5 ms·
> Alarmed by the devices’ sophistication, officials opted to warn a small number of potential targets in briefings that identified Supermicro by name. Executive
by jstrong 6y ago
> Alarmed by the devices’ sophistication, officials opted to warn a small number of potential targets in briefings that identified Supermicro by name. Executives from 10 companies and one large municipal utility told Bloomberg News that they’d received such warnings.
in my book that counts as "concrete proof."
- deftnerd 6y agoOnly if you believe that the warnings went out because of the "alarm over the devices' sophistication" and not "alarm over the idea this could happen" or even "alarm over a misidentification of a legitimate component and now we're too embarrassed to issue a retraction to those 10 CEOs"
- koheripbal 6y agoOk, but now you're making another argument with also zero evidence. I think it's fair to say there are multiple circumstantial pieces of evidence that SuperMicro is inserting security vulnerabilities. That should be enough to take the same decision that both the US gov't and Apple and others have made to avoid that manufacturer.
- michaelt 6y agoThe article certainly quotes a wealth of sources - but all of them seem to be vague, third-hand stuff. An unnamed "adviser" to security firms that analyzed Supermicro equipment. An executive for some unnamed company, who received a briefing. A venture capitalist who received a briefing. A retired FBI agent who was told there was an "additional little component" by someone he can't name. Some former FBI officials that refuse to name supermicro, and say only that supply chain attacks are possible. Fifty interviews with officials, all of whom asked not to be named. So apparently this information is so public that everyone and their dog is happy confirm it - yet at the same time, so classified that the victims and the 50 sources can't be named? That's pretty vague compared reports of hardware implants like credit card skimmers [1] which put pictures of the hardware front and centre and make it clear that the author has personally seen it and knows (basically) how it works. [1] https://krebsonsecurity.com/all-about-skimmers/ https://krebsonsecurity.com/all-about-skimmers/
- deleted 6y ago[deleted]
- jstrong 6y agofirst, I don't understand how this quote squares with your overall description -- it's specific, first-hand, from a named source, who should (on its face) know what he is talking about: > “This was espionage on the board itself,” said Mukul Kumar, who said he received one such warning during an unclassified briefing in 2015 when he was the chief security officer for Altera Corp., a chip designer in San Jose. “There was a chip on the board that was not supposed to be there that was calling home—not to Supermicro but to China.” second, the article presents a plausible scenario for why it would be difficult to get additional details: the U.S. govt's strategy for dealing with this was to let it play out, so they could learn more about the nature of the threat. any public disclosures about this are at odds with the strategy of the U.S. government in combating it. it seems like a very realistic scenario to me that some of the details of what happened became "lost in translation" - but that there is a real underlying truth. the first article wasn't convincing to me, but this one is very difficult to dismiss.
- michaelt 6y ago> first, I don't understand how this quote squares with your overall description A person who "received a warning in an unclassified briefing" isn't first-hand. At best it's second-hand, if whoever analysed the hardware implant was going out giving briefings in person. More likely it's third-hand. > it seems like a very realistic scenario to me that some of the details of what happened became "lost in translation" If the claim was an evil driver update, or a backdoored BIOS, that would be completely believable. Indeed, most of the details of this attack could just be a miscommunication about a BIOS backdoor - supply chain attack, malicious, code that shouldn't have been there, stored in an eeprom on the motherboard, undetectable by visual inspection. But the much more astonishing claim of a malicious hardware implant between layers of a PCB? Something that surprising needs the testimony of an electronics expert, not a cop or a C-suite officer. Especially after the purported victims from the first article denied knowing anything about it.