Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
JawnV6
Jul 4, 2004

So hot ...

Angela Merkle Tree posted:

the articles mention managers at the factories being pressured into altering the designs to add the chips. that seems a lot more complicated than subverting or altering another chip and ensuring that they make their way into the pick-and-place machine

yeah that's what's getting me. like this poo poo's hard enough to do with a real design team already, getting a PCB change for a finicky on-bus intercept that can still pass QA?

versus "yo, here's a sweet deal on bog standard flash components that definitely don't have a shady micro hiding in there no sir"

we couldn't prevent the second one with multiple in-person meetings with the vendor and CM present, the PLA leaning on GM's is just unnecessary

there's just much easier, cheaper, less short-rubber-hose pathways to getting this functionality

Adbot
ADBOT LOVES YOU

Loky11
Dec 12, 2006

Pull on the new flesh like borrowed gloves and burn your fingers once again
security conferences are basically digital state fairs of humanity.

apseudonym
Feb 25, 2011

Bulgakov posted:

shhhhhhh, keep quiet until the meetings we have inside the executive conference bathrooms :nono:

I thought our relationship was more than meetings :smith:

Pryor on Fire
May 14, 2013

they don't know all alien abduction experiences can be explained by people thinking saving private ryan was a documentary

Here's an article going around about how it would be implemented:

https://www.lightbluetouchpaper.org/2018/10/05/making-sense-of-the-supermicro-motherboard-attack/

basically flashing the BMC firmware with something it can pull off the internet, then then reading whatever it wants from memory

Potato Salad
Oct 23, 2014

nobody cares


If this is what it takes for us to get remotely passable hardware trust for code integrity for ilo/idrac to be developed and become standard next decade, so loving be it

BlankSystemDaemon
Mar 13, 2009




Potato Salad posted:

If this is what it takes for us to get remotely passable hardware trust for code integrity for ilo/idrac to be developed and become standard next decade, so loving be it
We first need a solution that actually works and which the vendors will implement, and I'm not aware of any.

evil_bunnY
Apr 2, 2003

Potato Salad posted:

If this is what it takes for us to get remotely passable hardware trust for code integrity for ilo/idrac to be developed and become standard next decade, so loving be it
/pwaise

Wiggly Wayne DDS
Sep 11, 2010



more about android usb attacks https://googleprojectzero.blogspot.com/2018/09/oatmeal-on-universal-cereal-bus.html

MrMoo
Sep 14, 2000

Nice work from Banksy, an actual video available now

https://www.instagram.com/p/BomXijJhArX/

Carbon dioxide
Oct 9, 2012

I just found a thing.

quote:

Rattlesnake Island is an 85 acre island resort in Lake Erie, located about a mile away from Put-In-Bay. With its own private airport and a marina that will accommodate the largest of yachts, there are a multitude of ways to arrive at Rattlesnake Island.

[...]
Rattlesnake Island Club (RIC) is an exclusive Private Resort dedicated to meeting the needs of its 65 equity Members. Because the Members own and operate the Club for their own benefit, no special request is too difficult to accommodate. An eclectic international staff is available for the season (end of May through the end of September) to accommodate every need. Rattlesnake Island is an oasis of privacy, relaxation, and fun in an otherwise chaotic world.

[...]

RIC is a place where fun loving people who have accomplished much in life can unwind and “let their hair down”. What happens at Rattlesnake Island, stays at Rattlesnake Island. We are, after all, A VERY Private Resort!

Yes. Very private. And also, its members login page at http://members.rattlesnakeislandclub.com/ is http-only.

I don't really know what to do with this information other than that I shouldn't touch the poop, but I thought to post it here.

flakeloaf
Feb 26, 2003

Still better than android clock

not good to touch poop from a place called putin bay

Shifty Pony
Dec 28, 2004

Up ta somethin'


MrMoo posted:

Nice work from Banksy, an actual video available now

https://www.instagram.com/p/BomXijJhArX/

pretty clearly performance art, and sloppily done at that since the "shredder" blades aren't even aligned in the right direction. auction house was almost certainly in on it as well as the work was hanging from the wall instead of in an easel and there's no way they don't go over something like that with a fine toothed comb to check for fakes.

amusing, but amusing in the same way as the "You didn't say the magic word!" screen in Jurassic Park.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shifty Pony posted:

pretty clearly performance art, and sloppily done at that since the "shredder" blades aren't even aligned in the right direction. auction house was almost certainly in on it as well as the work was hanging from the wall instead of in an easel and there's no way they don't go over something like that with a fine toothed comb to check for fakes.

amusing, but amusing in the same way as the "You didn't say the magic word!" screen in Jurassic Park.

Samuel L. ACKSYN
Feb 29, 2008


Stereotype posted:

that’s a stupid place to put a secret spy chip that clearly doesn’t fit the footprint at all. now I think this whole thing is stupid.

also what chip is missing from that and why is it still in their layout?

it looks like those pads are connected to the chip next to it, which i looks like it's this

"FLASH - NOR Memory IC 256Mb (32M x 8) SPI 104MHz 16-SOP"


presumably the footprint is for an alternate flash chip depending on board configuration...






or its the secret spot for the hacker chip

akadajet
Sep 14, 2003

MrMoo posted:

Nice work from Banksy, an actual video available now

https://www.instagram.com/p/BomXijJhArX/

all hail the king of cheap juxtaposition. very thought provoking

Raere
Dec 13, 2007

Details on those Russians trying to hack the wifi at OCPW
https://english.defensie.nl/topics/cyber-security/documents/publications/2018/10/04/gru-close-access-cyber-operation-against-opcw

One of the laptops they seized had photos and metadata from previous operations. Also google.ru searches for OCPW related things. And cellphones that were activated on the closest cell tower to the GRU barracks. A+ opsec

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

why are all memes looking like political cartoons these days

so many labels

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
I don't see DEBT anywhere in there, so it's not a political cartoon

Shifty Pony
Dec 28, 2004

Up ta somethin'


a little tweaking and it could be loss

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Carbon dioxide posted:

I just found a thing.


Yes. Very private. And also, its members login page at http://members.rattlesnakeislandclub.com/ is http-only.

I don't really know what to do with this information other than that I shouldn't touch the poop, but I thought to post it here.

you found a web site! tell us your secrets

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

akadajet posted:

all hail the king of cheap juxtaposition. very thought provoking

welcome to like 90% of art

half-assed inane commentary doesn’t become meaningful just because it takes 2000% longer to produce

Agile Vector
May 21, 2007

scrum bored



Subjunctive posted:

you found a web site! tell us your secrets

idk they found an island site that is almost awkwardly shouting that it is also a fuckcabal
while looking like a fan page for myst on free hosting

Agile Vector
May 21, 2007

scrum bored



A VERY private resort!

Trabisnikof
Dec 24, 2005

Krebs has a recent post with an interesting tidbit

quote:

More than a decade ago when I was a reporter with The Washington Post, I heard from an extremely well-placed source that one Chinese tech company had made it onto Uncle Sam’s entity list because they sold a custom hardware component for many Internet-enabled printers that secretly made a copy of every document or image sent to the printer and forwarded that to a server allegedly controlled by hackers aligned with the Chinese government.

https://krebsonsecurity.com/2018/10/supply-chain-security-is-the-whole-enchilada-but-whos-willing-to-pay-for-it/

he also seems to find the bloomberg piece credible

spankmeister
Jun 15, 2008






Raere posted:

Details on those Russians trying to hack the wifi at OCPW
https://english.defensie.nl/topics/cyber-security/documents/publications/2018/10/04/gru-close-access-cyber-operation-against-opcw

One of the laptops they seized had photos and metadata from previous operations. Also google.ru searches for OCPW related things. And cellphones that were activated on the closest cell tower to the GRU barracks. A+ opsec

Yeah I posted that already a couple of days ago.

I've been reading some of the comments on Dutch news sites and such and it's amazing how some people still think it's some kind of big conspiracy to make Russia look bad.

Putin's trolls and the idiots who parrot them always ask for evidence. How much more evidence could you possibly want? Only if Putin himself was caught while typing in a meterpreter session.. and even then.

Wiggly Wayne DDS
Sep 11, 2010



Trabisnikof posted:

Krebs has a recent post with an interesting tidbit


https://krebsonsecurity.com/2018/10/supply-chain-security-is-the-whole-enchilada-but-whos-willing-to-pay-for-it/

he also seems to find the bloomberg piece credible
krebs may be a big name but he's not that reliable. dhs bothered to talk about it as well: https://www.dhs.gov/news/2018/10/06/statement-dhs-press-secretary-recent-media-reports-potential-supply-chain-compromise

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Carbon dioxide posted:

I just found a thing.


Yes. Very private. And also, its members login page at http://members.rattlesnakeislandclub.com/ is http-only.

I don't really know what to do with this information other than that I shouldn't touch the poop, but I thought to post it here.

Sounds like you find a place that would very much like you to touch their poop

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

Raere posted:

Details on those Russians trying to hack the wifi at OCPW
https://english.defensie.nl/topics/cyber-security/documents/publications/2018/10/04/gru-close-access-cyber-operation-against-opcw

One of the laptops they seized had photos and metadata from previous operations. Also google.ru searches for OCPW related things. And cellphones that were activated on the closest cell tower to the GRU barracks. A+ opsec

huh, ive stayed in that marriott, weird

Midjack
Dec 24, 2007




a press release from the us government organization responsible for airport security, well i know i'm convinced.

Trabisnikof
Dec 24, 2005


what makes you say he’s unreliable? what did he gently caress up

Max Facetime
Apr 18, 2009


“Like our partners in the UK, the National Cyber Security Centre, at this time we have no reason to doubt the statements from the companies named in the story. That is, we have no reason to doubt that the statements are not saying exactly what they should be saying.”

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Trabisnikof posted:

what makes you say he’s unreliable? what did he gently caress up

not sure unreliable is the word but his scoops used to rely almost exclusively on having a friend who can read russian and hanging out on carder forums all day

Trabisnikof
Dec 24, 2005

Rufus Ping posted:

not sure unreliable is the word but his scoops used to rely almost exclusively on having a friend who can read russian and hanging out on carder forums all day

oh that’s fair, i was just throwing him on the pile of takes

Wiggly Wayne DDS
Sep 11, 2010



Rufus Ping posted:

not sure unreliable is the word but his scoops used to rely almost exclusively on having a friend who can read russian and hanging out on carder forums all day
yeah pretty much he's wandered out of his area of expertise and throws out his opinions on hot topics of the day regardless of if he has anything informative to say

Schadenboner
Aug 15, 2011

by Shine

Wiggly Wayne DDS posted:

yeah pretty much he's wandered out of his area of expertise and throws out his opinions on hot topics of the day regardless of if he has anything informative to say

dsyp

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Shifty Pony posted:

a little tweaking and it could be loss

I certainly lost about a minute of my life looking at it that I'm not getting back

BobHoward
Feb 13, 2012

The only thing white people deserve is a bullet to their empty skull
https://www.esquire.com/news-politics/politics/a23601640/mike-pence-china/

this isn't directly about the apple/amazon/etc story but it makes me wonder whether bloomberg's government sources are, shall we say, trumpy

Pryor on Fire
May 14, 2013

they don't know all alien abduction experiences can be explained by people thinking saving private ryan was a documentary

Remember when that Panama Papers story was written about all those rich people dodging taxes and we got all this info from an amazing noble leaker but magically there were zero Americans mentioned anywhere? What a perfect black and white story, we know who all the bad guys are now!

Not sure why I just thought of that.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
wasnt the lack of americans explained by who needs panama when you got delaware

Adbot
ADBOT LOVES YOU

Schadenboner
Aug 15, 2011

by Shine

ymgve posted:

wasnt the lack of americans explained by who needs panama when you got delaware

Yeah, that and straight-up offshore banking and asset structuring is legal here versus other countries that at least pretend to have better laws (which is what the Panama Papers was more for)?

  • Locked thread