Dell Ships Infected Motherboards
An anonymous reader writes "Computer maker Dell is warning that some of its server motherboards have been delivered to customers carrying an unwanted extra: computer malware. It could be confirmation that the 'hardware trojans' long posited by some security experts are indeed a real threat."
That's some great QA you've got going on over there.
Check out my world simulator thingy.
pwned.
Blank until
The Pentagon is spending millions on research designed to ensure it can trust the microchips in critical systems, especially those made outside the US.
- I think the only true way to be sure is to manufacture the microchips yourself, of-course this costs much more than millions.
This comes down to the old question raised by Ken Thompson of Trusting Trust.
You can't handle the truth.
It's firmware, meaning software in a ROM. It's only slightly unconventional.
And they say it's only on motherboards sent out as replacements. Interesting, you would think this would make it fairly easy to identify the source.
This malware code has been detected on the embedded server management firmware.
Firmware != Hardware It would have been impressive if it was a real hardware virus though e.g. some malicious chip that opens a backdoor on the network cards and allows remote code execution.
a feature.
Basically the entire computer's assembled in a sweatshop by barely literate people who are being paid jack-shit to assemble a "rich-boy toy" for some perceived fat cat in the US who sleeps on piles of money.
How the hell would they know if someone decided to pull a dick move like this?
And for what they're being *COUGH*paid*COUGH*, why the hell would they even care?
Chas - The one, the only.
THANK GOD!!!
I have not studied computer science, firmware trojans nor antivirus. Could someone explain to me:
1) How do firmware trojans work?
2) Are they OS independent?
3) What information can they send and/or damage can they do to a system?
I call it 'The Aristocrats'
It's worse than that. Even those of us that do realize it are kind of stuck. The model that saw out sourcing to China as the solution to pretty much everything more or less obliterated the midrange category for many items. It's really hard to find things these days that are midranged in price and quality. I don't generally need to go top of the line on things, but thanks to the outsourcing there isn't a whole lot of choice, I can cheap out which usually isn't a good idea or buy high end.
The free market really doesn't handle the situation where there's a nascent market for something which investors are ignoring.
It's also possible that the malware was actually dropped from a *nix or Windows system that wasn't itself infected, but where the user wanted to drag Dell through the muck. Doesn't need to be any of these Advanced Persistent Threats you keep reading about, just a terminated employee on his last day. I doubt that embedded hardware is connected to the internet while it's being assembled, so it seems unlikely that they got a chance infection - someone had to subvert their production process. That's most likely to be an insider.
How can you make such a claim?
Outsourcing to the cheapest bidder absolves them of responsibility?
I guess OJ really was innocent, and the lady that burned her own crotch by spilling coffee on herself really did deserve the million bucks from McDonalds..
No wonder the world is in shambles..
many parts are sourced from china. would it not be distinctly possible for that government to experiment with such trojans? most likely the evidence trail would be hard to track.
Birth is the leading cause of death.
**This call may be monitored for quality assurance purposes.**
Customer: Hi, my computer won't POST.
Steve (Samir): Okay, sir, first we must try a few things. Is the machine currently plugged in?
**3 hours later**
Steve: Sir, the problem appears to be a faulty motherboard. Unfortunately your system is out of warranty. Luckily, while the system was operational, our integrated key-logger was able to pull your shipping address and credit card numbers. We have billed you for a replacement system and it should be there in 3-5 business days. Someone will need to sign for it, perhaps your oldest daughter. Justine is turning into a fine looking young-lady, by the way.
A few of their SERVICE stock for a single motherboard showed signs of malware code on the embedded server management firmware. Dell reacted quickly and appropriately. You can read the forum posting that started this all here: http://en.community.dell.com/support-forums/servers/f/956/t/19339458.aspx
Of course this is disturbing, but it's quite a leap to say a 'hardware trojan' is 'shipping with Dell Servers'. Once again, a good example why you should never blindly trust "anonymous posters' on Slashdot... RTFA yourself.
Its not bad enough they ship with windows ?
#include bier;
There are some issues where malware winds up in places, and that is something beyond the vendor's control. However, having the motherboard's BIOS infected is just plain not excusable. How can people have any guarantee of security if a maker's QA process allows this stuff to happen? Even if they offshore it to another contractor, the buck stops at the company whose name is on the machine. How can we be sure that replacing the management software and/or a BIOS reflash will take care of the problem?
At least there are plenty of vendors to choose from in the x86 server market. IBM has some very good machines. HP always has had quality offerings. Oracle sells x86 and SPARC hardware, Cisco sells x86 servers that are decent. Even Apple has a top quality 1U server that can both work in a server room as well as a musician's rack.
Let's face it, Dell is the Ryanair (or, if you're American, the Southwest Airlines) of server vendors. Anyone who's ordered a server from them knows the drill only too well.
You want a cheap server? No problem, sir.
Oh, you wanted hard disks with your server? They're an optional extra, sir. They cost more.
You wanted more than 512MB RAM? That'll be extra, sir.
You wanted a processor which wasn't discontinued 18 months ago yet somehow we've managed to find a whole warehouse full of the buggers? That'll be extra, Sir.
You want a 3 year warranty or are you happy with our standard 30 minute warranty? Three year warranty's extra, Sir.
You want to actually speak to a technician during the course of the three years? Or are you happy being routed to the office cheese plant? The technician's extra, Sir.
Now we know there's another question they'll ask.
You want a motherboard that hasn't been pre-infected with firmware level trojans? That'll be extra, Sir.
Did anyone read the problem before replying, of course not - this is /. after all - so, from Dell ( just the important points ):
3. The W32.Spybot worm was discovered in flash storage on the motherboard during Dell testing. The malware does not reside in the firmware.
4. All industry-standard antivirus programs on the market today have the ability to identify and prevent the code from infecting the customer’s operating system.
5. Systems running non-Microsoft Windows operating systems cannot be affected.
Doesn't seem very serious, of course it's Windows only so, of course, you are running antivirus AND, of course, after motherboard swap don't put it to production without testing - which would catch it?
Anyway, still wondering even without antivirus - home come that people let their systems communicate over network with unauthorized traffic? Just going back 20+ years designing network systems, some even Windows, my systems never allowed any unauthorized traffic in or out - this of course sometimes needed even building your own comm. stacks, traps, hooks, proxies, whatever but also guaranteed that all traffic was legitimate! Saves a lot headache - of course all attempts were logged, alerted and, in case of outbound, the sources were isolated - automatically! So - even Windows can be built that way (with pain!), just wondering why some don't do that?