Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

21–30 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#22
post #15

Given that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.

A bit off topic, but the last time I needed a Windows laptop for business reasons (a long time ago) I bought a laptop directly from Microsoft and it appeared to be secure and also not loaded with advertising junk. The price seemed OK, fairly competitive.

Re: We purchased a machine from China and it came with malware preinstalled

#23
I bought a laptop once. It came with windows pre-installed. And a bunch of bloatware. And 101 things that phoned home under the guise of checking that a driver was up to date. And Norton. The definition of malware is open to large interpretation.

Re: We purchased a machine from China and it came with malware preinstalled

#24
The malware is a cherry on top, but the story before that is pretty awful already, and unfortunately seems to be representative of specialized software like that: proprietary (with constant risk of malware, indeed), awkward, poorly (if at all) documented, likely the protocols to speak to the hardware without it are kept in secret, and occasional shipment of Windows machines where just software would do (but probably it's written to just barely work on a given system, and won't run on others easily).

I think the main and annoying problem is those general practices, not just a single instance of malware.

Edit: Apparently some focus on the "Chinese" part, but I suspect that hardware being specialized and software being shipped by the hardware manufacturer are larger factors here: at least all the awkwardness before the malware part I've observed to be approximately similar with hardware+software produced by Chinese, European, and US companies.

Re: We purchased a machine from China and it came with malware preinstalled

#25
post #4

Is this anything new? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

Do you perhaps have a link about the story of amazon removing the 1984 book on all kindles? It sounds very interesting, partly because it seems so absurd.

Re: We purchased a machine from China and it came with malware preinstalled

#26

Earlier quoted context omitted.

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

Do you perhaps have a link about the story of amazon removing the 1984 book on all kindles? It sounds very interesting, partly because it seems so absurd.

https://www.pcworld.com/article/519855/amazon_kindle_1984_la...

That story is about a lawsuit from one of the people they took it from.

Amazon sold 1984 on the Kindle store without permission, and when they realized their error they deleted it from everyone's kindle and refunded their money.

Re: We purchased a machine from China and it came with malware preinstalled

#27

The story here is not the fact of the malware - it is the purpose of the malware: industrial espionage. China is well-known in industry for its sheer volume and brazenness of industrial espionage. A pick-and-place machine is especially well placed for this since it will, by necessity, have access to PCB designs and BOMs.

I have seen enough stories of supply-line sabotage to think that if you are going to build your infrastructure with Chinese hardware, air-gapping it is a necessity.

Probably a good idea to air-gap your pick and place machine even if it is not Chinese.

Re: We purchased a machine from China and it came with malware preinstalled

#28

Earlier quoted context omitted.

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

Do you perhaps have a link about the story of amazon removing the 1984 book on all kindles? It sounds very interesting, partly because it seems so absurd.

Here's a writeup [1]. A third party started selling kindle editions of 1984 and Animal Farm through Amazon despite not having any rights to do so. When they found out (presumably the rights holders complained), Amazon deleted the unauthorized editions.

[1] https://gizmodo.com/amazon-secretly-removes-1984-from-the-ki...

Re: We purchased a machine from China and it came with malware preinstalled

#29
I've bought systems off of Amazon that had pirated Windows licenses on them (otherwise a great little fanless box)

In a previous life I was an infosec consultant. We did some work for a hospital that found malware on the control hosts shipped with a brand new turnkey MRI system from a German manufacturer.

Re: We purchased a machine from China and it came with malware preinstalled

#30
The malware analysis report they've ordered (https://www.rmcybernetics.com/files/pdf/Malware-analysis-Fly...) is extremely light on details.

Yes, some things look suspicious (packing, lack of signatures, hardcoded IP addresses/hostnames, network traffic) - but I'm not seeing any clear-cut evidence that this is malware?

Post reply on HN