Supply chains and trust

By: Kevin G (, October 4, 2018 12:47 pm
Room: Moderated Discussions
David Kanter ( on October 4, 2018 8:23 am wrote:
> Bloomberg released a fantastic report on Chinese intelligence inserting malicious
> HW into supply chains for servers:
> It sure gives a different angle to the move to a hardware root-of-trust by the industry. In reality though,
> I'm not sure if HW RoT is sufficient. You can always sniff capacitance across an exposed wire!
> David

A couple of notes from my read through of the article:

SuperMicro's engineers themselves are not taking part in this. Only the manufacturing wing seems to be compromised. This will certainly have ramifications within the company.

The server compromise with Apple seems to have happened based upon luck rather than explicit targeting. However, Apple's cloak of secrecy seemingly prevented the reverse engineering of these chips when they were discovered. Also Apple has a robust enough internal security team to actually catch this kind of compromise which is something that could easily be overlooked.

The pictured chip only has six pins which my novice guess would some sort of SPI module. This would explain how they were able to interface with various other components on motherboards and sneak the chip into so many designs: often the traces for SPI ports remain after debugging is complete but the headers are no populated once a board reaches production. What stands out here is that it seemingly communicated with system management as a means of by passing OS level restrictions. This also has me wondering if this some how ties into various Intel AMT/Management Engine exploits that were made public a bit over a year ago. Or this could be something new as well.

The line about embedding some of these chips into the layers of the motherboard seems a bit improbable. It would only make sense if the existing manufacturing lines supported this but my impression of the market is that such manufacturing is only used in mobile applications where space is at a very high premium. Various network and server hardware doesn't use that level of board level integration to my knowledge (though I will admit if it is used, slipping in a chip between PCB layers is indeed a very clever means of hiding a chip). The intent here doesn't seem to be aimed at mobile either as it is very arbitrary who would get a particular phone and there are fewer interfaces to leverage against mobile hardware. With phones coming from so many suppliers outside of Chinese influence, it doesn't seem that it'd be useful as a wide spread attack vector (ie shutting down mobile infrastructure).

< Previous Post in ThreadNext Post in Thread >
TopicPosted ByDate
Supply chains and trustDavid Kanter2018/10/04 07:23 AM
  Supply chains and trustMaynard Handley2018/10/04 08:57 AM
    Supply chains and trustMaynard Handley2018/10/04 09:01 AM
      Supply chains and trustwumpus2018/10/04 03:35 PM
      Supply chains and trustRobert Williams2018/10/08 05:30 PM
        Supply chains and trustMaynard Handley2018/10/08 06:21 PM
          Supply chains and trustRobert Williams2018/10/09 08:03 AM
            Supply chains and trustRobert Williams2018/10/09 08:08 AM
              Supply chains and trustMaynard Handley2018/10/09 08:27 AM
    Supply chains and trustdmcq2018/10/04 09:31 AM
      Supply chains and trustGabriele Svelto2018/10/04 10:32 AM
        Supply chains and trustBrett2018/10/04 10:52 AM
          Supply chains and trustMaynard Handley2018/10/04 11:08 AM
            Supply chains and trustAdrian2018/10/04 11:36 AM
              Supply chains and trustMaynard Handley2018/10/04 11:51 AM
              Supply chains and trustRob Thorpe2018/10/04 12:09 PM
            Supply chains and trustDavid Hess2018/10/04 11:38 AM
            Supply chains and trustBrett2018/10/04 11:52 AM
          Supply chains and trustDoug S2018/10/04 12:33 PM
        Supply chains and trustDavid Hess2018/10/04 11:09 AM
      Supply chains and trustDavid Hess2018/10/04 11:03 AM
    Supply chains and trustDoug S2018/10/04 12:45 PM
      Supply chains and trustGabriele Svelto2018/10/05 12:53 AM
        Supply chains and trustdmcq2018/10/05 02:51 AM
          Supply chains and trustGabriele Svelto2018/10/05 03:34 AM
        Supply chains and trustDoug S2018/10/05 11:46 AM
          Supply chains and trustGabriele Svelto2018/10/06 01:59 PM
            Supply chains and trustDavid Hess2018/10/06 03:12 PM
    Supply chains and trustJ2018/10/04 09:24 PM
      Supply chains and trustAndrew Clough2018/10/05 05:38 AM
        Supply chains and trustDavid Hess2018/10/06 03:16 PM
        Supply chains and trustMaxwell2018/10/06 03:37 PM
    Hit job on Super Micro?Maxwell2018/10/04 09:46 PM
      Hit job on Super Micro?Brett2018/10/04 11:55 PM
        Hit job on Super Micro?David Hess2018/10/06 03:15 PM
  Supply chains and trustKevin G2018/10/04 12:47 PM
    Raptor Engineering's RaptorGabriele Svelto2018/10/05 03:42 AM
    Supply chains and trustGroo2018/10/06 05:49 AM
      Supply chains and trustDavid Kanter2018/10/06 08:04 AM
        Supply chains and trustGroo2018/10/06 02:42 PM
          Supply chains and trustDavid Kanter2018/10/06 02:46 PM
            SuperMicro boards are not made in USAAdrian2018/10/06 11:08 PM
              SuperMicro boards are not made in USAAdrian2018/10/06 11:28 PM
          Supply chains and trustjuanrga2018/10/07 06:12 AM
        Supply chains and trustDavid Hess2018/10/06 03:24 PM
      Supply chains and trustWes Felter2018/10/07 02:35 PM
  What did the BOM entry look like?Mark Roulo2018/10/04 01:21 PM
  Supply chains and trustMaynard Handley2018/10/04 03:01 PM
    Supply chains and trustdmcq2018/10/05 12:27 AM
      Here's what I think happenedDoug S2018/10/05 11:56 AM
        Here's what I think happenedBrett2018/10/05 03:17 PM
          FBI wants to be your first contactex-apple2018/10/05 03:41 PM
          Here's what I think happenedDoug S2018/10/05 09:59 PM
            Why call CIA?David Kanter2018/10/06 08:01 AM
              Why call CIA?Doug S2018/10/06 08:33 AM
                Why call CIA?David Kanter2018/10/06 02:43 PM
        Here's what I think happenedMaynard Handley2018/10/05 03:23 PM
          Here's what I think happeneddmcq2018/10/06 03:52 AM
    Supply chains and trustDavid Hess2018/10/06 03:34 PM
  Supply chains and trustGroo2018/10/06 06:01 AM
    Supply chains and trustetudiant2018/10/07 03:36 AM
Reply to this Topic
Body: No Text
How do you spell avocado?