4 ms·
They don’t say what the hack was and definitely do not say it was one of their pins. Probably some truth here, but as hard as they try, does not seem supportive
by jackconnor 8y ago
They don’t say what the hack was and definitely do not say it was one of their pins. Probably some truth here, but as hard as they try, does not seem supportive of their “chinese pin” theory. Very suspicious that this is related, I’m guessing they’re trying to do anything to cover their asses.
- annerajb 8y agoWhat is the chinese pin theory? Is this the name being used for the supposedly embedded on the PCB layers chip? Or the one that attaches on unpopulated pins/pads near the BMC memory area?
- trevyn 8y agoSounds like the Ethernet connector module was not from the, ahem, correct manufacturer: “Appleboum said one key sign of the implant is that the manipulated Ethernet connector has metal sides instead of the usual plastic ones. The metal is necessary to diffuse heat from the chip hidden inside, which acts like a mini computer. "The module looks really innocent, high quality and 'original' but it was added as part of a supply chain attack," he said.”
- RL_Quine 8y agoI'm not sure I believe this one as much, just based on the part you quoted. I can see a chip manipulating the BMC/IPMI flash to make it do things it shouldn't. I don't see how an ethernet port could be modified to be interesting. They're typically after the magnetics, or contain the magnetics themselves, so the only source of power would be the activity LEDs, or something, or maybe we assume a custom PCB as well. You've then also got to have it doing gigabit ethernet, or otherwise tampering with data it got from that interface, which feels unlikely. Maybe it's just the same as the last implant story, hidden in a less easy to find place? Hard to know without something even approaching technical information.
- simias 8y agoYou could easily DoS obviously, but beyond that I agree that it seems tricky to do anything worthwhile.
- moftz 8y agoIt could just be a sort of beacon to help identify where hardware went after the manufacturing process. If the same company is building the same hardware, the agent can slip in something more nefarious to make sure they target the right company. Servers are commodity products but they aren't manufactured in mass quantities like phones are. If a company orders thousands of them, that's likely thousands that will need to be made. A chinese manufacturing plant gets contracted to spin up production and an implant is slipped into some of the first boards just to see where they go. You don't want an expensive hardware trojan to end up in a Fortnite server; you want to hit Apple, Google, Lockheed Martin, Spacex, anyone with valuable IP or information. The more beacon implants you throw out there, the more likely someone will find one and you don't want to get caught too early in the game. Once those implants come online and phone home, you have a better idea where the remaining boards are going and slip in the real deal implants, the ones that will actually get you a backdoor.
- simias 8y agoHow would such a beacon work though? As RL_Quine points out there's only so much you can do at this point, especially if you want to be super stealthy. If you wanted to send a ping to an external server you'd have to craft an ethernet frame with the right target MAC address containing an IP datagram with the right IP address to be routed correctly in the datacenter and through the public firewall. You better make sure that your packet looks legit otherwise you're sure to trip anything looking for suspicious activity. "Hey look, our servers send weird packets to this suspicious IP, what gives?" And you have to do all that with a very low power device running from within the port itself. Seems like a very high bar to me, especially when there seems to be so many easier ways to backdoor a motherboard. But maybe the component is only hosted in the ethernet port but is actually connected to other signals on the motherboard.
- makomk 8y agoI've never seen an onboard Ethernet jack that doesn't have metal sides. The only places I've seen all-plastic Ethernet jacks are consumer networking gear and really ancient add-on cards. That makes me wonder if their source actually knows what he's talking about, especially given the lack of technical details about how this works.
- maxden 8y agoThis seems different than the extra chip attack according to the article. "subsequent physical inspection revealed an implant built into the server’s Ethernet connector"
- close04 8y agoThis feels like piling some more to cover up the weak premise of the previous article. It doesn't mean it's false, it just means Bloomberg already cried wolf and couldn't show it. At this point it feels more like taking shots at Supermicro than professional reporting.
- late2part 8y agototally seems like this is the case to me.
- simias 8y agoThat's my take as well. They quote many "experts" and report many incidents but they seem hard pressed to come with details and pictures. I can believe that these attacks occur but are they really at the scale implied by these stories? Why can they only report hearsay instead of showcasing even a single backdoored motherboard found in the wild? Haven't these experts taken pictures? Can we see them? Can we have some details on the components used? This story is incredibly weird, nothing makes sense to me. I can't believe that Bloomberg would willingly report fake news. The fact that they decided to go with it even though Apple and others told them several time using unambiguous language that they were not aware of such an attack means that they must have really trusted their sources since they're effectively saying "Apple is blatantly lying about such a critical issue". But then why would Apple be lying like that? Seems like it can only backfire for them when the truth is eventually exposed. Nothing makes sense.
- djrogers 8y agoWhat context are you using the word ‘pin’ here? I’m having some trouble follow your comment as ‘pin’ doenst line up with anything I’d contextually assume you to be referring to.