that was a terrible idea.
1. Probably don't open this link if you have a security clearance - I haven't been following the status of the Snowden files, but it probably is still considered to be classified info https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
Do enough people have their heads firmly planted in the sand that they believe there is no state sponsored bumps in the night? That is the only reasonable defense for such low value publication.
Speaking for myself, I’m still not gonna just take three letter agencies at their word, but the source article shifted me from “probably false” to “probably true”.
There are a lot of these soft underbellies around, like the fact your browser trusts CAs from potential adversaries, people walking around with phones whose firmware is entirely controlled by potential adversaries. It's painful to think about what would happen should a war ever break out.
> Supermicro, Apple and Amazon publicly called for a retraction. U.S. government officials also disputed the article.
They mentioned the denials, and then in the next paragraph went on to say it was bigger than they'd previously reported.
They didn't at any point address the broad degree of skepticism that exists among security researchers. This is a story which was met with a pretty wide swath of knowledgeable and credentialed people (much like the primarily alleged sources in the article) who pushed back on it, let alone the alleged targets.
In fact, one of the few named sources from the original article (Joe Fitzpatrick) made statements after the publication of the article against his contributions to the piece after its publication.
Again, I don't doubt for a second that these types of attacks happen/exist but I have a hard time accepting the `facts` as they are presented in this case and I think that is how a lot of people feel.