3 ms·
The article says: But they were capable of doing two very important things: telling the device to communicate with one of several anonymous computers elsewhere
by 07d046 8y ago
The article says:
But they were capable of doing two very important things: telling the device to communicate with one of several anonymous computers elsewhere on the internet that were loaded with more complex code; and preparing the device’s operating system to accept this new code. The illicit chips could do all this because they were connected to the baseboard management controller, a kind of superchip that administrators use to remotely log in to problematic servers, giving them access to the most sensitive code even on machines that have crashed or are turned off.
To me, that makes it sound like they could download from a remote host and inject code and do literally anything.
- jeletonskelly 8y agoIf this is indeed the case, I'm surprised someone didn't catch something earlier when the device was calling "home" over their network. I'm wondering if China stole BlackRidge First Packet Authentication tech [1] to keep things dark. BlackRidge is... "involved" in IC and defense projects. [1]https://patents.google.com/patent/US8346951B2/en https://patents.google.com/patent/US8346951B2/en