meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, October 5th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 5 October 2018

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Bloomberg Hardware Implant Story; Cloudflare Phishing; DNSSEC Root KSK Rollover

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, October 5th, 2018 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Honolulu, Hawaii.

0:13.0

John Robertson and Michael Riley published an article with Bloomberg's Business Week today that alleges that the Chinese military

0:22.5

compromised motherboards from Super Micro by implanting special hardware backdoors.

0:29.9

Now, all companies named in the article as being affected, most notably Apple, Amazon,

0:35.1

and Super Micro itself did publish statements denying that anything

0:39.5

like this was happening. Now, Apple mentioned, and this was already well known, that in 2016,

0:46.6

they did have some issues with drivers supplied by Supermicro that turned out to be backdoored.

0:57.8

But Apple also stated that they never came across a hardware backdoor as described in this article. Now according to the Bloomberg article,

1:03.8

this entire issue was discovered in 2015 when Amazon purchased Elemental Technologies.

1:13.6

Elemental Technologies does produce video streaming servers that made use of Super Micro Motherboards and when Amazon did its due diligence

1:19.6

on the company, they came across these back doors. Now Amazon again states that this was

1:26.6

not a case. They did their diligence here.

1:30.0

They found some issues with super micro equipment, but according to Amazon, this was more with

1:36.3

web portals and the like, and all these issues had been addressed by now.

1:41.7

None of the sources that the reporters interviewed for the article are named.

1:46.8

They mention that they reviewed some documents, but none of these documents are reproduced

1:53.3

as part of the article. The article does show an image of a small chip, sort of the tip of a pencil size, it's actually displayed sort of next to a

2:03.2

pencil to sort of make the point. It's however not clear if this image is the actual chip

2:08.8

found on the motherboards or if this is just a random component that is used for illustration.

2:15.2

And to me it actually looks more like the later.

2:18.7

But regardless all of this, what really matters is,

2:22.6

do you have to worry about it?

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.