Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

211–220 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#212

Earlier quoted context omitted.

It's fair play to act like any gov is doing this. E.G: Microsoft being American (and them being part of PRISM), I just assume the OS has a backdoor for the US gov. Now with Windows 10 heavy telemetry, it's even easier. I work for a client doing chips for credit cards. Did you know they are now full blown computers that can run a light version of Java (Java Card) ? The company is building their own hardware and softwa…

It's pretty absurd to both sides something like this. Do you have evidence that the US government is doing this on computers it sells overseas, or is this just magical speculation?

Around the time of the snowden leaks we learned that the NSA was installing backdoors on Cisco firewalls bound for foreign countries.

https://en.wikipedia.org/wiki/Cisco_Systems#Firewall_backdoo...

"A document included in the trove of National Security Agency files released with Glenn Greenwald's book No Place to Hide details how the agency's Tailored Access Operations (TAO) unit and other NSA employees intercept servers, routers and other network gear being shipped to organizations targeted for surveillance and install covert firmware onto them before they are delivered. These Trojan horse systems were described by an NSA manager as being "some of the most productive operations in TAO because they pre-position access points into hard target networks around the world."

Re: We purchased a machine from China and it came with malware preinstalled

#213

Earlier quoted context omitted.

I heard your type of argument about the US mass spying before Snowden, and surprise, we were not conspirationists after all. So call that educated magical speculation.

Well, but correct me if I'm wrong, the Snowden leak included nothing like this. Instead it included a lot of things that would be a lot easier to do if Google/Microsoft ect just gave them access. The very fact they had to do everything else is at least evidence that don't have direct access

It's just different use cases. Backdoors are more useful for targetted operations or specific data exfiltration, while plugging yourself to back bones is more useful for mass surveillance.

I don't even see why it's controversial to hold this opinion. Reading some comments, people seems to feel offended we could think that from the USA.

If anything, the USA are, with Russia and China, among the countries anybody in Europe like me would suspect the most about pulling things like this. The CIA and NSA have a terrible reputation, and the track record to support it.

We are talking about a country that went to war while lying about WMD against the UN vote, made money with south american cocaine while organizing coup after coup, elected Bush and Trump yet punished Chelsea Manning. A country that is still under the temporary 9/11 Patriot act, it used to mass spy on its entire population.

Of course I'm assuming the worse from them.

And yes, it's fair.

Actually, even if I were proven to be completely wrong in 10 years, it still would have been fair.

But I'm not even assuming that only from the US, but basically from any gov, including mine. Because history taught us that's what power does.

It's sane to be suspicious of people in power. Necessary for democracy, even.

Re: We purchased a machine from China and it came with malware preinstalled

#214
post #129

Earlier quoted context omitted.

Buying from China, as a westerner, is akin to buying the rope that will hang you. Regardless of the quality or price of their products. We should have never allowed them to become this powerful. Their ideology is toxic and incompatible with ours.

> We should have never allowed them What does this mean?

The UN was also giving them subsidized shipping rates via the UPU. And as they exploited the subsidies in increasingly-vast numbers, domestic shipping had rates to be increased yet more to compensate. It was cheaper to ship from China than domestically in the US. Basically a tarriff on domestic goods. What do you expect businesses to do? Even if manfacturing wasn't cheaper, it would still be cheaper overall to manufacture there.

Trump finally withdrew from the UPU in 2018 and ended the subsidies.

Re: We purchased a machine from China and it came with malware preinstalled

#215
post #126

Earlier quoted context omitted.

Why was the printer connected to the public internet? A DMZ subnet would have prevented this vector of attack.

I don't think I have ever seen a major US office building where the printers were on an isolated network. They are usually on the same network as the workstations, but sometimes on the server network, so the print server can connect directly to them. And to be honest, (I have been out of it for a few years now) I have yet to see a company block OUTGOING access on a DMZ.

Actually it's pretty common nowadays to have printers on an isolated VLAN. The only way "onto" that network is through a central printing management server that handles billing/accounting and job release duties.

You see it often in Universities, but also in larger businesses where you want to stop someone from accidentally printing 5000 copies instead of 50, or having print jobs stack up on top of each other in the output tray (think HR/sensitive information being scooped up by accident.)

Re: We purchased a machine from China and it came with malware preinstalled

#216

Earlier quoted context omitted.

It's pretty absurd to both sides something like this. Do you have evidence that the US government is doing this on computers it sells overseas, or is this just magical speculation?

I heard your type of argument about the US mass spying before Snowden, and surprise, we were not conspirationists after all. So call that educated magical speculation.

People have a hard time admitting that what Snowden/Assange revealed about the US is much more damning, from infected servers to keyloggers built into USB cables.

I find China is useful as a mirror to the US. If they are doing something problematic, it's highly likely the US gov is too but just hasn't disclosed it to the public.

Re: We purchased a machine from China and it came with malware preinstalled

#217

Earlier quoted context omitted.

I do. Highly effective propaganda has associated the facts around Chinese trade secret stealing with claims of racism and general xenophobia. As a result, now you have plenty of individuals all over the world whose moral compass pushes them to ignore the facts around trade secret stealing and even go dispute them in online conversations.

China is using the US’s Christian sensibilities (charity, forgiveness, etc) against them.

I don't know that it's Christian sensibilities so much as a political view extremely susceptible to this sort of shrewd manipulation. As the person you're responding to said, the smoke screen is to cast criticism of China as racist or xenophobic. They even have a term, "baizuo", to mock this concept: https://en.wikipedia.org/wiki/Baizuo

In general you're right though. They are very successful at using weaknesses against us.

Re: We purchased a machine from China and it came with malware preinstalled

#218

Earlier quoted context omitted.

Same. What I don't get is that on Amazon I've purchased 10's to 100's of thousands in product (was an early user, business account admin etc). Of all the reviews that SHOULD have credibility, someone who doesn't review a lot and buys a TON of product - you think would be slightly credible? Instead, for those (few) times I've posted a clearly negative review - gone for whatever reason. If you buy enough from Amazon, e…

> Product reviews that when you go back to understand how the piece of trash product got 5 stars you realize the reviews DO NOT EVEN RELATE TO THE PRODUCT you purchased. I mean, how does this even happen? Several ways: 1. Repurposing product listings for something unrelated and keeping the old sales data and reviews 2. Merging product listings to aggregate unrelated sales data and reviews 3. Fake reviews that were un…

> Several ways:

> 1. Repurposing product listings for something unrelated and keeping the old sales data and reviews

Sure - but this seems trivially solvable by Amazon - you can't tell that a product listing for a knife set is not a tech product??

> 2. Merging product listings to aggregate unrelated sales data and reviews

Again - def happens I think. But can't these go through some type of review? The ones I've seen are WAY off when you look deeper.

> 3. Fake reviews that were unrelated to the product all along

This is harder, I'd have 2 amazon staff review higher volume products.

Re: We purchased a machine from China and it came with malware preinstalled

#219

Earlier quoted context omitted.

I’ve found this is true for everything but brother printers. I’ll never buy another brand again.

The Brother color laser printer I purchased 7-8 years ago was the best printer purchase I ever made. I barely print, and the toner doesn't dry up the way inkjet ink does. It just sits there, ready for the occasional print job. No BS software required.

Thank you and the parent. I’ll try this path in the future.

Re: We purchased a machine from China and it came with malware preinstalled

#220
About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was phoning home info...likely wifi credentials...etc.

It started me off on the thought process of "How many other things can be compromised?" SD cards with fake/hidden partitions? MCU counterfeits with entire subsystems?

IMHO...anything with an ethernet port, wifi, bluetooth...or anything that is able to at any time connect to those things needs to be watched.

Post reply on HN