Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

151–160 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#151

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. This is one of the big reasons that Apple locked down its Lightning/USB ports so hard. There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems. It was a huge topic i…

> There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems.

I think you're conflating two separate issues. IIRC, I think the exfiltration concerns were more for "in place" chargers at places like airports. There's definitely a separate retail "fake Apple charger" problem, but that has more to do with safety and quality control.

It wouldn't make much sense for a retail fake Apple charter to have exfiltration circuitry, because then you run into the problem of how to exfiltrate some rando's data from some random charter. Also I'm guessing that stuff would be expensive. It really only makes sense to me for a thing like that to be a targeted attack (e.g. swap out some research scientist's charger at a conference, and place an exfiltration receiver near his hotel room).

> I even have a few "data condoms" leftover from those years. (If you don't remember, they're little dongles you put between your USB cable and the USB charger that only have the power lines connected.)

Those are useful for other things. For instance, I have some devices that deactivate and switch to transfer mode when they connect to data, so I use those for charging those devices while I'm still using them. Also, I think they can allow faster charging from a data-enabled port in some cases.

Re: We purchased a machine from China and it came with malware preinstalled

#152
post #126

20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. How it was discovered. We put a card on listening/prem mode and mirror everything for that subnet the printer was on. I thought I screwed it up with the double mirror/traffic. when investigating why the issue, we found nothing wrong with the config, only when we plu…

Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack.

If it was a multi-function printer with email capability, then yes it would need to have internet access. Or because it was 20 years ago and printers being hacked was a very low security concern.

Re: We purchased a machine from China and it came with malware preinstalled

#154
post #76

Earlier quoted context omitted.

If you buy a Sony product made in Thailand, what protects you from encountering crap like in the article is not that it's made in Thailand instead of China, but that Sony has a reputation to protect and the expertise to do proper quality control. If you buy stuff directly from a Thai company that you never heard of before just because their product was the cheapest, you'll have to do your own testing and will likely…

A lot of Chinese company owners have moved production to Vietnam, Thailand. Laos, Cambodia, Indonesia, etc., specifically because they are aware of this changing preference in the West. Chinese owned business is not China-based business, but most Chinese-owned businesses are subject to CCP influences. As you pointed out: manufacturing standards vary factory to factory and region to region, and quality issues abound i…

There's another, more capitalist reason: wages in most of those countries are lower than wages in China. It's not because of "changing preference".

Re: We purchased a machine from China and it came with malware preinstalled

#155

Earlier quoted context omitted.

You know what? I don't care anymore. When this type of thing happens it's almost always China. Whether it's intentional malware or a lack of QA, how could one tell? They have such a reputation for both I don't know why we still let their electronics into our countries.

it's because chinese goods are consistently good that anything bad is news. ironic isn't it literally everything is made in china, if the quality is as bad as you say the world would have fallen apart. It seems critical thinking is rare among news outrage these days. The same comments were said of Japanese products back in the day, "IP thieves", "shitty quality", and here we are decades later praising Japanese produc…

> literally everything is made in china, if the quality is as bad as you say the world would have fallen apart.

And that's why nowadays things like washing machines and refrigerators which used to last decades now break within the first year or two.

> The same comments were said of Japanese products back in the day, "IP thieves", "shitty quality", and here we are decades later praising Japanese products. Its hilarious at this point.

But these stereotypes lasted only for a decade tops! I have not seen the same commitment to quality that Japanese brands produced. I believe it is a cultural difference, Japanese take great pride in workmanship.

Re: We purchased a machine from China and it came with malware preinstalled

#156

20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. How it was discovered. We put a card on listening/prem mode and mirror everything for that subnet the printer was on. I thought I screwed it up with the double mirror/traffic. when investigating why the issue, we found nothing wrong with the config, only when we plu…

> anytime someone says china doesn't steal technology Does anyone believe that any non-CCP actors are disputing China’s ongoing, massive, organized trade secret theft?

I do. Highly effective propaganda has associated the facts around Chinese trade secret stealing with claims of racism and general xenophobia. As a result, now you have plenty of individuals all over the world whose moral compass pushes them to ignore the facts around trade secret stealing and even go dispute them in online conversations.

Re: We purchased a machine from China and it came with malware preinstalled

#158

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. This is one of the big reasons that Apple locked down its Lightning/USB ports so hard. There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems. It was a huge topic i…

in ~2005 whilst I was the IT manager at Lckheed Martin's RFID division - we were implementing TLS on Exchange for all email... among other security measures...

We had a compromised machine (linux) and had to un-plug it...

BUT

On the security calls was an interesting conversation about the Chinese infiltration of Lockheed.

Lockheed, had at the time, only (3) three egress connects to the internet.

The chinese did the following:

1. They did phishing attacks on those who worked at Lockheed + plus their orbit who attended various conferences and events... giving them seemingly valid contact info (business cards and such) of their agents who also attended said events.

2. Would email the Lockheed Targets and in the emails contain links to military phishing links which would install malware on said target's machine...

3. Would trickle out data so as not to be exposed...

4. Would attack known international suppliers of Lockheed's sub-components through air-gap measures (meaning that Lockheed epoxied USB ports in machines and suppliers were (ironically) then required to transfer data via USB sticks... and China was infecting the machine which the supplier was loading the USB sticks with such to infect Lockheed employees once they received and connected said sticks...

How this was discovered:

Lockheed employees bitches about machine being slow. Investigation ensues and the trickle malware is discovered;

The chinese know they have been discovered and they open the floodgates on all their bots within Lockheed...

HUGE firehose...

Lockheed had to shut down all three egress until resolution...

Yeah, china is in EVERYTHING.

Re: We purchased a machine from China and it came with malware preinstalled

#159
post #126

Earlier quoted context omitted.

Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack.

If it was a multi-function printer with email capability, then yes it would need to have internet access. Or because it was 20 years ago and printers being hacked was a very low security concern.

Use a mail relay instead of directly connecting to the internet.

Re: We purchased a machine from China and it came with malware preinstalled

#160
A decade ago, an article [1] was published in the Russian "Hacker" magazine where the author alleged that a Russian OEM manufacturer's motherboard sourced from China had a BMC chip (which should've been disabled as per the mobo spec) inject a hypervisor into the host machine.

It was, again, allegedly, discovered because the author was developing some kind of distributed computing software that required a hypervisor of its own, and this exact mobo was crashing in a way that was consistent with a hypervisor being already present. The author goes further to describe how he devised a way to consistently detect hypervisors by measuring platform register access timings, and tried to report the findings to the FSB (Russian CIA/FBI) to no avail.

I personally don't put much stock in the story, as the magazine was a rag and I could come up with something like that at the time, but there it is.

[1] https://xakep.ru/2011/12/26/58104/

Post reply on HN