Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

251–260 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#251

Earlier quoted context omitted.

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

Do any of them steal IP, as is alleged here, and has certainly happened in other cases involving Chinese, often state-controlled, companies?

Do companies hire/recruit (ex-)employees from competitors to re-implement the same features?

Yes.

Lots of IP between your ears. No point in the code/manuals/docs when you wrote them yourself. You’ll know they’re not exactly correct and may appreciate being able rewrite from the ground-up now knowing what you now know.

Re: We purchased a machine from China and it came with malware preinstalled

#252
post #89

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

I bought a bluetooth dongle on Amazon recently. didn't work out of the box, and the instruction booklet told me I had to download and install an unsigned device driver that I should download from a specific dropbox link. I tried to write a measured review on Amazon explaining the problem, but Amazon rejected the review. I threw it away and composed an angsty tweet [1], but I really should have returned it. [1] https:…

A chinese USB-C to Ethernet adapter had instructions to download and install a macOS kernel extension for it to work. Thanks but no thanks. This was a product that was (presumably) vetted and retailed by an EU electronics retailer.

Re: We purchased a machine from China and it came with malware preinstalled

#253

Earlier quoted context omitted.

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

Do any of them steal IP, as is alleged here, and has certainly happened in other cases involving Chinese, often state-controlled, companies?

Do western artists and corporations borrow stuff from other cultures and competitors? All 20th century rock & roll, most of hollywood, and pretty much all of pre-90s Silicon Valley is based on that premise.

That you think it's theft is a debatable/controversial point of view on Internet forums, but if that is to be the case, many more people/corporations from USA should feel threatened, not just a few chinese scapegoats which help avoid the elephant in the room: why would anyone own ideas in the first place? Ideas are born out of other ideas and every one benefits from that. Restricting knowledge sharing can lead to disastrous outcomes as Jonathan Blow brilliantly argued in a talk called Preventing the collapse of Civilization which appears to pop up on HN every so often: https://www.youtube.com/watch?v=pW-SOdj4Kkk

Re: We purchased a machine from China and it came with malware preinstalled

#254
post #77

Earlier quoted context omitted.

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

I was royally pissed off when I suspected my brand new Lenovo laptop was acting strange. The only in the end to stop it was to reinstall the OS, I then later found out it was the superfish issue https://slate.com/technology/2015/02/lenovo-superfish-scanda... I will never buy Lenovo again

The problem is more or less all hardware manufacturers do that. There's variations: some bundle only the Windows backdoor, some bundle Superfish, some bundle Intel/AMD's anti-theft and ME/PSP features. That society is ok with that is a huge problem to say the least.

Re: We purchased a machine from China and it came with malware preinstalled

#255
post #68

Earlier quoted context omitted.

> "efficient" MBA eloi outsourced everything to morlocks a long time ago. This is the biggest weakness of the West - and it all stems back to "share holder value". Companies, US ones, in particular, seem to have some absurd drive to pay endless dividends to shareholders, and drive 'value' via share price, by appearing to be profitable. In other words, get stuff from the cheapest provider. It didn't help that at the s…

People don't realize that the US defense budget is practically the only thing keeping American manufacturing alive.

Eh. Manufacturing has never gone down in GDP terms. It just seems to have gone down due to layoffs as a result of further mechanization of production.

Re: We purchased a machine from China and it came with malware preinstalled

#256
post #220

About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was p…

Does this include headphones that connect to my phone via bluetooth?

Re: We purchased a machine from China and it came with malware preinstalled

#257

Earlier quoted context omitted.

What would the chips connect to in order to phone home? My protected home wifi? A random telecom carrier for which it will have to have, by chance, a valid prepaid sim card?

Hey, Alexa, please tell me what random devices in my house are connecting to the internets? Hey, Roomba, did you download the latest firmware yet? Great! Now go clean the dining room, I have a top-secret meeting in there in 10 minutes. Hey, Alexa, set the dining room lights to "top-secret meeting" mode.

quite the conspiracy. But I do suppose amazon sidewalk could be tapped into?

Re: We purchased a machine from China and it came with malware preinstalled

#258
post #30

The malware analysis report they've ordered ( https://www.rmcybernetics.com/files/pdf/Malware-analysis-Fly... ) is extremely light on details. Yes, some things look suspicious (packing, lack of signatures, hardcoded IP addresses/hostnames, network traffic) - but I'm not seeing any clear-cut evidence that this is malware?

It's frustrating. I've seen anti malware software pick up anything that has a file name in Mandarin as malware. I used to use a great little program called Clover which was basically File Explorer for Windows but it allowed tabs. I stopped using it after a while because anti malware kept flagging it. Did it have malware? Maybe! I couldnt really get a good answer and I figured having tabs in file explorer isnt worth i…

I haven't thought about Clover in forever, but didn't it add tabs to your existing Explorer, versus being an Explorer clone plus tabs? The behavior required for the former probably looks a lot like malware to a heuristic detection engine.

Re: We purchased a machine from China and it came with malware preinstalled

#259
post #29

I've bought systems off of Amazon that had pirated Windows licenses on them (otherwise a great little fanless box) In a previous life I was an infosec consultant. We did some work for a hospital that found malware on the control hosts shipped with a brand new turnkey MRI system from a German manufacturer.

I've seen plenty of stick PCs on Amazon that definitely have pirated copies of Windows on them. I continue to be a bit surprised that Microsoft hasn't gone after Amazon for "aiding & abetting" this, but they probably have bigger fish to fry.

they dont make their money on Windows licenses anyway. they make it on all the crap they shove in your face when you use windows.

you've been able to pirate windows 10 using their "windows 7 free update" key even after they discontinued it. and everyone who got a free upgrade from 7->10 uses the same key so its not like you are gonna get caught.

Re: We purchased a machine from China and it came with malware preinstalled

#260
post #220

About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was p…

[deleted]
Post reply on HN