02-27-2019, 03:55 AM
https://www.tomshardware.com/news/superm...38697.html
Quote:Last year, Bloomberg ran a report, saying Supermicro-supplied servers come with Chinese backdoors and that this may have been a reason for Apple to dropped them in 2016; although Apple denied espionage concerns at the time. Although new research publsihed today doesn’t exactly confirm Bloomberg’s report that Supermicro servers ship with pre-installed backdoors, it does point to the microcontrollers used by Supermicro and the firmware that comes with them being easily backdoored without detection.
Researchers from Eclypsium, a firm specializing in firmware security, were able to commission a bare-metal server from IBM, install a backdoor in one of its microcontrollers, and then allowed IBM to re-use the server for other customers. The researchers were later able to reclaim that same server and noted that the backdoor was still active on the server, which means IBM lacks proper reclamation process that can clean previously used bare-metal servers of accidental or intentional backdoors. Attackers could use the same process that the researchers used to brick or steal data from other IBM customers.
...
Over the past few years, more companies have come to realize that supply-chain security is just as important if not more important than applying software patches. Verifying that purchased hardware hasn’t been tampered with either from factory or somewhere in the supply chain should be an even bigger priority for cloud service providers who are responsible for the data protection of millions of customers.

