Live data from Hacker News

FTDI driver kills fake FTDI FT232s

eevblog.com

91–100 of 315 posts

Re: FTDI driver kills fake FTDI FT232s

#91
post #19

I hope this causes a major and publicly visible malfunction in some important device/installation/machinery, of course with no harm done to any persons, but enough of an embarrasment to really set an example, so no vendor will think of pulling tricks like these in the future. Takeaway lesson: End users should never touch anything remotely FTDI-like, since it's probably impossible to verify if the device is genuine or…

I hope this causes a major and publicly visible malfunction in some important device/installation/machinery, of course with no harm done to any persons

I actually hope that this does cause an event drastic enough so that FTDI will have blood on its hands that ends in jail time for management and engineers. I don't want to see anyone hurt, especially not innocent third parties, but fuck FTDI, fuck the management who ordered this, and fuck the engineer(s) who didn't quit in protest. I'm not easily offended, but as a programmer who has been responsible for code that would result in loss of life if I made it defective by design, I have no sympathy for this sort of thing. One other thing that I could hope for is that this teaches everyone the true cost of closed source, especially drivers. Don't put up with it.

Re: FTDI driver kills fake FTDI FT232s

#92
post #72

Earlier quoted context omitted.

They may not be WHQL certified, per Wikipedia: > A company can choose to sign their own drivers rather than go through the WHQL testing process. These drivers would not qualify for the "Certified for Windows" logos, but they would install on 64-bit versions of Windows and install without a warning message on 32-bit versions of Windows Vista or Windows 7. However, it will not install without a warning message on Windo…

But they are pushed through Windows Update? Doesn't everything there have to be WHQL?

Correct. To use the non-MSFT signed approach, the driver has to add the cert to the registry beforehand somehow (eg. using certutil -addstore -f TrustedPublisher), which obviously rules out a straight install using Windows Update.

Re: FTDI driver kills fake FTDI FT232s

#93
post #80
post #7

FTDI have been anti-consumer for years - their last several drivers have introduced intentional instability and Code 10 errors for suspected counterfeit devices. I think this is totally crappy. I see what they're trying to do (create market incentive for consumers to insist on real FTDI chips) but the reality is that it's just screwing over innocent consumers who buy a device.

It's not a great situation, but where does FTDI responsibility for supporting counterfeit devices start and end? If they let it continue more devices may hijack their USB VID, perhaps with bugs and glitches. Should they patch their driver to protect their reputation?

Your 'bugs and glitches' strawman is humorous because FTDI intentionally introduced bugs and glitches with the counterfeit devices, so they're certainly not trying to protect their reputation, just their profits.

FTDI's responsibility for supporting counterfeit devices ends a long way before tampering with them.

I think the moral high road to take in this situation would be to ignore the clones, but failing that, the approach which Prolific have taken (make the driver refuse to start on a known counterfeit device) seems a lot better than intentionally introducing bugs and not completely ludicrous like damaging the hardware.

Re: FTDI driver kills fake FTDI FT232s

#94

Microsoft should revoke the driver's signature via their next CRL update, so that it refuses to install (effectively making the drivers unsigned). It is acting maliciously and will break consumer's hardware, even hardware which doesn't contain any FTDI chips. If FTDI have an issue with a company ripping off their IP then go sue that company. But what they're doing is catching consumers in the firing line, who will wi…

I'm sure you realize that the counterfeiters operate in such a fashion and in regions of the world that make sueing them impossible. Which suck because it means FTDI really has no options to enforce their IP rights that don't hurt consumers.

Re: FTDI driver kills fake FTDI FT232s

#95
I think FTDI might be shooting themselves in the foot here.

Plugging in a USB is messy, and you will sometimes get an "Unrecognized Device" error, which you simply fix by unplugging and replugging.

I could see a similar hiccup causing their driver to sometimes "brick" a legitimate device.

Then this false positive ripples back to a manufacturer who bought 50,000 of those chips on the last run, and thinks they might all be fake...

It turns everything into a huge mess.

Very poor management decision, and shame on the engineers for implementing it.

Re: FTDI driver kills fake FTDI FT232s

#96
post #94

Microsoft should revoke the driver's signature via their next CRL update, so that it refuses to install (effectively making the drivers unsigned). It is acting maliciously and will break consumer's hardware, even hardware which doesn't contain any FTDI chips. If FTDI have an issue with a company ripping off their IP then go sue that company. But what they're doing is catching consumers in the firing line, who will wi…

I'm sure you realize that the counterfeiters operate in such a fashion and in regions of the world that make sueing them impossible. Which suck because it means FTDI really has no options to enforce their IP rights that don't hurt consumers.

... thus they have moral right and obligation to damage the hardware belonging to other people because some other people don't recognize their "IP rights"?

What's you point here?

Re: FTDI driver kills fake FTDI FT232s

#97
post #94

Microsoft should revoke the driver's signature via their next CRL update, so that it refuses to install (effectively making the drivers unsigned). It is acting maliciously and will break consumer's hardware, even hardware which doesn't contain any FTDI chips. If FTDI have an issue with a company ripping off their IP then go sue that company. But what they're doing is catching consumers in the firing line, who will wi…

I'm sure you realize that the counterfeiters operate in such a fashion and in regions of the world that make sueing them impossible. Which suck because it means FTDI really has no options to enforce their IP rights that don't hurt consumers.

Nobody would fault FTDI for releasing new drivers that don't work with counterfeit parts.

That alone would cause enough inconvenience to manufacturers to make sure they use legitimate parts.

It's the (unethical) bricking of the parts that has everybody up in arms.

Re: FTDI driver kills fake FTDI FT232s

#99
post #19

I hope this causes a major and publicly visible malfunction in some important device/installation/machinery, of course with no harm done to any persons, but enough of an embarrasment to really set an example, so no vendor will think of pulling tricks like these in the future. Takeaway lesson: End users should never touch anything remotely FTDI-like, since it's probably impossible to verify if the device is genuine or…

Basically all vendors outsource production. Very few vendors will knowingly put a fake chip in their product, the trick is pulled by someone closer to manufacturing, either to cut costs or to try and ship earlier in case the original chip is hard to get right now.

I doubt very few vendors will realize if a fake FTDI chip is part off their manufactured product even after rigorous testing since the functionality is correct (until you get this driver).

EDIT: I doubt FTDI have thought this through. I will share this with the hardware designers I know and most will probably react like on the linked thread, and just switch to another chip to avoid any possible hassle.

Re: FTDI driver kills fake FTDI FT232s

#100
post #94

Microsoft should revoke the driver's signature via their next CRL update, so that it refuses to install (effectively making the drivers unsigned). It is acting maliciously and will break consumer's hardware, even hardware which doesn't contain any FTDI chips. If FTDI have an issue with a company ripping off their IP then go sue that company. But what they're doing is catching consumers in the firing line, who will wi…

I'm sure you realize that the counterfeiters operate in such a fashion and in regions of the world that make sueing them impossible. Which suck because it means FTDI really has no options to enforce their IP rights that don't hurt consumers.

FTDI is almost certainly trying to exercise IP rights that don't actually exist, because breaking other people's stuff is not an authorized method for dealing with trademark infringement.
Post reply on HN