By: David Hess (, October 4, 2018 12:38 pm
Maynard Handley ( on October 4, 2018 12:08 pm wrote:
> No-one is denying that the PRC engages in cyber-espionage (just like Russia, just like the US).
> What is being denied is the precise details of the Bloomberg story, that a physical device (a
> "chip") of certain character was placed on multiple boards with the capability of doing certain
> things. THAT is the part that looks like "stupid people trying to write technolingo".
> There are too many details that seem to make no sense --- for example this device
> is tiny, right, "grain of rice". So how do data and power get to it? Microbumps? But
> then where exactly does it sit, because microbumps are going to require something
> bizarre like peeling the ceramic off the CPU. And that's not going to stand out?

Chip scale packages have become ubiquitous. I have no difficulty imagining a tiny BGA or similar being missed and did not take the photographs and descriptions in the article literally. I doubt the returned boards were initially checked for that level or correctness anyway.

This attack has been discussed in trade articles for at least a decade along with firmware and mask based attacks. I am surprised it took so long but some incident has to be the first widely publicized one.

> "This happened at a crucial moment, as small bits of the operating system were being stored
> in the board’s temporary memory en route to the server’s central processor, the CPU."
> So what, it's sitting on the traces between the DRAMs and the CPU? And what? Injecting
> enough current into those traces to rewrite the signal? Using what power?
> Or
> "The illicit chips could do all this because they were connected to the baseboard management controller"
> So what is it? Where exactly WERE they connected? To the CPU? the DRAM? the BMC?

I wondered about this also but the obvious place to insert it is the QSPI interface between the south bridge and memory containing the motherboard firmware or perhaps the eSPI interface which replaced LPC. So the malicious chip patches the motherboard firmware but any other firmware interface could also work. Once the SMM (System Management Mode) code is compromised, the attacker wins.

Incidentally, this technique of firmware patching goes back decades. Some of the first programmable logic was used to patch mask programmed ROMs. Look up the Signetics 82S107 if you are interested.
