burnt-resistor 3 days ago

Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

  • hollow-moe 3 days ago

    > defense-in-depth and proper network design Damn, we're all doomed then

  • inigyou 3 days ago

    There is a a server I have whose host provides a VPN for customers onto the BMC network. I don't know if they are checking which IP address I access through the VPN, and I don't really want to find out lest I get terminated.

    There's another one from a host that just has it open to the internet. I bet you'd find a bunch by scanning the internet.

    • burnt-resistor 2 days ago

      This isn't the way. If you're in an engineering role, you have an ethical professional responsibility to do what's reasonably secure and pushback against unreasonable insecurity.

      I was once fired (forced to "resign") from a full-time job at a major university because I refused to rush weakening the security of a credit card processing network covered by PCI-DSS because a vendor couldn't figure out how a VPN works.

      • inigyou 1 day ago

        Firing was the correct move. You may be protected for refusing to commit a crime, but violating PCI-DSS isn't a crime. Businesses are free to choose which of their contracts to violate and accept the risk attached to that. You could have anonymously reported the violation to the bank.

sillywalk 3 days ago

*controllers

Too bad Oxide's non-BMC[0] service processor or something similar isn't available on all servers.

[0] https://oxide.computer/faq-friday/is-the-oxide-service-proce...

  • inigyou 3 days ago

    If you just don't plug in the BMC network port, you effectively have this. But people do plug in the BMC network port because it's extremely useful.

    • LargoLasskhyfv 3 days ago

      And then you have firmwares which switch to 'in-band-management' for convenience, if they detect that.

      If you don't disable that, and sometimes even then.

      Making that shit available on your general uplink.

preisschild 3 days ago

Thats why I just want upstream OpenBMC support and redfish