Live data from Hacker News

Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

servethehome.com

11–20 of 26 posts

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#11
post #4

Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. It is IMHO more likely that it has inferior performance or even more probably a shorter lifetime due to inferior quality of components and/or sub-standard manufacturing. About the: >When our reader tried using iPXE, a network booting tool, with the NIC, it failed even though genuine cards work without issue. kn…

Security requires availability which is far from guaranteed when using counterfeit hardware

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#12
post #4

Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. It is IMHO more likely that it has inferior performance or even more probably a shorter lifetime due to inferior quality of components and/or sub-standard manufacturing. About the: >When our reader tried using iPXE, a network booting tool, with the NIC, it failed even though genuine cards work without issue. kn…

>Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. Even if it isn't a security risk from a data theft/malicious code standpoint, it could be substandard in quality and be exponentially more likely to fail. A failure could just be an annoyance, taking Jim Bob's pornoputer off the home network and causing him to be unable to connect to the YouPorns until his nep…

>especially if you have already trickled special forces soldiers into the country on tourists visas or via smuggling routes (United States special forces actually train to go into countries ahead of common forces to cause disruption and/or train local resistance) and can cause further disruption by causing mass panic with shootings/bombings/attacking first responders.

Exactly how does this work? Wouldn't this require your troops to somehow blend into the populace and not stick out like a sore thumb? If the US were planning to invade Germany or Britain, this would work fine, but for some other parts of the world (esp. east/SE Asia), US special forces are going to be instantly recognizable as foreigners because they generally don't look anything like the locals.

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#13
post #10

Will official Intel drivers work on a counterfeit card? It seems like Intel would bake some authentication into the drivers and authentic hardware such that the drivers would not work if the card is counterfeit.

>authentication Where? Intel sells network chips to OEMs, one of the more shady ones decided to directly clone Intel PCB.

In this case, are you saying the answer is "Yes, official Intel drivers will work on a counterfeit card," and it is not possible for Intel to include anything in the driver or hardware that can perform authentication? I was asking because I don't know.

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#14
post #4

Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. It is IMHO more likely that it has inferior performance or even more probably a shorter lifetime due to inferior quality of components and/or sub-standard manufacturing. About the: >When our reader tried using iPXE, a network booting tool, with the NIC, it failed even though genuine cards work without issue. kn…

A PCI express card can use Bus Mastering to gain read/write access to main memory, bypassing the CPU. Counterfeit hardware running arbitrary code that has Direct Memory Access can do anything. Its much worse than running an arbitrary binary on the Operating System. If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk!

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#15
post #6
post #2

For anyone trying to spot counterfeit products in general, a good place to look is at the FCC logo. On the counterfeit card in the article the FCC logo is wrong. The real logo ends with two concentric circles with a pie-slice out of them forming the "cc" while the counterfeit logo clearly has a different shape.

A different article, linked by the HN post one, shows much better quality screen-printing logos on a counterfeit card than on the counterfeit in the immediate article: https://forums.servethehome.com/index.php?threads/comparison... Though I can't see an FCC logo in the different article's photos. (I also can't see an FCC logo on the different model of supposedly-Intel quad-gigabit PCIe card of mine I just looked at.)

It's a general quick way to check, it'll not always work. A bodged FCC logo means it's almost certainly a counterfeit. A proper or missing FCC logo means near nothing. I just noticed the bodged FCC logo in the original article, that's all.

sometimes you can spot similar shenanigans based on the CE logo but that's more rare.

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#16
post #12

Earlier quoted context omitted.

>Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. Even if it isn't a security risk from a data theft/malicious code standpoint, it could be substandard in quality and be exponentially more likely to fail. A failure could just be an annoyance, taking Jim Bob's pornoputer off the home network and causing him to be unable to connect to the YouPorns until his nep…

>especially if you have already trickled special forces soldiers into the country on tourists visas or via smuggling routes (United States special forces actually train to go into countries ahead of common forces to cause disruption and/or train local resistance) and can cause further disruption by causing mass panic with shootings/bombings/attacking first responders. Exactly how does this work? Wouldn't this require…

> but for some other parts of the world (esp. east/SE Asia), US special forces are going to be instantly recognizable as foreigners because they generally don't look anything like the locals.

Not everyone in the United States is a blond haired, blue eyed white person.

Also, simply adopting the local dress is often enough in many countries where immigration has been a thing for decades now. You also can adopt local hair styles, this is why you'll see a lot of the special forces community with long hair and beards in Afghanistan and similar countries.

If you dress the part, walk the part, speak the part (the DLIFLC alone teaches 24 languages) you can blend in to a city pretty easily. Will you stand out like a sore thumb in a remote village, almost certainly, can you stroll through a town of tens of thousands of people with very little attention paid to you, usually.

With previous U.S. actions though it is usually go into a country mostly-overtly and just train local fighters (or fly them to the United States for training) but the Special Forces community has many instances of infiltration in advance of regular military units, as well as ongoing humanitarian efforts (which helps build awareness of local cultures and customs and dialects). Green Beret medics for example have been used in multiple African countries to provide medical aid, just doing general health checkups on villages and the like, a buddy of mine that was an 18D (Army - special forces medical sergeant) mentions it in his book Love Me When I'm Gone (by Robert Patrick Lewis) as well as a lot of training with foreign military in their country, in his case Germans.

---

Say the Asian country of Makebeleivia wanted to get special forces in place into a country that was largely caucasian prior to a proper attack to disrupt. How do they do it? You send some people in as tourists on various commercial flights, you can use multi-national companies you control or have some coercion over to bring workers over on work visas (and might actually do work for weeks or months), you get some in on student visas, you can pay coyotes to sneak some in, you can sneak some in yourself if there is a coast by deploying them via submarine and having them slip into tourist towns as tourists or with fake identification. Then you use any number of means to arm them with conventional firearms and if you want to cause mayhem you have your demolitions experts cook up crude explosives. The purpose here would be to create panic and tie up first responders, this also puts the national government agencies on edge thinking there is some sort of terrorist attack and is more likely to distract than make them think "oh hey a military invasion might be underway". You can either go after relatively 'usless' targets like crowded public places or you can go after more strategic targets like damns, ill-protected power plants, substations, key bridges in and out of large cities or bridges that create strategic issues for moving heavy equipment, etc.

---

A somewhat good example of foreign agents operating on foreign soil, although in a different capacity, is Mossad. They've done a lot of kidnappings on foreign soil to bring war criminals back to stand trial, assassinations abroad, kidnapping defectors to stand trial, etc

Find some examples here https://en.wikipedia.org/wiki/Operations_conducted_by_the_Mo...

One of the more high profile things Mossad has done is going after Black September, for the Munich bombings. The 2005 film Munich is about this.

Also, Sayeret Matkal, which is basically Israeli's Delta Force - they've sabotaged airliners, done kidnappings and raids, assassinations, done physical evidence gathering in Syria.

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#17
post #4

Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. It is IMHO more likely that it has inferior performance or even more probably a shorter lifetime due to inferior quality of components and/or sub-standard manufacturing. About the: >When our reader tried using iPXE, a network booting tool, with the NIC, it failed even though genuine cards work without issue. kn…

A PCI express card can use Bus Mastering to gain read/write access to main memory, bypassing the CPU. Counterfeit hardware running arbitrary code that has Direct Memory Access can do anything . Its much worse than running an arbitrary binary on the Operating System. If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk!

>If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk!

Undoubtedly, what is IMHO missing is any proof that the counterfeit hardware (besides being likely of inferior quality) is actually running arbitrary software.

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#18
post #4

Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. It is IMHO more likely that it has inferior performance or even more probably a shorter lifetime due to inferior quality of components and/or sub-standard manufacturing. About the: >When our reader tried using iPXE, a network booting tool, with the NIC, it failed even though genuine cards work without issue. kn…

>Maybe it is just me, but I fail to see any evidence that a counterfeit card is necessarily a security risk. Even if it isn't a security risk from a data theft/malicious code standpoint, it could be substandard in quality and be exponentially more likely to fail. A failure could just be an annoyance, taking Jim Bob's pornoputer off the home network and causing him to be unable to connect to the YouPorns until his nep…

Sure, could, may, it is possible, it is easy, etc., but nothing that proves specifically that the specific counterfeit NIC is actually a risk.

As the article says, a compromised NIC is a security risk, but no proof of that NIC being compromised (nor that it is actually easier to compromise it).

And I would expect that an hostile government would have their own counterfeit NIC's:

1) better copied/marked/silkscreened

2) gave iPXE working on them exactly like the originals

i.e. not easily recognizable.

Even more specifically, I seemingly quickly found on Alibaba a "legitimate" NIC (in the sense that has no fake Intel marks) that looks very like the given specimen.

So the counterfeiters can buy those and put the fake Intel markings on them, reselling them for double or triple the cost, why would they change anything else?

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#19
post #17

Earlier quoted context omitted.

A PCI express card can use Bus Mastering to gain read/write access to main memory, bypassing the CPU. Counterfeit hardware running arbitrary code that has Direct Memory Access can do anything . Its much worse than running an arbitrary binary on the Operating System. If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk!

>If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk! Undoubtedly, what is IMHO missing is any proof that the counterfeit hardware (besides being likely of inferior quality) is actually running arbitrary software.

And thats the challenge, you can't ever really know that the firmware, or even the logic implemented in silicon is identical. You don't need evidence that it is different, it is impossible to know, one must assume it could be, thus a security risk.

Re: Identifying Risky Counterfeit Intel Gigabit CT Network Adapters

#20
post #17

Earlier quoted context omitted.

A PCI express card can use Bus Mastering to gain read/write access to main memory, bypassing the CPU. Counterfeit hardware running arbitrary code that has Direct Memory Access can do anything . Its much worse than running an arbitrary binary on the Operating System. If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk!

>If you accept that running random binaries is a security risk, than running counterfeit hardware that runs arbitrary software is a greater risk! Undoubtedly, what is IMHO missing is any proof that the counterfeit hardware (besides being likely of inferior quality) is actually running arbitrary software.

A good risk assessment starts by evaluating possible attack vectors before they’re exploited. If you wait until they’re actively exploited, you might find yourself dealing with an incident response instead.

Another big component of risk is trustworthiness. You might evaluate a vendor’s reputation, test/qa processes, support channels, and the legal environment they operate in. If you don’t even know who the vendor is, that’s a big barrier to establishing much trust.

Post reply on HN