Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

221–230 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#222
post #89

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

I bought a bluetooth dongle on Amazon recently. didn't work out of the box, and the instruction booklet told me I had to download and install an unsigned device driver that I should download from a specific dropbox link. I tried to write a measured review on Amazon explaining the problem, but Amazon rejected the review. I threw it away and composed an angsty tweet [1], but I really should have returned it. [1] https:…

Huh. I just got some insecure crap from Amazon, composed a pretty scathing review about it, and they put it up:

https://www.amazon.com/review/R2OY2YYNJ3WW4H/

Re: We purchased a machine from China and it came with malware preinstalled

#223

Earlier quoted context omitted.

that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. This is one of the big reasons that Apple locked down its Lightning/USB ports so hard. There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems. It was a huge topic i…

in ~2005 whilst I was the IT manager at Lckheed Martin's RFID division - we were implementing TLS on Exchange for all email... among other security measures... We had a compromised machine (linux) and had to un-plug it... BUT On the security calls was an interesting conversation about the Chinese infiltration of Lockheed. Lockheed, had at the time, only (3) three egress connects to the internet. The chinese did the f…

Hey, this is a really interesting anecdote, you should write it up and publish as a blog post or submit it to HN.

Re: We purchased a machine from China and it came with malware preinstalled

#224
post #129

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

Buying from China, as a westerner, is akin to buying the rope that will hang you. Regardless of the quality or price of their products. We should have never allowed them to become this powerful. Their ideology is toxic and incompatible with ours.

Yes, that's like Europeans signing contracts to buy natural gas from Russia. Amazingly short-sighted.

Re: We purchased a machine from China and it came with malware preinstalled

#225

20 years ago, china hide 2nd network card that was in listener mode, transmitting documents at random times, mostly peek. This was at a research company. How it was discovered. We put a card on listening/prem mode and mirror everything for that subnet the printer was on. I thought I screwed it up with the double mirror/traffic. when investigating why the issue, we found nothing wrong with the config, only when we plu…

Did you report them to the CIA?

Re: We purchased a machine from China and it came with malware preinstalled

#226

Earlier quoted context omitted.

Well, but correct me if I'm wrong, the Snowden leak included nothing like this. Instead it included a lot of things that would be a lot easier to do if Google/Microsoft ect just gave them access. The very fact they had to do everything else is at least evidence that don't have direct access

It's just different use cases. Backdoors are more useful for targetted operations or specific data exfiltration, while plugging yourself to back bones is more useful for mass surveillance. I don't even see why it's controversial to hold this opinion. Reading some comments, people seems to feel offended we could think that from the USA. If anything, the USA are, with Russia and China, among the countries anybody in Eu…

But, and this is where the equivalency annoys me. You could literally end up in jail for saying some of these things about China in China. You could just as well talked about abuses of women and the me to movement, but the reason that hasn't happened in China may well be not that there men are somehow better behaved, but that they appear to have put a women who did come out with an accusation under house arrest until she agreed to stop talking about it. Yes the US has done and doubtless continues to do bad things, part of that comes just from having power which the US has had for a long time, part of that comes from truly bad people ect. But the Snowden leak happened in the US. US newspapers reported on it. College professors talked to their class about it. You can talk about it on this US hosted and owned website. None of that is true in China, right? So yes I am more skeptical of the US doing shady business when a large percentage of US citizens object to shady business and can talk about it than I am of China doing shady stuff when they've built their internet to insulate their government from as much criticism as possible

Re: We purchased a machine from China and it came with malware preinstalled

#227

Earlier quoted context omitted.

Well, but correct me if I'm wrong, the Snowden leak included nothing like this. Instead it included a lot of things that would be a lot easier to do if Google/Microsoft ect just gave them access. The very fact they had to do everything else is at least evidence that don't have direct access

It's just different use cases. Backdoors are more useful for targetted operations or specific data exfiltration, while plugging yourself to back bones is more useful for mass surveillance. I don't even see why it's controversial to hold this opinion. Reading some comments, people seems to feel offended we could think that from the USA. If anything, the USA are, with Russia and China, among the countries anybody in Eu…

> It's just different use cases.

That's a hand-wavy redirection that isn't relevant to the issue at hand, which is that:

There is no evidence of the US (and, in fact, many other large countries, with exceptions for e.g. Israel) installing backdoors and breaking into computers in order to steal intellectual property.

There is ample evidence of China doing exactly that, against a variety of targets (not just the US - they've taken things from Japan and the EU, among many others).

I wouldn't be surprised if every nation with a functioning Internet connection tries to put the hac on whatever they can.

But that's not the topic under discussions - the topic is stealing and commercializing IP, for which there is tons of evidence for China doing, and accusations of e.g. the Five-Eyes doing it are rampant speculation with absolutely no evidence included.

Yes, that includes your comment.

Re: We purchased a machine from China and it came with malware preinstalled

#228

Earlier quoted context omitted.

A bit off topic, but the last time I needed a Windows laptop for business reasons (a long time ago) I bought a laptop directly from Microsoft and it appeared to be secure and also not loaded with advertising junk. The price seemed OK, fairly competitive.

When buying a Windows machine, you can purchase "Signature Edition" versions through Microsoft which will come with only the crapware selected by Microsoft, and not by the manufacturer https://www.microsoft.com/en-gd/store/b/signaturepcs

It looks like that isn't available for those in the US, since the redirect takes me to a 'not available' page. Are the 'Signature Edition' versions at all available in the US?

Re: We purchased a machine from China and it came with malware preinstalled

#229

Earlier quoted context omitted.

It's pretty absurd to both sides something like this. Do you have evidence that the US government is doing this on computers it sells overseas, or is this just magical speculation?

Around the time of the snowden leaks we learned that the NSA was installing backdoors on Cisco firewalls bound for foreign countries. https://en.wikipedia.org/wiki/Cisco_Systems#Firewall_backdoo... "A document included in the trove of National Security Agency files released with Glenn Greenwald's book No Place to Hide details how the agency's Tailored Access Operations (TAO) unit and other NSA employees intercept ser…

Where's the part where the US steals and then commercializes Chinese IP?

Re: We purchased a machine from China and it came with malware preinstalled

#230

Earlier quoted context omitted.

I heard your type of argument about the US mass spying before Snowden, and surprise, we were not conspirationists after all. So call that educated magical speculation.

People have a hard time admitting that what Snowden/Assange revealed about the US is much more damning, from infected servers to keyloggers built into USB cables. I find China is useful as a mirror to the US. If they are doing something problematic, it's highly likely the US gov is too but just hasn't disclosed it to the public.

> I find China is useful as a mirror to the US. If they are doing something problematic, it's highly likely the US gov is too but just hasn't disclosed it to the public.

You think the US is engaging in systematic genocide? I'm guessing not. If so, you should consider why you would say something so ridiculously out of step with reality.

Post reply on HN