Live data from Hacker News

FTDI driver kills fake FTDI FT232s

eevblog.com

71–80 of 315 posts

Re: FTDI driver kills fake FTDI FT232s

#71
post #47

Earlier quoted context omitted.

There are a variety of laws that would apply here, and doing what they did, if done intentionally, is almost certainly cause for civil liability. They are not allowed self-help in the form of destroying other pieces of hardware. If they have a problem with counterfeit chips, the solution is customs/legal process/etc If they aren't happy with what that buys them, they should be pushing for legal change.

It's quite possibly a violation of U.S. Code 1030(a)(5)(A), a federal felony: (5) (A) [Whoever] knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; Now "protected computer" and the [ab]use of the Interstate Commerce Clause mean that the device with the FTDI would likely need to be co…

FTDI is not a US company.

Re: FTDI driver kills fake FTDI FT232s

#72
post #57

Earlier quoted context omitted.

Isn't the WHQL process supposed to vet for malware like this?

They may not be WHQL certified, per Wikipedia: > A company can choose to sign their own drivers rather than go through the WHQL testing process. These drivers would not qualify for the "Certified for Windows" logos, but they would install on 64-bit versions of Windows and install without a warning message on 32-bit versions of Windows Vista or Windows 7. However, it will not install without a warning message on Windo…

But they are pushed through Windows Update? Doesn't everything there have to be WHQL?

Re: FTDI driver kills fake FTDI FT232s

#73
post #48

Earlier quoted context omitted.

No, that's not the case here. Fake FTDI chips are going to be used in absolutely everything, products from Alibaba to name brand professional stuff. It's pretty much guaranteed not everybody has complete control of their semiconductor supply chain, and even if they do there's an incentive for all companies to cut costs where they can. A consumer buying a product doesn't make an informed decision about the type of ser…

It shares the critical element of diffuse responsibility . Everyone can half-reasonably shrug their shoulders and say, "Well it isn't MY fault". If a Sony product happens to have a fake FTDI chip in it, this is FTDI's way of incentivizing Sony (via angry customers) to manage their supply chain, because as you say there's an incentive even for Sony to cut costs where they can- perhaps by turning a blind eye when they…

> Everyone, in demanding the lowest price no matter what (all the way up the supply chain) bears part of the blame.

Your use of the word "blame" implies that you think there's some wrongdoing on the part of someone other than FTDI. As far as I can see, there's absolutely nothing wrong with the production and use of these clone chips except that they are being labeled with FTDI's trademark. They're piggybacking on FTDI's software work, but that's nothing that the government has an interest in stopping. If FTDI doesn't like people using their software without buying their hardware, they can resort to more traditional means like not giving out their software so freely or including DRM.

Re: FTDI driver kills fake FTDI FT232s

#74
post #64

Earlier quoted context omitted.

As a consumer I have no way to know if the FTDI in my device is real. It really isn't my fault. This is FTDI's way of incentivizing companies using consumers, like I said in my original comment, and it sucks .

As a consumer I had no way of knowing the motorcycle I bought was stolen. It came with the keys, the title, there was no evidence of thievery (most commonly broken parts around the ignition). The police said, "Wow we wouldn't have known this was stolen without running it in our database either". I didn't know. But it still gets repossessed, and I'm still out $1k. (True story, and my first brush with the laws around b…

These FTDI fakes aren't stolen, though. There is a massive difference between stolen, counterfeit, and clone. If the chips are only sold as "FTDI-compatible", then I would even say they should be completely legit, like Dalvik vs. Java.

Re: FTDI driver kills fake FTDI FT232s

#75
post #64

Earlier quoted context omitted.

As a consumer I have no way to know if the FTDI in my device is real. It really isn't my fault. This is FTDI's way of incentivizing companies using consumers, like I said in my original comment, and it sucks .

As a consumer I had no way of knowing the motorcycle I bought was stolen. It came with the keys, the title, there was no evidence of thievery (most commonly broken parts around the ignition). The police said, "Wow we wouldn't have known this was stolen without running it in our database either". I didn't know. But it still gets repossessed, and I'm still out $1k. (True story, and my first brush with the laws around b…

If the person from whom the motorcycle was stolen discovered one night that it was at your house and just took it back, they would be committing a crime. Even though the motorcycle was rightfully theirs, there is a procedure to go through to get it back. Simply showing up and taking it back is a form of vigilantism. What FTDI is doing is also a form of vigilantism.

Re: FTDI driver kills fake FTDI FT232s

#76
post #54

Does anyone know of good FTDI alternatives? Are there any clone makers that are relatively legit (i.e. they put their actual brand name on the chip, they support drivers, etc)? At $4.50 a pop for bog-standard bit-banging in a day and age where you can get ARM M4 SoCs for $2.75 a pop (n=1 prices) I would think FTDI would have more above-the-table competition than they do. Is the subterfuge required for illegitimate cl…

FTDI's major advantage is that their WHQL'd drivers are already installed with Windows. That's why people build chips to the same API.

Ah, that makes sense. The "right" answer would probably be to convince the USB-IF to standardize the interface. FT232 and FT245's popularity should be argument enough that it's worth doing. I have no idea how politically viable that would be.

EDIT: looks like they did standardize a USB-to-serial device class [1]. Maybe they just need to update it?

[1] http://www.atmel.com/Images/doc4322.pdf

Re: FTDI driver kills fake FTDI FT232s

#77
post #64

Earlier quoted context omitted.

As a consumer I have no way to know if the FTDI in my device is real. It really isn't my fault. This is FTDI's way of incentivizing companies using consumers, like I said in my original comment, and it sucks .

As a consumer I had no way of knowing the motorcycle I bought was stolen. It came with the keys, the title, there was no evidence of thievery (most commonly broken parts around the ignition). The police said, "Wow we wouldn't have known this was stolen without running it in our database either". I didn't know. But it still gets repossessed, and I'm still out $1k. (True story, and my first brush with the laws around b…

Except in this analogy, someone sold you a Ducati with Pirelli tires that happened to be counterfeit. And suddenly Pirelli shows up and torches your bike because someone used a tire that had their logo.

Edit: Apparently I don't proof-read

Re: FTDI driver kills fake FTDI FT232s

#78
post #47

Earlier quoted context omitted.

It's quite possibly a violation of U.S. Code 1030(a)(5)(A), a federal felony: (5) (A) [Whoever] knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; Now "protected computer" and the [ab]use of the Interstate Commerce Clause mean that the device with the FTDI would likely need to be co…

FTDI is not a US company.

But Future Technology Devices International Limited (USA) is. http://www.ftdichip.com/FTContact.htm

Re: FTDI driver kills fake FTDI FT232s

#79
post #47

Earlier quoted context omitted.

There are a variety of laws that would apply here, and doing what they did, if done intentionally, is almost certainly cause for civil liability. They are not allowed self-help in the form of destroying other pieces of hardware. If they have a problem with counterfeit chips, the solution is customs/legal process/etc If they aren't happy with what that buys them, they should be pushing for legal change.

It's quite possibly a violation of U.S. Code 1030(a)(5)(A), a federal felony: (5) (A) [Whoever] knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; Now "protected computer" and the [ab]use of the Interstate Commerce Clause mean that the device with the FTDI would likely need to be co…

Was the driver pushed out by Windows Update from WHQL? That's via a network.

Re: FTDI driver kills fake FTDI FT232s

#80
post #7

FTDI have been anti-consumer for years - their last several drivers have introduced intentional instability and Code 10 errors for suspected counterfeit devices. I think this is totally crappy. I see what they're trying to do (create market incentive for consumers to insist on real FTDI chips) but the reality is that it's just screwing over innocent consumers who buy a device.

It's not a great situation, but where does FTDI responsibility for supporting counterfeit devices start and end?

If they let it continue more devices may hijack their USB VID, perhaps with bugs and glitches. Should they patch their driver to protect their reputation?

Post reply on HN