Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

171–180 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#171
post #126

Earlier quoted context omitted.

Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack.

>> 20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. > Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack. Aren't most network printers connected to office networks with public internet access? I sounds like this printer was making outgoing connections, and…

It doesn’t take long as a system administrator to become certain that printers are working against you. By and large they have user hostile hardware and software.

Re: We purchased a machine from China and it came with malware preinstalled

#172
post #89

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

I bought a bluetooth dongle on Amazon recently. didn't work out of the box, and the instruction booklet told me I had to download and install an unsigned device driver that I should download from a specific dropbox link. I tried to write a measured review on Amazon explaining the problem, but Amazon rejected the review. I threw it away and composed an angsty tweet [1], but I really should have returned it. [1] https:…

> I tried to write a measured review on Amazon explaining the problem, but Amazon rejected the review.

This facet of the Big Tech censorship problem hardly ever gets any attention, but it's no less bad than YouTube and Twitter censoring their political opponents.

Re: We purchased a machine from China and it came with malware preinstalled

#173
post #129

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

Buying from China, as a westerner, is akin to buying the rope that will hang you. Regardless of the quality or price of their products. We should have never allowed them to become this powerful. Their ideology is toxic and incompatible with ours.

"Their ideology is toxic and incompatible with ours."

But it's okay to buy Oil from regimes that kill gay people or cobalt mined by Child slave labour?

Lets place the blame where it actually belongs: our corporations will sell our values, our kidneys and the entire planet down the river id they can. China is just one of the few countries that beat them at their own game.

Re: We purchased a machine from China and it came with malware preinstalled

#174
post #37

I am more than a little concerned that since the miniaturization and commoditization of spy hardware (miniature microphones, cameras, and wireless communication), that run-of-the-mill consumer electronics are being bugged by default. Given the cost is pennies or just a couple dollars, from an espionage perspective, it'd be worth it to spend a few hundred million or even billion putting bugs into literally everything…

This has already happened: smartphones and wifi. People financed it themselves by buying the things. (Wifi can see you: "The next big Wi-Fi standard is for sensing, not communication" https://news.ycombinator.com/item?id=29901587 )

FWIW, I think whether we build a dystopia or utopia depends on whether or not we can make our rulers live under the same panopticon as the rest of us.

Re: We purchased a machine from China and it came with malware preinstalled

#176

Earlier quoted context omitted.

>> 20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. > Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack. Aren't most network printers connected to office networks with public internet access? I sounds like this printer was making outgoing connections, and…

It doesn’t take long as a system administrator to become certain that printers are working against you. By and large they have user hostile hardware and software.

> By and large they have user hostile hardware and software.

Eh, typical "user hostile hardware and software" is not even in the same league as exfiltrating your data to an adversary.

Re: We purchased a machine from China and it came with malware preinstalled

#177

20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. How it was discovered. We put a card on listening/prem mode and mirror everything for that subnet the printer was on. I thought I screwed it up with the double mirror/traffic. when investigating why the issue, we found nothing wrong with the config, only when we plu…

It's fair play to act like any gov is doing this.

E.G: Microsoft being American (and them being part of PRISM), I just assume the OS has a backdoor for the US gov. Now with Windows 10 heavy telemetry, it's even easier.

I work for a client doing chips for credit cards. Did you know they are now full blown computers that can run a light version of Java (Java Card) ? The company is building their own hardware and software, and just to get to a conference room, you need biometric access + badge + pin code. Pretty sure they send data to my country agencies in some way despite having to trick the banking system to do so for them.

Same from any software, server/cloud hosting or hardware. If it comes from a specific country, this country is most probably using it for intelligence. It doesn't even need to be on a network now, because there is so much interactivity with all devices. And eventually, one will be.

Re: We purchased a machine from China and it came with malware preinstalled

#178
post #126

Earlier quoted context omitted.

Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack.

>> 20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. > Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack. Aren't most network printers connected to office networks with public internet access? I sounds like this printer was making outgoing connections, and…

20 years ago I would have expected that most printers were connected to a parallel or serial port on a PC and any network printing functions would be handled by the PC. But then I think, wait, that was the year 2002 (which seems like yesterday when I say it) so maybe printers with direct network connections were pretty common then. My sense of the passage of time has really gotten compressed as I get older.

Re: We purchased a machine from China and it came with malware preinstalled

#179

Earlier quoted context omitted.

I very rarely write negative reviews, but every time I have was for something of this magnitude and not once has any ever been left up on any platform.

Same. What I don't get is that on Amazon I've purchased 10's to 100's of thousands in product (was an early user, business account admin etc). Of all the reviews that SHOULD have credibility, someone who doesn't review a lot and buys a TON of product - you think would be slightly credible? Instead, for those (few) times I've posted a clearly negative review - gone for whatever reason. If you buy enough from Amazon, e…

I canceled Prime and stopped buying stuff on Amazon over 3 years ago for these sort of reasons. You cannot trust the product descriptions, you cannot trust the reviews, and you cannot trust that what you actually get is the same thing you thought you were buying.

Re: We purchased a machine from China and it came with malware preinstalled

#180

20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. How it was discovered. We put a card on listening/prem mode and mirror everything for that subnet the printer was on. I thought I screwed it up with the double mirror/traffic. when investigating why the issue, we found nothing wrong with the config, only when we plu…

Printers are a huge attack vector that often go unnoticed by less competent IT folk. This is one reason why I try to avoid hardware from mainland companies like lenovo. Not that you can avoid it entirely but I try.
Post reply on HN