Supermicro server motherboards with hardware backdoor?

Oct 04, 2018 108 Replies

On Saturday, October 6, 2018 at 11:38:32 AM UTC-4, snipped-for-privacy@nospam.org w rote:

to have

Add a series resistor to the other source and it's a

Big caps??? The clock line is high for half a bit time on every bit. Why do you need "big" caps? I expect the small capacitance needed could have b een included in the one device.

They may not use a resistor, they may not vampire power from the data lines . We don't know much about how the device worked. I was suggesting what c ould be possible.

I don't see the resistor being a problem really. If you modify the layout and the automated optical inspection configuration, it is very unlikely any one would spot your changes unless they compare the design to the original design files which is, I believe, how the hack was discovered. Had the mod been between the board layers and top/bottom layer Gerbers where not chang ed, this likely would not have been discovered - at least not at Elemental. I think they said Apple discovered the hack by detecting aberrant network traffic which is what some here have suggested should have been noticed.

Rick C.

use

I would expect anyone to back up their data before an update because we kno w they can go south. A friend did an update earlier this year and his whol e machine was bricked because it was one with less memory. I don't know if MS eventually acknowledged the problem, but he wasn't the only one to end up with an unbootable machine.

Still, considering that by default I believe Win 10 does updates automatica lly, you would think these types of problems would be a bigger issue for MS than it seems to be.

I think that is a bit much... but then I may be very surprised at some poin t. I read "The Puzzle Palace" only to find the cable companies cooperated with the security agencies to feed them cables before they were sent. I wo uld not have expected that either.

LOL! Good one. :)

I wish I had you running my IT department... instead of me.

Rick C.

It would have been very difficult to design in. There are many design revi ews where the entire team (hardware and software) has a chance to critique the design. A chip like this could be spotted possibly. Then not only is the jig up with the board, but with your implanted agent and the finger can easily be pointed back to YOU (the country responsible). This was discuss ed in the article.

Adding it in manufacturing was done with the aid of the factory IN CHINA! See the connection? But they had plausible deniability since there was no one to attest the claim. I am sure the info they got on bribes and threats was off the record so there is no real proof to publicly embarrass China. It was not discovered at the factory. It was discovered in the field by a security review and also independently by noticing aberrant network traffi c.

As the article said, they will be embedding chips between layers (or alread y have) in other exploits.

I recall working at a DoD company where they talked about the possibility o f buying chips which had been altered in manufacturing to spy on government systems. I found it hard to believe this could be possible at the time, b ut I suppose if you are manufacturing them, it wouldn't take much in the wa y of changes to add a back door. Heck, often chips have back doors anyway only for users to discover them after the chips are in the field. A spy on ly needs to discover them before it is public knowledge.

Rick C.

the

r

onal

e.

lash

be

f

types

CPLDs

256

ze

I think they've been around because they are fundamentally different from a dding chips. In the late 70s or early 80s an array processor I worked on u sed a 16 or 18 layer board with an "omega" layer for termination resistors in ECL. That was basically painted on the fiberglass between layers. I ex pect capacitors would not have been so easy since they require much more he ight. Do they add capacitors between layers now?

Not saying it can't be done, just asking if it commonly available.

Rick C.

Lol! A few months ago I bought a couple of eBay machines, one for personal use and one for work. Both have Win 10 and I am presently happier with th at then any prior Windows. They really added some useful features rather t han trying to tell us what we should want. That said, one of the machines won't run very long if used much after booting. I am not able to update it because of blue screen crashes. I've spent a few hours trying to fix it, but no joy. So I'm buying another, even cheaper, eBay machine to continue working with and will be putting Linux on the broken one. I bet it works j ust fine.

The only program I'm worried about running on Linux is a Forth program, Win

32Forth. If it runs under Wine, I'll be happy (Wine is for running Windows programs under Linux, not the other way 'round, right?) If not I'll have to port my code to Gforth which will require a few mods to OS interfaces fo r RS-232 ports, Telnet and accessing the paste buffer. My program puts dat a into the paste buffer for the user to drop into a spread sheet. That act ually saves a lot of time in testing and would be very bad to have to give up.

Rick C.

Well, ok. If you need a detailed procedure on how to assign the blame, I can provide one.

  1. The first step is to deny that there's a problem. If the problem goes away, you win, and can stop right here. If not, precede to the next step.
  2. The next step is to misidentify the problem in a manner that deflects the blame from the obvious culprit and delivers it to your worst enemy. For example, if Microsoft delivers a self destructive Windoze update, it must be President Trump's fault.
  3. When blaming your worst enemy no longer draws the necessary attention, the next step is to blame the innocent. The could mean a former employee, another department, the janitor, or anyone who is incapable of properly defending themselves.
  4. Blaming the innocent will inevitably fail, but should give you time for the next step, which is appoint a committee of luminaries, experts, academics, and con artists who will approach the problem from as many directions as there are members, and reach an equal number of conclusions. Extra credit for also providing an equal number of useless solutions to the problem.
  5. When the committee inevitably fails, a very expensive consultant will be hired to properly assign the blame. Of course he will be hired by the obvious culprit who cannot be blamed or the consultant might not get paid.
  6. The absence of a suitable culprit is not a sufficient reason to bypass the punishment phase of the process. No progress can be made unless someone has been punished for allowing things to gone wrong. Generally, it will be someone already scheduled for early retirement, or perhaps someone who is disliked by management. Once out of the way, this person can also be blamed for a variety of other things that have gone wrong. Don't worry, they won't talk because they are collecting their golden parachute retirement pay off.

I forgot to mention if someone accidentally finds the initiative to make a proper backup, the backup media will soon disappear to insure that the backup thief gets credit for finding the all important backups after a frantic search.

I hope this help you understand the process should anyone actually trust you do solve a computer problem.

(Hint: File by file incremental backups suck and are a giant time burn. Backing up only user data is worse. The only backup that really works for me are image backups and rsync type backups).

Jeff Liebermann jeffl@cruzio.com 150 Felker St #D http://www.LearnByDestroying.com Santa Cruz CA 95060 http://802.11junk.com Skype: JeffLiebermann AE6KS 831-336-2558

Succinctly put! :-)

The last of Microsoft's customers who could still regard themselves as "Users" were running win2kSP4. After that with winXP, Microsoft's customers were on the downhill slope to becoming hostages. It started gently at first becoming a cliff like plummet into the depths of what Microsoft rather ironically named "Vista", after which it somehow just kept going from bad to worse.

Johnny B Good

I recall when XP first came out it was widely hated. But it didn't take lo ng for users to warm up to it and eventually really like it. So much so th at when Vista showed up with only two crimes committed (requiring new drive rs for everything which meant many devices which were not currently in prod uction would never work again and be default turning on various security pr otections which users thought were new features rather than existing featur es now turned on and could be turned off) it was widely hated from the get- go. This hatred was so widespread that MS saw and opportunity to make even more money from users who didn't *want* Vista by charging even more money to buy Vista along with the right to uninstall it and revert to XP. But I used Vista on a laptop for four years and was relatively happy with it.

By the time Win 8 came along I think users were in the habit of hating anyt hing new from MS, which was not at all reduced by the extremely goofy resid ual functionality of trying to make it compatible with touchscreen devices like tablets which it didn't have much opportunity to appear on with Androi d running on 99 of 100 mobile devices that didn't run iOS. I actually know a friend who had a Windows phone which she only had to give up this past y ear when MS dropped all support.

So this brings us up to Win 9 ^H^H 10 which did not repeat any of the previ ous grievous errors... and as far as I can see didn't create any new ones e ither. Yeah, it's still Windows, but I don't go to sleep every night cursi ng MS like I used to. Yeah, I'm planning to dessert and join the Linux cam p and I might actually do it this time. I have a whole spare machine that either has an unfixable (by me) Windows update error or a hardware fault. At least installing Linux will tell me which one it is.

Lots of fun ahead. :D

Rick C.

That lot is also true for political problems, e.g. nomination processes.

gnuarm wrote

So you are suggesting they are using the existing clock?

formatting link

For that 'thing' to actually send data it must set clock high and then low again, you cannot pull yourself up by the hairs. You cannot have a circuit powered from a positive supply generated by its own output FYI. Something to do with conserva/// or perpet...

OK, if you can modify the board (= circuit) the all bets are off.

I would think, as a spy-master why not just monitor the databits and send on some Gigle-Hertz to a nearby listening device (car, whatever) has been done to tap consulates with transmitters powered from microwave beams.. However on a board like this plenty of power available if you can route it. When sci.crypt was more fun there were references to listening systems that used the RFI from computers to decode decrypted stuff, to view what was on the screen (passwords) etc etc, just recently I did read an other paper on that.

Of course it is fun to be able to just query the data via some IP address, or have it send to the mother-land at given times on some IP address, but then you do not wan the SPI bus, but more likely have modified firmware in one of the processor interface chips, east-brdge . west bridge what was it, processor updates ;-). I think that is also what US is doing. I see my top secret invasion plans with 'snort' leaving the system all the time... Many many years ago somebody got really pissed in sci.crypt when I pointed that out... stepped on some tones I suppose.

Anyways there a zillion ways to get at the data, and every big country is having a go at it (maybe small ones too). It is a fun hobby, if war arrives I'd be glad to play.

mm Apple, Steve Jobs tried selling his old stuff by saying the Macs were as powerful as what was used by the new-nuke-testing facilities in the US. People buy that crap.

I seriously wonder if the story was true Apple's competence (was it an Apple board?) in controlling its own manufacturing. it is more in the spirit of "let's move it all to the US and charge even more for the crap". I have clicked my fingers to de-hypnotize those Apple buyers, but I need help, it is stuck so deep in their brain, lemme put it this way: DON'T YOU SEE APPLE IS DANGEROUS (click).

.

hehe

snipped-for-privacy@gmail.com wrote in news: snipped-for-privacy@googlegroups.com:

Any person acting as an IT administrator for any client should always (and this is well known) turn off automatic updates and set all such activity to manual. This includes and is assuredly possible with Windows 10 as well.

You all have to be stupid to listen to the trash talk and believe the bullshit. The fact is that the OLD windows OSes are no longer robust (if they ever were) (wow one had serial port hooks)and are certainly vulnerable. Whereas Windows 10 is keeping up with the hacker Joneses. Find the stats on machines rendered unuseable via a hack that wants you to pay to get your machine back. The number of previous OSes is far higher than those of Windows 10 and those machines are ALWAYS a machine that was not updated to abate any attacks. If you are on the net, you need Linux or fully updated Windows 10. And no, it is not passing your info on. That is what the vulnerable systems allow. Duh.

Jeff Liebermann wrote in news: snipped-for-privacy@4ax.com:

You are worse than a troll. You actually believe that bullshit you spewed. Man, the truth must have had some hellish sting to it for you to get so angry over it.

I understand computer science, so getting your thumbs up on my capabilities is hardly my goal. You do not see me blaming the scientists. Especially not those whom have been doing it decades longer than you have.

On Sunday, October 7, 2018 at 3:15:59 AM UTC-4, snipped-for-privacy@nospam.org wrot e:

org

r.

hy do

een

w again,

own output FYI.

Not sure what you are talking about. This circuit doesn't need to drive th e clock line does it? Regardless, there are multiple signal lines. They d on't need to be high all the time, just enough to power the circuit.

nes.

could

ut and

ne

How else could the chip have been inserted into the design???

on some Gigle-Hertz to a nearby listening device (car, whatever)

beams..

How would they know where the board ended up? Even if you sit and wait for a board to show up where you want to spy, anything that emanates RF is sub ject to two problems, 1) being detected in a sweep and B) being shielded si nce most installations try to prevent RFI.

t.

at used the RFI from computers

etc, just recently I did read an other paper on that.

When I was still getting my ears wet in electronics the US Government had a dopted TEMPEST requirements to prevent emanation of RF that could be used t o snoop computers. They were big, heavy, metal encased and had screened CR Ts as well as keyboards. Expensive, yes, but subject to snooping, no.

, or have it send to the mother-land at given times

e . west bridge what was it, processor updates ;-).

I don't think you really read the article.

e time...

d that out... stepped on some tones I suppose.

Your code is too cryptic for me to understand what you are saying.

having a go at it (maybe small ones too).

esign

nged,

rk

as powerful as what was used by the new-nuke-testing facilities in the US.

ple board?) in controlling its own manufacturing.

more for the crap".

help,

I didn't see that manufacturing was all moved to the US. I think they just moved it out of China.

Interesting that they started that way, in countries other than China and g radually moved into China. Taiwan was one of the earlier countries and lik ely to end up as one of the new ones.

Rick C.

"Assuredly"??? So you don't know! I seem to recall I've tried to tell Win dows to download updates, but let me say when to install them. I think las t time it nagged me a lot and let me put it off for some period of time, bu t there was no option to tell it to stopp with the nagging and finally when I wasn't on the computer frequently enough to say no *in time* it went ahe ad and did the update.

If you know another setting to wait for me to give Windows 10 permission ra ther than repeatedly having to deny it's requests I'd like to know about it .

They are talking about the info Windows 10 sends back to the mother ship. It is claimed this is only anonymous info to improve the system, but many d oubt MS. Who can blame them?

Rick C.

Ah, my favorite topic... me.

Please keep things simple. I am a troll. I like to write provocative and inflammatory drivel and poetry. Oddly, you're the only person who seems to be provoked or inflamed.

Well yes, I wrote it, therefore it's a fair assumption that I believe what I write. I only have one requirement. Whatever I write must be worth reading. With the exception of this message, I suspect that I've done rather well.

Hardly. If I write something, by definition it is my truth. Whether you believe my truths is optional. I don't pretend to have any effect on your version of the truth. I simply add some entertainment value while trying to understand how you think. It's much like shooting neutrons into a fissionable atom, hoping to hit the tiny nucleus, and then take inventory of what comes flying out. Judging by the debris trail behind your logic, that could become a major project and possibly the topic of a research report.

I am not a computah scientist. I perform damage control on the mistakes of computah scientists. I don't blame them for anything because I'm profiting from their mistakes. I much prefer to blame government agencies, large corporations, and industry organizations.

Doing what? I've been fixing computahs to support my decadent and lavish lifestyle since 1983. That's 3.5 decades experience saving customers from the end products of computer science. Longer if you include my computah hobby phase. What is "it" that you have been doing?

Jeff Liebermann jeffl@cruzio.com 150 Felker St #D http://www.LearnByDestroying.com Santa Cruz CA 95060 http://802.11junk.com Skype: JeffLiebermann AE6KS 831-336-2558

Jeff Liebermann wrote in news: snipped-for-privacy@4ax.com:

Yer an idiot, at best. Reputah Le Buta... I'd kick you right in the knee, green teeth.

Jeff Liebermann wrote in news: snipped-for-privacy@4ax.com:

You are so utterly full of s*it, child.

snipped-for-privacy@gmail.com wrote in news:69a8a5d9-3d5d-4c9f-8bfb- snipped-for-privacy@googlegroups.com:

I see that you have problems with word definitions too. Not a surprise.

snipped-for-privacy@gmail.com wrote in news: snipped-for-privacy@googlegroups.com:

It is like this. You are an abject idiot not only for not updating but for ignoring the prompt to do so.

My machine is up to date, so I see no such notifications.

And do you really need to cry and piss and moan about notifications anyway?

You are a trip. Never a dull moment, but also never to be given credence.

Rick C.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required