Live data from Hacker News

FTDI removes counterfeit-bricking driver from Windows Update

eevblog.com

111–120 of 131 posts

Re: FTDI removes counterfeit-bricking driver from Windows Update

#111

Earlier quoted context omitted.

In the US there isn't a legal way to purchase counterfeit goods. It may be different in other countries. Similar to stolen property, the person left holding the bag gets in trouble too. Edit: after actually looking up the issue instead of guessing it turns out that in most places (other than France and Italy) there isn't much at stake for the end user, and almost all of the laws are written to stop the sale or manufa…

It is however perfectly legal to make a hardware device that could make use of the Same API and driver i.e a clone. Provided it is not branded as a FTDI chip, but rather "FTDI Driver compatible" Now that may violate the terms and lic of the driver software on windows (not on linux because it is GPLv2) but that would not make it illegal to buy nor would it give them (FTDI) the legal right to modify that hardware

Using the FTDI vendor ID is branding it as an FTDI product. I would argue that it is even more important than the text printed on the chip since that is the part of the brand that the average end user is exposed to.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#112
post #109

Earlier quoted context omitted.

Do we have evidence FTDI was in fact making the counterfeits randomly fail on purpose, separate from this bricking thing? Hanlon's Razor is still worth thinking about. For example I have a Prolific chip that is almost certainly a fake that only works with driver X.Y.Z, I always assumed that was because the fakers targeted that driver and made an imperfect spoof.

The Prolific counterfeit protection is documented as being explicit (and not the result of an accidental incompatibility): Prolific introduced a check in later drivers which requires a specific response the fakes didn't implement. http://dreamlayers.blogspot.com/2011/10/pl-2303-code-10-erro... Thankfully, Prolific chose to simply prevent their drivers from starting with an easy-to-Google code, rather than causing fru…

Fairly damning, thank you.

Coincidentally, PL-2303 sounds like chip model I have from Prolific.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#113
post #84

Earlier quoted context omitted.

Not entirely sure what your argument was here, you sort of drifted into the weeds a bit. I think you meant to argue: "There is one source of media coverage, although it's largely just twitter comments. And just because something is difficult to prove doesn't mean it's not provable." Both are valid arguments. I don't count ZDnet as a very credible source of news, and in this case, some googling seems to show they are…

Check other posts on this HN story; others have proven the drivers were deliberately malicious by analyzing either a USB stream or a driver disassembly (I haven't read enough to know which).

It was USB stream.

The problem isn't knowing the driver itself can cause a bricked chip and therefore bricked device.

The problem is Joe-Average isn't going to be able to prove it was this driver and not just a defective device/chip for another reason. Even with a free "testing" tool someone can make to check for the flipped PID bit, Joe-Average has no clue this is even going on, and is likely to just throw away his bricked device.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#114

Earlier quoted context omitted.

But that's impossible for something like a Windows driver to determine. The only way the FTDI driver could determine if the chip counterfeit was a slight difference in how the counterfeit chips handled a certain EEPROM write. And the counterfeiters will be sure the next revision of the chip takes care of this corner case.

Sure, the driver doesn't know the manufacturing process. His point is the chips are simply so different, there are bound to be obvious ways for the driver to tell.

If the chip manufacturer needed this incredibly subtle trick to determine a real chip from a fake at the driver level, what does that say about how close the counterfeiters got?

The chip dies may be incredibly different, but the fake operated 99.99% like the real one. There were no "obvious ways" to tell them apart.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#115
post #25

It's interesting watching this play out with reputable, legal companies. Something similar happened earlier in the year with Nintendo 3DS flashcards, however the software was not just disabling the flashcard, but would brick the users 3DS. Their response was essentially, "Yeah? What are you going to do about it?" and promising to replace the 3DS of anyone who could prove they were using a legitimate card.

Few will be surprised if prosecutors are found to care more about shenanigans in the MS-Win ecosystem than those in the Nintendo ecosystem. Actually FTDI may be in more danger from class action tort lawyers. This is almost a perfect class for them, in that lots of people suffered a limited but not negligible harm.

Correct. Most arguments seem to assume that FTDI is either 100% responsible for damaging hardware that doesn't belong to them, or 0% responsible. Clearly the company itself assumed the latter position would prevail in each and every jurisdiction where people use computers. I don't know what sort of drugs they had to take to arrive at that conclusion, but I don't want any, thanks.

One big problem is that civil courts in the US do not work that way at all. FTDI could easily be found 5% responsible for an enormous judgement.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#116
post #7

There should be lawsuits. I really hope a class action gets started with people who were bitten by this. I'm serious. This kind of behavior needs to be nipped in the bud and made a massive example of, or else we will see it in the future.

We do not want to set a precedent whereby a company responds to customer feedback, and then gets hit by a huge lawsuit anyhow. That just incentivizes companies to dig their heels in, because it means there's no change in outcome between speedily responding and trying to stay the course, at which point staying the course is the only sensible choice. There's a time and a place for mercy, and giving positive feedback to…

"Act first and apologize later" is a bad idea when your actions affect large numbers of uninvolved parties.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#117
post #30

Earlier quoted context omitted.

No, but suppose this was another scenario, such as automatic product bagger/sealers and some counterfeit part was being bricked by the original manufacturer. I doubt anyone outside of the warehouse/manufacturing industry would care, nor would anyone outside that industry have any real right to care. In the FTI situation, I'm indifferent, but I just don't like the "crowd mentality" thing where people get stirred up ab…

The company I work for uses (genuine) FTDI USB-Serial converters in our $500,000 medical instruments. I have full confidence in our Supply Chain Management people, but mistakes happen. If we were to send out a field upgrade to the instruments, as happens periodically, and some of them had the counterfeit chips, then suddenly there are patients all over the world, many in Emergency Rooms or Intensive Care, that can't…

The scenario you present is a little "doomsday". You'd have to replace all of your deployed product's chips with cheap counterfeit ones for this to happen -- and you say you have complete confidence in your supply chain.

My warehouse has a couple Sharp Max baggers w/ counter and sorter, which are just as expensive as your medical instruments. The electronics check to ensure you are using only the Sharp brand parts, otherwise the machine refuses to work.

Most printer cartridges won't work in printers unless they are the name-brand cartridge (printers read the chip on the cartridge).

Neither permanently damage the counterfeit parts, but it doesn't matter much if you can't use the counterfeit part you just bought (thinking you were going to save a buck or two).

Frankly, I don't buy the argument that a lot of users didn't know they had bought counterfeit. For a device that retails for $15 and you got it new for $1.50, well, something is up.

Perhaps a better way for FTI to go would be to detect the counterfeit when it's plugged in, then just refuse to do anything with it. (although this would allow someone to get a non-FTI driver to work)

Re: FTDI removes counterfeit-bricking driver from Windows Update

#118
post #117

Earlier quoted context omitted.

The company I work for uses (genuine) FTDI USB-Serial converters in our $500,000 medical instruments. I have full confidence in our Supply Chain Management people, but mistakes happen. If we were to send out a field upgrade to the instruments, as happens periodically, and some of them had the counterfeit chips, then suddenly there are patients all over the world, many in Emergency Rooms or Intensive Care, that can't…

The scenario you present is a little "doomsday". You'd have to replace all of your deployed product's chips with cheap counterfeit ones for this to happen -- and you say you have complete confidence in your supply chain. My warehouse has a couple Sharp Max baggers w/ counter and sorter, which are just as expensive as your medical instruments. The electronics check to ensure you are using only the Sharp brand parts, o…

Steep discounts for volume are the norm. Its arguable that the consumer doesn't know nor care why the discount; as long as the vendor/product passes a qualification test.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#119
post #7

There should be lawsuits. I really hope a class action gets started with people who were bitten by this. I'm serious. This kind of behavior needs to be nipped in the bud and made a massive example of, or else we will see it in the future.

We do not want to set a precedent whereby a company responds to customer feedback, and then gets hit by a huge lawsuit anyhow. That just incentivizes companies to dig their heels in, because it means there's no change in outcome between speedily responding and trying to stay the course, at which point staying the course is the only sensible choice. There's a time and a place for mercy, and giving positive feedback to…

Given their initial reactions on Twitter, I don't feel bad if they get taken to court over this. As others have mentioned, they only agreed to rapidly reverse course after Microsoft put them in time out.

Re: FTDI removes counterfeit-bricking driver from Windows Update

#120
post #44

Their best course of action: - unbrick devices they bricked, so the chips will at least work with drivers other than theirs - log something to the windows event log about a clone device being detected It's their choice whether they should work with the clone device or not; I would hope they would choose to. I understand their reluctance, but people are going to be only slightly less mad about a device not working tha…

Windows drivers can opt to mark the device they are responsible for as "non operational".

https://en.wikipedia.org/wiki/Device_Manager#Error_Codes

I think it's the #43 I've seen from time to time: "Windows has stopped this device because it has reported problems."

http://technet.microsoft.com/en-us/library/cc725873(v=ws.10)...

They get a special icon in "Device Manager", and, if I remember right, the statusbar-thingie that dances around while newly-connected devices are detected will put up a bubble with an error message.

Post reply on HN