3 ms·
I have not seen anything that indicates how installing this chip would do anything at all without also modifying the trace design and fabrication of the PCB its
by cyphunk 8y ago
I have not seen anything that indicates how installing this chip would do anything at all without also modifying the trace design and fabrication of the PCB itself.
Also does anyone have information about the "baseboard management controller" mentioned? I would like to understand the complexity required to MiTM a ROM or FLASH memory read by such a controller before concluding the feasibility and number of players in manufacturing chain required for it to work.
- adrian_b 8y agoThe BMC is an ARM microcontroller that has complete access to everything, exactly like the Intel Management Engine, but the server vendors prefer a separate chip for the same job. What is described in the article is very easy to do by inserting a microcontroller on the SPI link that connects the BMC with the flash memory containing the BMC programs, which are copied from there to a RAM at boot. However, such a microcontroller would need 8 pins for at least 7 signals: ground, power, SPI clock and 4 SPI data, to and from BMC and flash memory. Nonetheless, 8-pin packages can be very small, e.g. 0.8 mm by 1.35 mm, i.e. only slightly larger than 1 square millimeter. So from a technical point of view, all is easily feasible. The problem is that it would require compromised people in several places at the subcontractors, because the design files for the PCB must be replaced wherever the PCB is made and in another place, at the PCB assembly, the pick & place document must be replaced and an extra reel with the backdoor component must be mounted on the equipment and that reel must come from somewhere else than from the normal suppliers of the assembly line without raising suspicions. It can be done, but many accomplices are required. Because most of the time the backdoor component will pass the SPI data signals transparently, it will not be detected at any electrical testing and the usual optical inspections are unlikely to detect such a small change. I am using many Supermicro motherboards, so I am wondering if this story is true. If it were true, it would not be much of a surprise, because they did not do something really novel but they just matched what USA also did, e.g. in the Cisco case.
- cyphunk 8y agoBut also if a modification of the SPI bus can result in exploitation then the manufacturer will just patch the memory in place. Cheaper, easier, less detectable. So... the manufacturer is not the source of attack.