[1] https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
[1] https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
> Servers, routers get “beacons” implanted at secret locations by NSA’s TAO team. (subtitle from the article in GP; emphasis mine)
Didn't make sense at first but now it does. Yeah, that would be impressive.
There is no need to add imaginary Chinese spy chips to Supermicro mainboards the common AST2x000 BMC chips are already ideal spy chips by design and given the observed quality of the firmware e.g. there used to be an undocumented command available via the SSH management shell to drop into a root shell on the BMC and you could just download the plaintext password file required to log in via HTTP. While disclosing the password file via SSH is bad you can't even blame Supermicro for storing the plaintext passwords in the first place since IPMI BMCs have to store the plaintext passwords because they're required for the terrible challenge-response handshake mandated in the protocol which doesn't allow storing only a precomputed salted hash over the password. How many companies dispose of old servers without wiping the BMC passwords? How many of them reuse a single password over large parts of the server fleet? Some days I find it hard to attribute this to incompetence instead of malice. Now where have I left my tinfoil hat? sigh