Bloomberg: China broke into US companies by adding chip on server motherboards

Discussion in 'Frontpage news' started by Hilbert Hagedoorn, Oct 4, 2018.

  1. Hilbert Hagedoorn

    Hilbert Hagedoorn Don Vito Corleone Staff Member

    Messages:
    48,544
    Likes Received:
    18,856
    GPU:
    AMD | NVIDIA
    rl66 likes this.
  2. Typhoon2097

    Typhoon2097 Guest

    Messages:
    9
    Likes Received:
    5
    GPU:
    nV GTX1080Ti
    Riiiiight... It's not the russians this time, now it's the chinese again... And coincidentally this is published in the middle of US-China trade war :D
     
  3. poornaprakash

    poornaprakash Active Member

    Messages:
    94
    Likes Received:
    18
    GPU:
    AMD/Nvidia
    If we see things as a whole China now exactly behaving like the old US were. Karma retaliation :p
     
  4. Brasky

    Brasky Ancient Guru

    Messages:
    2,610
    Likes Received:
    648
    GPU:
    Gigabyte 4070 Ti Su
    5$ says typhoon is a bot. any takers?
     
    airbud7 and KissSh0t like this.

  5. msotirov

    msotirov Guest

    Messages:
    54
    Likes Received:
    28
    GPU:
    rx 480
    The same way your Intel or AMD CPU works without drivers. The driver is embedded in the chip itself and is called "firmware".

    By the way, you realize that Intel ME is essentially the same thing like this new supposedly Chinese spy chip. Intel ME has it's own mini-OS running separate from everything else on your PC, complete with network access to top it off.
     
    carnivore and tunejunky like this.
  6. Typhoon2097

    Typhoon2097 Guest

    Messages:
    9
    Likes Received:
    5
    GPU:
    nV GTX1080Ti
    I'll take that 5 bucks anytime ;)
     
    fantaskarsef, Noisiv and gx-x like this.
  7. Valken

    Valken Ancient Guru

    Messages:
    2,924
    Likes Received:
    901
    GPU:
    Forsa 1060 3GB Temp GPU
    oh noes... them pesky Russians, err... Chinese are SPYING AGAIN!!!

    "The stories get weird here; Apple and Amazon are denying any existence of the chip. "Apple has never found malicious chips, hardware manipulations or vulnerabilities that have been deliberately placed on a server, Apple has never had contact with the FBI or any other service about such an incident," Apple says it has 2000 servers from Supermicro, but denies that it has found the chips. Amazon says in its denial that it found four problems with the purchase of Elemental, a takeover that took place in 2015. None of those were in the hardware."

    But of course, you can't believe any of those Commie Tech companies like Apple or Amazon... Still waiting for Trump to drain that swamp...
     
    tunejunky and gx-x like this.
  8. gx-x

    gx-x Ancient Guru

    Messages:
    1,530
    Likes Received:
    158
    GPU:
    1070Ti Phoenix
    Bloomberg is fake news.
     
    rl66 and Noisiv like this.
  9. vbetts

    vbetts Don Vincenzo Staff Member

    Messages:
    15,140
    Likes Received:
    1,743
    GPU:
    GTX 1080 Ti
    I just want to say something real quick, let's not make this into a political debate. I already got enough of that going around with all the freaking political ads everywhere!
     
  10. schmidtbag

    schmidtbag Ancient Guru

    Messages:
    8,020
    Likes Received:
    4,398
    GPU:
    Asrock 7700XT
    As an American, I can't say US-based companies are a whole lot more trustworthy than Chinese or Russian. But... I also don't really care if a government (domestic or foreign) is spying on me, so despite this news, I'll still gladly buy Chinese (or American) parts. All I care about is price and performance.
    I was also thinking of just simply removing the chip. Or, take a screwdriver and a hammer and just give it a little tap to crush it. Surely, the chip is not crucial to the functionality of the board, so might as well ignore it.
    As for the driver thing, there are plenty of hardware features that work without drivers. Drivers are nothing more than just basic code that allows the OS to have control/access over hardware. There is nothing preventing hardware from performing logic functions without the OS being aware of it. Take keyloggers for example, or the potential malware that takes advantage of Spectre and Meltdown.
    That being said, I wouldn't be surprised if the chip sits somewhere between the storage controller, the chipset, and the NIC. It probably just listens in on the data and encodes it to be sent over the NIC. I'm sure it's completely isolated and undetectable by the rest of the system.
     

  11. Denial

    Denial Ancient Guru

    Messages:
    14,207
    Likes Received:
    4,121
    GPU:
    EVGA RTX 3080
    It would get political because all the companies that Bloomberg said this happening to are outright denying the story. Typically if they want to keep shut they'll use boilerplate "No comment" but they are literally saying this didn't happen and it's entirely fabricated news story. Bloomberg itself posted a counter article summarizing it.

    https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-beijing-respond

    So what exactly is going on here? Seems extremely weird for them to deny it like this because any indication of a real attack would open them to a massive legal liability after a denial like that.
     
    fantaskarsef, Noisiv and tunejunky like this.
  12. tunejunky

    tunejunky Ancient Guru

    Messages:
    4,460
    Likes Received:
    3,085
    GPU:
    7900xtx/7900xt
    and i thought I was cynical...lol

    anyhow, Denial is on point about the liability issues.

    Amazon Cloud Services and Apple Cloud...
    that's a lot of liability right there without bringing in government contracts.

    SuperMicro, wow, i had such a high opinion of them.

    one of the reasons (other than cheap labor and a huge market) tech companies produce in China is political stability. this is a gut punch to every American tech company with eyes on the fat wallets of the Pentagon.
     
  13. nhlkoho

    nhlkoho Guest

    Messages:
    7,754
    Likes Received:
    366
    GPU:
    RTX 2080ti FE
    There isn't exactly any penalty to publicly lie about stories like this anymore. I can't even count how many times a story came out in the past year (politically motivated or not) that was denied and then turned out to be true in the end.
     
    fantaskarsef and tunejunky like this.
  14. Denial

    Denial Ancient Guru

    Messages:
    14,207
    Likes Received:
    4,121
    GPU:
    EVGA RTX 3080
    You're right and it's definitely getting significantly more difficult to judge the accuracy of stories due to the increasing level of dishonesty across the board. Is Bloomberg outright fabricating this story? Are the six current/former white house officials lying? Are the companies lying that this didn't happen? I don't know - which is why I find this story so strange. Bloomberg is a fairly trusted news publication, it's rated typically as center/left center - most of the "conspiracy this is fake news" posts I see about this story are implying that it's a White House hit job on China designed to "promote" the ongoing trade dispute, in fact someone mentioned that here. I don't know why a slightly left leaning site (at worst) would fabricate or agree to fabricate a story about this. I'm also positive that if they didn't fabricate the story, they did some due diligence and vetted the sources - there is six of them from the white house and several "apple insiders" they are using as sources. That's like a fair number of sources - which would lead me to believe that there is some level of truth to the story. But even the company's responses are outright puzzling to me. In terms of PR you almost never outright deny a story like this - whether the story is true or false - it's just not worth the legal risk. Yet, despite the ongoing facebook saga, complete with multi-billion dollar fines due to them covering their hack up, all of these companies choose to outright deny this story.

    I'm not really taking a side or saying who is lying or not but it's just extremely weird to me. None of the "conspiracyesque" narratives I've seen thus far really fit what's going on here.
     
  15. Fox2232

    Fox2232 Guest

    Messages:
    11,808
    Likes Received:
    3,371
    GPU:
    6900XT+AW@240Hz
    Bloomberg being hacked with fake article? Or is that real article?
    In-Q-tel? Good name for company... intel "Q"estion/ery/...

    Secondly, I really want to see real photo of those microchips and to what components they were connected.
    There are very few specific places where some chip can affect anything.

    No way to affect code being executed in CPU, that's simply not possible as chip would have to intercept, analyze and change data going from memory/storage in real time.
    (crazy computational capacity required, a lot of traces overriden, And a lot of hacking-chip-on-board-storage required to actually have reference on what to intercept.)

    Maybe possible to send fake read and writes to storage controller, but again very complicated for anything this small without a lot of onboard memory and traces.

    Most feasible way would be this having access to BIOS chip, simply parsing and altering/inserting modules. So basically rootkit deploy chip.
    - reason here would be to survive BIOS update

    But then following description is way too incorrect:
    "⑤ When a server was installed and switched on, the microchip altered the operating system’s core so it could accept modifications. The chip could also contact computers controlled by the attackers in search of further instructions and code."

    = = = =
    And then there is that F*ing Big Important thing:
    IIRC, US made some legislation changes which classify foreign cyber-attack as Act of War. I have no clue if it went through and under which conditions it should have apply. US guys will probably know.
     
    Last edited: Oct 4, 2018

  16. HeavyHemi

    HeavyHemi Guest

    Messages:
    6,952
    Likes Received:
    960
    GPU:
    GTX1080Ti
    All that is missing is one PHYSICAL example of this. I find it impossible to believe that these are installed all over the planet yet nobody can find one? That not one single person in years has come forward and said 'hey look at this'. This story fails my basic sniff test for that basic reason.
     
  17. Denial

    Denial Ancient Guru

    Messages:
    14,207
    Likes Received:
    4,121
    GPU:
    EVGA RTX 3080
    Yeah I agree but then why is there a concerted effort by seven different people ranging from different backgrounds both politically and private/public trying to say this happened? Or, why is Bloomberg so hellbent on fabricating a story like this when it was obviously going to be outright denied by the companies and obvious lack of evidence? The whole thing just seems so strange to me.
     
  18. Broke-back served
     
  19. Koniakki

    Koniakki Guest

    Messages:
    2,843
    Likes Received:
    452
    GPU:
    ZOTAC GTX 1080Ti FE
    Care to share any links? Honestly I would loved to see some! I thought you meant PNY at first but afaik they don't make motherboards anymore.
     
  20. Size_Mick

    Size_Mick Master Guru

    Messages:
    630
    Likes Received:
    463
    GPU:
    Asus GTX 1070 8GB
    What's really sad is that SuperMicro used to be the only company who made their boards in the USA.
     

Share This Page