| ▲ | Servers can be backdoored by exploiting buggy motherboard controll(arstechnica.com) |
| 23 points by joozio a day ago | 7 comments |
| |
|
| ▲ | sillywalk a day ago | parent | next [-] |
| *controllers Too bad Oxide's non-BMC[0] service processor or something similar isn't available on all servers. [0] https://oxide.computer/faq-friday/is-the-oxide-service-proce... |
| |
| ▲ | inigyou a day ago | parent [-] | | If you just don't plug in the BMC network port, you effectively have this. But people do plug in the BMC network port because it's extremely useful. | | |
| ▲ | LargoLasskhyfv 17 hours ago | parent [-] | | And then you have firmwares which switch to 'in-band-management' for convenience, if they detect that. If you don't disable that, and sometimes even then. Making that shit available on your general uplink. |
|
|
|
| ▲ | burnt-resistor a day ago | parent | prev | next [-] |
| Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely. |
| |
| ▲ | inigyou a day ago | parent | next [-] | | There is a a server I have whose host provides a VPN for customers onto the BMC network. I don't know if they are checking which IP address I access through the VPN, and I don't really want to find out lest I get terminated. There's another one from a host that just has it open to the internet. I bet you'd find a bunch by scanning the internet. | |
| ▲ | hollow-moe a day ago | parent | prev [-] | | > defense-in-depth and proper network design
Damn, we're all doomed then |
|
|
| ▲ | preisschild a day ago | parent | prev [-] |
| Thats why I just want upstream OpenBMC support and redfish |