10 ms·
We purchased a machine from China and it came with malware preinstalled
- mrunkel 5y agoGiven that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.
- mark_l_watson 5y agoA bit off topic, but the last time I needed a Windows laptop for business reasons (a long time ago) I bought a laptop directly from Microsoft and it appeared to be secure and also not loaded with advertising junk. The price seemed OK, fairly competitive.
- wlesieutre 5y agoWhen buying a Windows machine, you can purchase "Signature Edition" versions through Microsoft which will come with only the crapware selected by Microsoft, and not by the manufacturer https://www.microsoft.com/en-gd/store/b/signaturepcs https://www.microsoft.com/en-gd/store/b/signaturepcs
- gigaflop 5y agoIt looks like that isn't available for those in the US, since the redirect takes me to a 'not available' page. Are the 'Signature Edition' versions at all available in the US?
- wlesieutre 5y agoHmm good question, I just took what came up in Google which is apparently the "English (Grenada)" site. Maybe they've dropped this in the US.
- gigaflop 5y agoIt looks like they no longer offer it: https://www.howtogeek.com/402888/looking-for-a-microsoft-signature-edition-pc-heres-what-to-do-instead/ https://www.howtogeek.com/402888/looking-for-a-microsoft-sig...
- truffdog 5y agohttps://www.howtogeek.com/402888/looking-for-a-microsoft-signature-edition-pc-heres-what-to-do-instead/ https://www.howtogeek.com/402888/looking-for-a-microsoft-sig... looks like they dropped the program
- emiliosic 5y agoI had Surface 3 Pro and it was a nightmare. In the end, the SSD died and the way the machine is glued together, it's impossible to open without breaking the screen. Before its final death, it had problems with sleep/wake functions. A standard reinstall wouldn't fix it. Eventually had to take it back to Microsoft for a full re-image. That did the trick.
- raverbashing 5y agoOr it's just malware that's "around" the company since nobody cares what they download, which USB keys they plug, etc Autorun USB malware is very common
- gruez 5y ago>Autorun USB malware is very common that hasn't worked since windows xp sp2.
- raverbashing 5y agoDoesn't mean machines with malware won't save files to attached USB drives
- fpgaminer 5y ago> Or it's just malware that's "around" the company since nobody cares what they download, which USB keys they plug There's a fun story documented on Darknet Diaries (https://darknetdiaries.com/transcript/22/ https://darknetdiaries.com/transcript/22/) about a wind farm that got hacked. The "malicious" actor had found his way into their infrastructure and installed some idle cryptominers. But he was also taking the time to maintain all the infrastructure; applying updates and patches on a regular basis in an effort to keep other would-be hackers out. The security consultant discloses all of this to the company. Well, the story ends with the company making a business decision to leave things as they are. They were effectively getting free IT.
- 3pt14159 5y agoYou know what? I don't care anymore. When this type of thing happens it's almost always China. Whether it's intentional malware or a lack of QA, how could one tell? They have such a reputation for both I don't know why we still let their electronics into our countries.
- Aperocky 5y ago> When this type of thing happens it's almost always China. It could only happen in China - because the author bought dubious stuff from unknown third party on AliExpress. Craiglist scams happen mostly in US because people don't use it elsewhere. Sort of like how you shoot the arrow first and then draw a target around it, 100% bullseye.
- pphysch 5y agoThe malware described in the article is script kiddy stuff. Probably part of a ripped Win7. Stuxnet, Pegasus, Vault 7 tech are far more dangerous with that capacity to cause real harm to actual people. Who developed these?
- WesolyKubeczek 5y ago
- DrBazza 5y ago> "efficient" MBA eloi outsourced everything to morlocks a long time ago. This is the biggest weakness of the West - and it all stems back to "share holder value". Companies, US ones, in particular, seem to have some absurd drive to pay endless dividends to shareholders, and drive 'value' via share price, by appearing to be profitable. In other words, get stuff from the cheapest provider. It didn't help that at the same time people like Carl Icahn came along and stripped a company that was cheap to buy, but also sat on a pile of cash. And again, if he could 'drive value' for the share holders, said company was a target. Eventually state-level politics appear - artificially low-prices Chinese goods because the CCP fix the exchange rate, or subsidise an entire market to corner it globally. Rinse repeat, and that's where we're at now.
- phendrenad2 5y agoAlright let's think about this. If equipment was entering the US with pirated Windows licenses, wouldn't Microsoft ask customs enforcement to block them until the manufacturer stopped pirating? Also why would Windows Ultimate indicate piracy? Wouldn't it be weird if "Windows Home" flashed up on the screen while booting an industrial machine? It's more likely to make sense that Windows Home isn't licensed for use on industrial machines.
- Sirened 5y ago> wouldn't Microsoft ask customs enforcement to block them until the manufacturer stopped pirating Well, they would if they knew. I have purchased a variety of random computing hardware from Chinese suppliers and despite the product pages claiming they had no on-board OS installed, they came with cracked versions of Windows. They do it because customers want an OS but don't want to shell out for a license. It costs them nothing to pirate software (especially when they lie about it) and getting caught and actually blocked is very hard. This isn't like them intercepting a shipment of counterfeit purses where you can clearly tell by looking at the item. You'd have to boot the computers and then verify that they have an OS installed and then that it's properly licensed, which is well out of reach for a random customs officer. > why would Windows Ultimate indicate piracy? It's a very expensive license and, if you have any experience pirating Windows (I cough don't) that's usually what you find since if you're going to steal something, why steal the shittier, less featurefull version?
- klondike_ 5y ago>why would Windows Ultimate indicate piracy? Microsoft sells an embedded, stripped down version of Windows with extended support life for industrial machines like this. Ultimate is intended for workstations and power users.
- Jwarder 5y agoAt this point how can they trust any installers they get from the company? The risk the manufacturer bundling some "legitimate" remote access tool that won't show up as a virus seems high to me. Once burned twice shy.
- kgeist 5y agoChinese phones sold here were found to not only send telemetry to Chinese IP's, some of them send SMS' to paid services, register Telegram accounts, etc. It's like a botnet. Here's the article: https://habr-com.translate.goog/ru/post/575626/?_x_tr_sl=ru&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp https://habr-com.translate.goog/ru/post/575626/?_x_tr_sl=ru&...
- kautzz 5y agoor maybe they don’t give a fuck about your tiny company that’s too cheap to buy a decent pic n’place? maybe the malware was actually intended getting ip from the company that manufactured machines like yours in the thousands. why do you always assume US companies are the only ones being copied from?
- hereforphone 5y agoMoving manufacturing back to our home countries (assuming a mostly Western audience here) is important not just for economic reasons but also for health, safety, and security. Trying to do so might get you called a racist, but it might depend on what political party is giving it a shot. This is an old problem and too little is being done about it.
- drno123 5y agoThank you! We receiced ZhengBang pick and place machine last week and did nit have the time to unpack it yet. We will definitely be careful now.
- dave333 5y agoThe author's website also has an interesting collection of science gadgets - tesla coils etc. https://www.rmcybernetics.com/science/diy-projects https://www.rmcybernetics.com/science/diy-projects
- deleted 5y ago[deleted]
- nyolfen 5y agohttps://archive.fo/DIrdx https://archive.fo/DIrdx
- amelius 5y agoIs this anything new? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
- southerntofu 5y agoI'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 1984 from all Kindles. Microsoft proudly bragged about their remote app "kill switch". Let's not even talk about about CPU vendors embedding "anti-theft" solutions which are nothing more than RCE-as-a-service on a hardware/firmware level. Or hardware vendors bundling rootkits like Lenovo on some laptop series, and most phone manufacturers on all their devices.
- the_dripper 5y agoDo you perhaps have a link about the story of amazon removing the 1984 book on all kindles? It sounds very interesting, partly because it seems so absurd.
- dec0dedab0de 5y agohttps://www.pcworld.com/article/519855/amazon_kindle_1984_lawsuit.html https://www.pcworld.com/article/519855/amazon_kindle_1984_la... That story is about a lawsuit from one of the people they took it from. Amazon sold 1984 on the Kindle store without permission, and when they realized their error they deleted it from everyone's kindle and refunded their money.
- tgv 5y agoThat's really something entirely different than malware. You know that Amazon books on kindle are subject to that. It's not malware on the Kindle, it's their whole schtick.
- iqanq 5y agoTalk to afraid.org, perhaps they'll take down the subdomain.
- 300bps 5y agoBought a system on Ali Express to save money, the parts don't match what they ordered, it is infected with a virus designed to steal their data and infect executables on any USB device plugged into it to spread the infection. Ali Express says computers with viruses on them aren't against terms of service. They for some reason continue to use the system and try to get it to work. £4k GBP...relatively low cost compared to a branded competitor...We sent the file for proper malware analysis which did confirm that it did indeed contain malware. The malware would collect user data and send it to a remote address.
- bserge 5y ago
- Maxburn 5y agoI can't read the article from here but attacking the supply chain isn't new. It is something that requires constant vigilance.
- hdjjhhvvhga 5y agoI remember I bought a few phones from Aliexpress once for one of my IoT projects. I was somewhat surprised they don't really hide the malware, it's preinstalled. These are not just the usual bloatware you can't install but also the main web browser already modified injecting random crap.
- encryptluks2 5y agoI bought an HP machine in the US with malware deployed from Windows Updates.
- Iwan-Zotow 5y agoSee? You don't have to install malware yourself - that's the service!
- mrunkel 5y agohttps://archive.is/DIrdx https://archive.is/DIrdx
- 0xbadc0de5 5y agoThe story here is not the fact of the malware - it is the purpose of the malware: industrial espionage. China is well-known in industry for its sheer volume and brazenness of industrial espionage. A pick-and-place machine is especially well placed for this since it will, by necessity, have access to PCB designs and BOMs.
- RunSet 5y agoI have seen enough stories of supply-line sabotage to think that if you are going to build your infrastructure with Chinese hardware, air-gapping it is a necessity. Probably a good idea to air-gap your pick and place machine even if it is not Chinese.
- ed25519FUUU 5y agoAirgapping wouldn’t be enough here since it infects any USB device plugged in. You’ll have to run the USB through some antivirus any time you want to use a new design from a “good” computer.
- miles2sleep 5y agoYou could go for overkill and establish a one-way data transfer methodology with built in crc/ecc. Receive-only optics on the destination side might be usable.
- upwardbound 5y agoYou could buy a big box of flash drives and use them as a disposable commodity that is one-time-use. E.g. these flash drives are $3.49. https://smile.amazon.com/Verbatim-Pinstripe-Flash-Drive-49063/dp/9802181749/ https://smile.amazon.com/Verbatim-Pinstripe-Flash-Drive-4906...
- jjulius 5y agoBut then you're getting into a bit of an e-waste problem.
- 01acheru 5y agoHug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird Chinese website send it back, if you are asked to download a sketchy application with a Chinese readme send it back, etc... After a while you'll notice you are sending everything back. And it is not only Aliexpress or other Chinese marketplaces or websites, Amazon is full of Chinese crapware just the same. edit: read the article from archive, well it just confirms to me what I wrote earlier.
- netmare 5y ago> After a while you'll notice you are sending everything back. What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.
- Clubber 5y agoHe offers a simple solution in the first paragraph. >everyone should avoid Chinese crapware.
- capableweb 5y ago> Surely buyers can't possibly afford sending everything back. What country you live in with so poor online protections you can't return things within the return window without incurring extra costs for doing so? Sounds broken.
- vladvasiliu 5y agoIn France, for example, it's legal for the customer to be on the hook for return shipping. This is often the case with smaller merchants, but even bigger ones have this policy. Example: Darty [0] So if you have to pay for the crap to be shipped all the way back to China, I can see how that may become expensive. [0] Darty return policy, in French: https://www.darty.com/achat/services/retour-retractation/index.html https://www.darty.com/achat/services/retour-retractation/ind...
- jeroenhd 5y agoI do wonder if this really was sabotage or if someone building these machines accidentally got their installer USB infected with some unrelated malware. If this was a targeted attack, I'd expect the manufacturer to ship the infection in the zip file with the replacement program as well. The old components and the lack of modern drivers is a problem many industrial tools seem to suffer from. It's crap like the bad capture card that keeps Windows XP and 7 around. I don't expect there ever to be any modern drivers for an outdated capture platform unless a hobbyist writes their own open source version, so unless a compatible enough alternative card with modern drivers can be installed, I assume this machine is doomed to run Windows 7 for years to come.
- Damogran6 5y agoIs that any kind of excuse? Supply Chain infection is a sidechannel way to infect YOUR network...what's your intellectual property worth? What's it worth if through the unintentional infection you find yourself figuring out how to get cash into bitcoin to pay a ransom? Relying on an ancient card and drivers seems like a cop-out...they managed to create the solution once, they're obligated to do it again, lest your company's bottom line hinge on a house of cards an intern cobbled together for another company 12 years ago, that only works with the September 2008 drivers.
- jeroenhd 5y agoOf course intent matters. Accidents can happen and don't necessarily soil an entire brand name, but intent definitely does. You'll be surprised how common these "house of cards an intern cobbled together for another company 12 years ago, that only works with the September 2008 drivers" situations really are when it comes to specialised hardware. As long as the machine keeps working, it can be sold, software security and maintenance be damned. There's a reason hospitals and factories pay Microsoft for the last few Windows 7 updates it'll release this year and it's not that management doesn't like the theme Microsoft put on Windows 10. That's even more likely to be the case for industrial machines purchased off AliExpress, where hardware is often either old, second hand stuff or made as cheaply as possible from available parts. The standard of quality there is minimal, I'm surprised they risked buying this thing through AE in the first place.
- disgu 5y ago> Presumably it would be a way to steal company information such as designs, accounts, and so on. Does it collect user metrics like a lot of software does or does it actually steal designs? The report is absolutely not clear about this. I have not read many reports like this but are they all like the one they link to? Is that what a malware analysis looks like? I'm completely behind the idea of calling every single software that collects user data and sends it off to a server malware but this is just not the case. We don't say Windows comes with malware, we in the West call it telemetry data to improve the user experience.
- PragmaticPulp 5y ago> Does it collect user metrics like a lot of software does or does it actually steal designs? The reports mark it as a Trojan/backdoor. This means it gives the company remote access to the machine. They can do whatever they want with it. This isn’t anything like analytics reporting.
- megous 5y agoAnything with remote updates falls into that category.
- me_me_me 5y agomalware is any software that hides its existence from user. The windows telemetry is on edge of being malwere, even if its of no consequence to you. You cant say it will always stay that way.
- rightbyte 5y agoWhy is it not malware? The Wikipedia definition of malware lists "steals data". Last time I tried the amount of deep registry hacks to turn everything(?) of was silly. Windows obviously ships with malware nowadays. I think you need enterprise edition for a supported way to turn all the BS off.
- tremon 5y agoI'm going to broaden your definition to "malware is any software that hides its existence or its behaviour from the user". There's little value in knowing that a certain piece of software exists on your machine if you don't know what it's for.
- duxup 5y agoIf I have a choice I generally try to limit my purchases from “non free” countries. It’s not always easy, the line is hardly easy to see, but it is a choice I will go out of my way to make.
- deleted 5y ago[deleted]
- sandworm101 5y agoI bought a laptop once. It came with windows pre-installed. And a bunch of bloatware. And 101 things that phoned home under the guise of checking that a driver was up to date. And Norton. The definition of malware is open to large interpretation.
- npteljes 5y ago>I bought a laptop once. It came with windows pre-installed Some would say, not without merit in my opinion, that the malware part started with Windows itself. https://www.gnu.org/proprietary/malware-microsoft.html https://www.gnu.org/proprietary/malware-microsoft.html But even if we aren't that stringent with the definition of malware, we had malware preinstalled on our computers quite some time. https://en.wikipedia.org/wiki/Lenovo#Security_and_privacy_incidents https://en.wikipedia.org/wiki/Lenovo#Security_and_privacy_in... https://en.wikipedia.org/wiki/Dell#Self-signed_root_certificate https://en.wikipedia.org/wiki/Dell#Self-signed_root_certific...
- defanor 5y agoThe malware is a cherry on top, but the story before that is pretty awful already, and unfortunately seems to be representative of specialized software like that: proprietary (with constant risk of malware, indeed), awkward, poorly (if at all) documented, likely the protocols to speak to the hardware without it are kept in secret, and occasional shipment of Windows machines where just software would do (but probably it's written to just barely work on a given system, and won't run on others easily). I think the main and annoying problem is those general practices, not just a single instance of malware. Edit: Apparently some focus on the "Chinese" part, but I suspect that hardware being specialized and software being shipped by the hardware manufacturer are larger factors here: at least all the awkwardness before the malware part I've observed to be approximately similar with hardware+software produced by Chinese, European, and US companies.
- StreamBright 5y ago> proprietary (with constant risk of malware, indeed) being proprietary has nothing to do with risk of malware, indeed
- defanor 5y agoTo be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation. [1] https://en.wikipedia.org/wiki/Proprietary_software https://en.wikipedia.org/wiki/Proprietary_software Edit: wording.
- ChrisLomont 5y ago>the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And you cannot do that on open source either. Both cases require a chain of trust, and empirically, neither is significantly more secure.
- jcims 5y agoI've bought systems off of Amazon that had pirated Windows licenses on them (otherwise a great little fanless box) In a previous life I was an infosec consultant. We did some work for a hospital that found malware on the control hosts shipped with a brand new turnkey MRI system from a German manufacturer.
- capableweb 5y agoWhat did the malware do precisely? The definition is so broad and context-sensitive, that just saying malware doesn't really say anything. Some people would consider TPM and it's code malware, others would consider anything they don't like malware (like telemetry collection in Windows or whatever).
- jcims 5y agoIt was one of the big Microsoft worms from ~10 years ago plus a few random ones.
- Wingman4l7 5y agoI've seen plenty of stick PCs on Amazon that definitely have pirated copies of Windows on them. I continue to be a bit surprised that Microsoft hasn't gone after Amazon for "aiding & abetting" this, but they probably have bigger fish to fry.
- flatiron 5y agothey dont make their money on Windows licenses anyway. they make it on all the crap they shove in your face when you use windows. you've been able to pirate windows 10 using their "windows 7 free update" key even after they discontinued it. and everyone who got a free upgrade from 7->10 uses the same key so its not like you are gonna get caught.
- csmpltn 5y agoThe malware analysis report they've ordered (https://www.rmcybernetics.com/files/pdf/Malware-analysis-FlyerSMT_HV-zhengbang.pdf https://www.rmcybernetics.com/files/pdf/Malware-analysis-Fly...) is extremely light on details. Yes, some things look suspicious (packing, lack of signatures, hardcoded IP addresses/hostnames, network traffic) - but I'm not seeing any clear-cut evidence that this is malware?
- inglor_cz 5y agoI have seen a (badly written?) router firmware that behaved suspiciously just like you describe, but the only provable thing was that they checked for updates from the vendor in a rather non-optimal way. Until today, I am not sure whether this was malice (=malware) or incompetence (=hey, let us phone home every 5 seconds and go crazy if the connection fails for any reason).
- q3k 5y agoYeah that analysis is... not great. It looks like an instance of 'xred': https://s.tencent.com/research/report/880.html https://s.tencent.com/research/report/880.html Which seemingly infects .exes (ie., is not just a worm), so it's totally possible that the OEM here isn't acting maliciously, but they just got infected themselves.
- AlwaysRock 5y agoIt's frustrating. I've seen anti malware software pick up anything that has a file name in Mandarin as malware. I used to use a great little program called Clover which was basically File Explorer for Windows but it allowed tabs. I stopped using it after a while because anti malware kept flagging it. Did it have malware? Maybe! I couldnt really get a good answer and I figured having tabs in file explorer isnt worth it.
- nyx 5y agoI haven't thought about Clover in forever, but didn't it add tabs to your existing Explorer, versus being an Explorer clone plus tabs? The behavior required for the former probably looks a lot like malware to a heuristic detection engine.
- caaqil 5y agoThe malware now has 60/67 rating [1] on VT. Their analysis [2] is pretty good too. [1]: https://www.virustotal.com/gui/file/1679b086f649d92456b2f60028fe3be7169e955830319e7f68063ab76379a37e/detection https://www.virustotal.com/gui/file/1679b086f649d92456b2f600... [2]: (PDF) https://www.rmcybernetics.com/files/pdf/Malware-analysis-FlyerSMT_HV-zhengbang.pdf https://www.rmcybernetics.com/files/pdf/Malware-analysis-Fly...
- gruez 5y ago>Their analysis [2] is pretty good too. seriously? It's rather poor. >It was identified the malware is packed with Borland Delphi 6.0 - 7.0 as shown in the figure below Borland Delphi is a compiler. It's not a packer. Saying that it's "packed with Borland Delphi" makes as much sense as "it's packed with visual c++". >The strings of interest are as shown in the figure below But if it's packed (as previously suggested), then any strings of interest won't be visible. All we see is a bunch of strings related to dynamically linked libraries. That also doesn't tell you much, because you can dynamically load libraries so all the evil APIs you use don't show up on the list. The rest of the report seems to be reciting outputs from various reverse engineering tools, with little analysis added. The whole report gave the impression the author is a script kiddie.
- caaqil 5y agoI mean sure, the analysis isn't thorough and has some oopsies, but from my POV it's not a report written by malware analysts or experts (rather, by someone you wouldn't expect to analyse it at all), so I'm not setting the bar too high.
- VoidWhisperer 5y agoSince the site seems to have been hugged to death, here is the link to an archived version from a few days ago: https://archive.md/DIrdx https://archive.md/DIrdx
- titzer 5y agoI am more than a little concerned that since the miniaturization and commoditization of spy hardware (miniature microphones, cameras, and wireless communication), that run-of-the-mill consumer electronics are being bugged by default. Given the cost is pennies or just a couple dollars, from an espionage perspective, it'd be worth it to spend a few hundred million or even billion putting bugs into literally everything and letting the market put them into the homes of all your political targets in other countries. Then the problem is just sifting the data, which is easy with the massive amount of computational power that every nation state has these days. That's a great dystopia.
- bruce343434 5y agoWhat would the chips connect to in order to phone home? My protected home wifi? A random telecom carrier for which it will have to have, by chance, a valid prepaid sim card?
- mellavora 5y agoHey, Alexa, please tell me what random devices in my house are connecting to the internets? <waits for answer> Hey, Roomba, did you download the latest firmware yet? Great! Now go clean the dining room, I have a top-secret meeting in there in 10 minutes. Hey, Alexa, set the dining room lights to "top-secret meeting" mode.
- bruce343434 5y agoquite the conspiracy. But I do suppose amazon sidewalk could be tapped into?
- carapace 5y agoThis has already happened: smartphones and wifi. People financed it themselves by buying the things. (Wifi can see you: "The next big Wi-Fi standard is for sensing, not communication" https://news.ycombinator.com/item?id=29901587 https://news.ycombinator.com/item?id=29901587 ) FWIW, I think whether we build a dystopia or utopia depends on whether or not we can make our rulers live under the same panopticon as the rest of us.
- jokoon 5y agoI'm curious how the Chinese government is able to install malware in chinese-made android phones. It's hard to know which brands to avoid, and which brands are more trustworthy. Even brands that are not chinese are still based in China...
- jjuel 5y agoSo they bought a machine from a brand they have never heard of off AliExpress to save a little money, and it was infected with malware. Color me surprised...
- drclau 5y agoI always wondered, how safe from tampering during manufacturing are devices 'designed in US/Europe/etc' that are built in China? Can anyone shed some light on the processes/practices that keep these devices safe, both from HW and SW points of view?
- jeroenhd 5y agoMeasures could be put in place, like installing the OS only when it arrives from the Chinese construction site or shipping pre-installed SSDs with Bitlocker enabled (with unique keys per customer) so that the drives cannot be tampered with unnoticed. In practice, I've never heard of companies actually investing in these checks. There are a few "assembled in the USA" products that probably flash their install image outside China, but who says the American intelligence agencies in turn won't tamper with those? They've done it before, after all. I'm a little surprised there aren't any viable open source programs for what is essentially a precise plotter with a complicated plot head. A bunch of plants could work together to construct a system free of vendor lock-in and expensive replacement parts if they would just work together.
- nimbius 5y ago"The malware would collect user data and send it to a remote address." unpopular question, but how is this any different than mistakenly forgetting to disclose 'telemetry' in your code? or backdoors that routinely get disclosed in US embedded hardware products like firewalls and routers? or Discord scanning your entire hard disk? Ill admit the product seems pretty poorly designed from the get-go, but the tactics at work here are pretty standard when you consider things like Alexa and Ring get a pass for similar chicanery.
- IggleSniggle 5y agoAlexa and Ring don't get a pass though, do they? For these very reasons. I know this is the HN crowd and not the general population, but I think most of HN would agree that undisclosed telemetry is super bad / malicious, and that disclosed / configurable telemetry is much better...but still often must be disabled because the Well is Poisoned by inappropriately utilized telemetry.
- marginalia_nu 5y agoIt isn't, and those things are just as bad. As a concrete example of just how far the creeping acceptance of surveillance has come. Remember BonziBuddy[1], and the absolute shit storm over that and the lawsuits and all that? Well what they did nearly indistinguishable from what Alexa does, and Cortana, and Siri, and Google Assistant. But it's just the way things are now. And no, it's not fine because everyone is doing it. It's still just as bad as it was then. [1] https://www.youtube.com/watch?v=L958sMz1kWs https://www.youtube.com/watch?v=L958sMz1kWs
- PragmaticPulp 5y agoIt’s marked as a “Trojan/backdoor”, meaning remote access tool, and it tries to spread itself by inserting files to any USB stick inserted into the computer. Giving someone full remote control over a computer and trying to spread that control as a computer virus is nothing like anonymous analytics collection.
- matheusmoreira 5y agoIt's not really any different but these are "legitimate" companies with "legitimate" interests in people's data so nobody says anything. Governments do the same things that many hackers have gone to jail for at much larger scales and they award themselves medals for it. They literally stockpile exploits and don't help patch vulnerabilities, allowing their own citizens to remain insecure. The FBI once let a child abuse case fall apart because the judge ordered them to disclose the vulnerability and they refused.
- PragmaticPulp 5y agoIf you can’t load the article, the machine is a desktop pick-and-place for populating PCBs and the malware is flagged as a backdoor/Trojan for remote access. As these desktop pick and place machines come down in price, I hope that the OpenPnP software package becomes more developed: https://openpnp.org/ https://openpnp.org/ It was originally intended for full DIY PnP machines, but it’s a perfect candidate for converting these existing machines to open source software control.
- deleted 5y ago[deleted]
- vultour 5y agoThe “proper malware analysis” had me cracking up. I really hope they didn’t pay any significant amount of money for that.
- avnigo 5y ago> AliExpress Says Malware is OK [...] They stated that it does not breach their terms and that no action will be taken. I'm sure many things don't explicitly breach their terms, but surely I expected there to be a catchall that would include malware. Of course, their terms are to protect AliExpress, and not the consumer, so it doesn't look like they'd wanna go above and beyond on that end, but I hoped they'd at least care about customer satisfaction.
- JediPig 5y ago20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. How it was discovered. We put a card on listening/prem mode and mirror everything for that subnet the printer was on. I thought I screwed it up with the double mirror/traffic. when investigating why the issue, we found nothing wrong with the config, only when we plugged it to another network, we discovered it was something on the network. We narrow it down quickly to the printer. We told head of security (we were hired for an audit ) and it soon became known it was stealing trade secrets and sending them overseas. that was 20 years ago, and till this day, I remember anytime someone says china doesn't steal technology... I remember this printer. this was done at the state level and was caught.
- rafale 5y agoWhy was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack.
- dookahku 5y agoThat doesn't feel like a reasonable response... How's anormal person supposed to know what DMZ subnet would means?
- josephcsible 5y agoA normal person wouldn't, but there should be someone on a company's IT staff who does.
- tablespoon 5y ago>> 20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. > Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack. Aren't most network printers connected to office networks with public internet access? I sounds like this printer was making outgoing connections, and I doubt many people/companies go through the trouble of specially blocking those from printers. You'd have to be especially security conscious and paranoid (especially 20 years ago!), to be operating under the assumption that your own equipment is working against you.
- luckyorlame 5y agoCool, talk about value add!
- mrtweetyhack 5y ago
- aembleton 5y agoWebsite is returning an error. Here's a web archive link https://web.archive.org/web/20220125124520/https://www.rmcybernetics.com/general/zhengbang-zb3245tss-pick-place-machine https://web.archive.org/web/20220125124520/https://www.rmcyb...
- iancmceachern 5y agoHackaday covered this recently too: https://hackaday.com/2022/01/22/zhengbang-pick-places-your-confidential-data-in-the-bag-slowly/ https://hackaday.com/2022/01/22/zhengbang-pick-places-your-c...
- oversocialized 5y agogood thing every local and state government institution in the united states is using Zoom because it is "free"
- pftburger 5y agoChina isn’t a single thing… treating it as such creates a tribalistic atmosphere that’s good for no-one at all…
- akireu 5y agoA decade ago, an article [1] was published in the Russian "Hacker" magazine where the author alleged that a Russian OEM manufacturer's motherboard sourced from China had a BMC chip (which should've been disabled as per the mobo spec) inject a hypervisor into the host machine. It was, again, allegedly, discovered because the author was developing some kind of distributed computing software that required a hypervisor of its own, and this exact mobo was crashing in a way that was consistent with a hypervisor being already present. The author goes further to describe how he devised a way to consistently detect hypervisors by measuring platform register access timings, and tried to report the findings to the FSB (Russian CIA/FBI) to no avail. I personally don't put much stock in the story, as the magazine was a rag and I could come up with something like that at the time, but there it is. [1] https://xakep.ru/2011/12/26/58104/ https://xakep.ru/2011/12/26/58104/
- AlwaysRock 5y agoIncredible. How many people are using this exact machine without being aware of this?
- steve76 5y ago
- Ccecil 5y agoAbout 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was phoning home info...likely wifi credentials...etc. It started me off on the thought process of "How many other things can be compromised?" SD cards with fake/hidden partitions? MCU counterfeits with entire subsystems? IMHO...anything with an ethernet port, wifi, bluetooth...or anything that is able to at any time connect to those things needs to be watched.
- megous 5y agoTBH, this sounds like nonsense. What kind of ROM? There are not many ROMs in tablet SoCs. And how would it affect Android install in such a specific way? Wipe the whole eMMC and install a fresh, clean AOSP build and something is forcing a home page in a browser? Without a lot more detail, this sounds all kinds of improbable.
- Ccecil 5y agoI wasn't the one doing the work on it and I may be incorrect about how it was working. It was at a level where it wasn't a simple update software fix...it required more. Asking now to see about specifics. What I do know for sure was it was bad enough that we decided never use them.
- vorpalhex 5y agoAndroid uses an A/B partition scheme. Either the bootloader can be infected or both partitions can have the malware. With the A/B split, even if you blow away eg B, A can reinfect B. It would be trivial to add extra circuitry to reinfect both partitions as well.
- megous 5y agoRight I guess I assumed 'wiping android' meant starting over: erasing the eMMC via TRIM and flashing a new bootloader/repartitioning/etc. via BROM USB mode or something like that. I guess OP might have meant just 'factory reset'. Which is not really 'wiping the android' at all.
- pl0x 5y ago
- tharne 5y agoIn 2019 the Chinese covered up the early spread of COVID then later repeatedly stonewalled anyone doing serious research into the disease's origin. By letting COVID spread for months unchecked the Chinese effectively ensured that there was no way to stop this thing from going global, which it did, ultimately killing over 5M people and counting. If we're unwilling to hold the Chinese to account for that in any meaningful way, I can't imagine we're going to do anything whatsoever about a little (or even a lot of) industrial espionage. We'll gladly let the Chinese run roughshod over us and humiliate us repeatedly if it means we can still by our iPhones on the cheap.
- deleted 5y ago[deleted]
- contingencies 5y agoI've just passed the 20 year anniversary of my arrival in China. Having lived in at least eight cities over that period and traveled broadly, I would strongly caution against assuming this is a deliberate attack by the vendor, much less the government. The vast majority of Windows instances in China are sourced from pirated distribution media and it is usual for those to be infected. This affects everyone domestically, not just machines shipped out. Furthermore, most apps are pirated with the same issues. Finally, many people's thumb drives touch a plethora of dirty machines (printing shops that support the still largely paper-driven bureaucracy, photography shops, work and home PCs, etc.) and thus are excellent vectors for malware. As usual, Hanlon's razor: resist over-attribution to malice.
- dynamohk 5y agogot a usb on ebay with malware for windows.
- flibberbit 5y agoAs much as that sucks, it's not all that surprising. You decided to try to undercut everyone else who desired a living wage. That's not to say getting infected with malware is "what you deserved", nobody should have their security compromised. What I'm saying is that you compromised your security by not working with people you can trust, people who are asking for a living wage and thus don't have to resort to putting malware into the products they create. People in China aren't bad people, they're just people put into a tough situation. It's plenty easy to get good quality products out of China, just like anywhere else. The problem is that few people are willing to pay the real price for products, they want cheap regardless of consequences. As someone also in the electronics design and manufacturing space I find this type of behavior very troubling. I demand what I consider a fair wage for my work and in return I also try to support other people in the industry also getting a fair wage. If all you do is buy the cheapest possible services you are really telling others they should do the same and not support you. The only solution I see is to stop pushing the costs of your business onto others that can't afford it. Go buy quality used hardware from people you can trust rather than complaining that a former colony of yours is trying to steal something from you.