Servers can be backdoored by exploiting buggy motherboard controll

arstechnica.com

23 points by joozio 17 hours ago


sillywalk - 15 hours ago

*controllers

Too bad Oxide's non-BMC[0] service processor or something similar isn't available on all servers.

[0] https://oxide.computer/faq-friday/is-the-oxide-service-proce...

burnt-resistor - 14 hours ago

Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

preisschild - 14 hours ago

Thats why I just want upstream OpenBMC support and redfish