Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

271–280 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#271
post #32

Earlier quoted context omitted.

https://www.pcworld.com/article/519855/amazon_kindle_1984_la... That story is about a lawsuit from one of the people they took it from. Amazon sold 1984 on the Kindle store without permission, and when they realized their error they deleted it from everyone's kindle and refunded their money.

That's really something entirely different than malware. You know that Amazon books on kindle are subject to that. It's not malware on the Kindle, it's their whole schtick.

> You know that Amazon books on kindle are subject to that.

Most people don't. And the few that do only know because of this scandal.

There's something profoundly unintuitive about it. When you buy 5$ a book in the bookstore, you can't wake up some day with the door open, 5$ on your table and the book gone from your library.

Re: We purchased a machine from China and it came with malware preinstalled

#272
post #265
post #220

About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was p…

TBH, this sounds like nonsense. What kind of ROM? There are not many ROMs in tablet SoCs. And how would it affect Android install in such a specific way? Wipe the whole eMMC and install a fresh, clean AOSP build and something is forcing a home page in a browser? Without a lot more detail, this sounds all kinds of improbable.

Android uses an A/B partition scheme. Either the bootloader can be infected or both partitions can have the malware. With the A/B split, even if you blow away eg B, A can reinfect B. It would be trivial to add extra circuitry to reinfect both partitions as well.

Re: We purchased a machine from China and it came with malware preinstalled

#273
post #220

About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was p…

[deleted]

Re: We purchased a machine from China and it came with malware preinstalled

#274

Earlier quoted context omitted.

I do. Highly effective propaganda has associated the facts around Chinese trade secret stealing with claims of racism and general xenophobia. As a result, now you have plenty of individuals all over the world whose moral compass pushes them to ignore the facts around trade secret stealing and even go dispute them in online conversations.

Explain further, please. Your response doesn't answer the question; I can't decide if it's deliberate obfuscation through scary words or an complete misunderstanding of what is being asked.

Just go on to reddit, and you'll find lots of people defending China against what they think is a smear campaign. Lots of these people appear to be young westerners who have bought into China's propaganda.

Re: We purchased a machine from China and it came with malware preinstalled

#275
post #48

Earlier quoted context omitted.

> proprietary (with constant risk of malware, indeed) being proprietary has nothing to do with risk of malware, indeed

To be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation. [1] https://en.wikipedia.org/wiki/Proprietary_software Edi…

>the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious.

And you cannot do that on open source either. Both cases require a chain of trust, and empirically, neither is significantly more secure.

Re: We purchased a machine from China and it came with malware preinstalled

#276
post #265
post #220

About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was p…

TBH, this sounds like nonsense. What kind of ROM? There are not many ROMs in tablet SoCs. And how would it affect Android install in such a specific way? Wipe the whole eMMC and install a fresh, clean AOSP build and something is forcing a home page in a browser? Without a lot more detail, this sounds all kinds of improbable.

I worked in a factory, where all the pc’s were infected with malware - at the production line too. This would have the unfortunate effect that when we wanted to flash calibration data to the device, malware would write itself to it because the way we would write the data was to a special section of the eMMC that would get mounted as a drive - malware detected a new drive and copied itself. We only discovered it because sometimes the devices wouldn’t boot - I think it took 3 days of nonstop debugging to figure it out. They thought we were crazy, when we finally tried to convince them that something was not right with their setup.

That was a large factory in China. I remember Philips had a production line there also.

Re: We purchased a machine from China and it came with malware preinstalled

#277

Earlier quoted context omitted.

A bit off topic, but the last time I needed a Windows laptop for business reasons (a long time ago) I bought a laptop directly from Microsoft and it appeared to be secure and also not loaded with advertising junk. The price seemed OK, fairly competitive.

When buying a Windows machine, you can purchase "Signature Edition" versions through Microsoft which will come with only the crapware selected by Microsoft, and not by the manufacturer https://www.microsoft.com/en-gd/store/b/signaturepcs

https://www.howtogeek.com/402888/looking-for-a-microsoft-sig... looks like they dropped the program

Re: We purchased a machine from China and it came with malware preinstalled

#278
post #163

Earlier quoted context omitted.

>I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If you spend just a small bit of effort, you can look for items not made in China. They are usually higher quality. Japanese companies (and increasingly large American ones) are moving / have moved their production elsewhere due to an increasingly hostile business environment in Chi…

> Sony makes their phones in Thailand, speakers/headsets in Malaysia. Panasonic produces a lot of consumer electronics in Malaysia. Samsung makes some of their phones in Vietnam, and the high-end ones in Korea. Their fridges are also made in Thailand/Korea. Google makes their Nest line of products in Thailand/Vietnam now. Some Netgear Arlo products are made in Indonesia, (some?) Netgear switches are made in Thailand.…

"Made in USA" has fairly strict rules. You can sneak some components in but it needs to be negligible and not misleading.

Re: We purchased a machine from China and it came with malware preinstalled

#279
post #48

Earlier quoted context omitted.

To be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation. [1] https://en.wikipedia.org/wiki/Proprietary_software Edi…

>the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And you cannot do that on open source either. Both cases require a chain of trust, and empirically, neither is significantly more secure.

For a whole computer stack, that's true enough.

Injecting malware in a single small widely distributed program and remaining stealthy for any length of time is a lot harder if it's open source.

Re: We purchased a machine from China and it came with malware preinstalled

#280
post #27

Earlier quoted context omitted.

I have seen enough stories of supply-line sabotage to think that if you are going to build your infrastructure with Chinese hardware, air-gapping it is a necessity. Probably a good idea to air-gap your pick and place machine even if it is not Chinese.

Airgapping wouldn’t be enough here since it infects any USB device plugged in. You’ll have to run the USB through some antivirus any time you want to use a new design from a “good” computer.

You could buy a big box of flash drives and use them as a disposable commodity that is one-time-use. E.g. these flash drives are $3.49. https://smile.amazon.com/Verbatim-Pinstripe-Flash-Drive-4906...
Post reply on HN