Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

281–290 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#281
post #188

Earlier quoted context omitted.

This has already happened: smartphones and wifi. People financed it themselves by buying the things. (Wifi can see you: "The next big Wi-Fi standard is for sensing, not communication" https://news.ycombinator.com/item?id=29901587 ) FWIW, I think whether we build a dystopia or utopia depends on whether or not we can make our rulers live under the same panopticon as the rest of us.

I don't disagree with the smartphones and WiFi, though the big 2 are highly motivated to at least secure the kernel and their own spyware. I am more thinking of these things targeting sensitive military installations or personnel. > whether or not we can make our rulers live under the same panopticon as the rest of us. Uh, nope. It's been "rules for thee and not for me" since the dawn of time.

> I am more thinking of these things targeting sensitive military installations or personnel.

Ah, yes, it sure would be nice to think that they're a bit more careful, but then I think of things like the OPM leak and I go cross-eyed. ( https://en.wikipedia.org/wiki/Office_of_Personnel_Management... - I'm sure you know what I'm talking about but I figured I'd add a link for anyone who didn't.)

> It's been "rules for thee and not for me" since the dawn of time.

Aye, but I think that's just what the panopticon could overturn, if we set it up that way. I'm not particularly hopeful, but maybe there's a possible future where we overcome our worser natures and use technology wisely. Star Trek vs. N. Korea.

FWIW I call this idea the "Tyranny of Mrs. Grundy": if everyone is on the lens-end of the cameras, including police and politicians, then no one escapes censure by Mrs. Grundy. ( https://en.wikipedia.org/wiki/Mrs_Grundy ) We're forced to create a "humane tyranny".

"Humane tyranny" sounds like an oxymoron from today's POV, but I think the challenge is to "de-oxymoron-icize" it. Due to the advancing tech, I don't think it's optional , the panopticon will happen (it arguably already has), so the challenge is to make it more-or-less livable.

Re: We purchased a machine from China and it came with malware preinstalled

#282
post #15

Given that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.

Or it's just malware that's "around" the company since nobody cares what they download, which USB keys they plug, etc Autorun USB malware is very common

> Or it's just malware that's "around" the company since nobody cares what they download, which USB keys they plug

There's a fun story documented on Darknet Diaries (https://darknetdiaries.com/transcript/22/) about a wind farm that got hacked. The "malicious" actor had found his way into their infrastructure and installed some idle cryptominers. But he was also taking the time to maintain all the infrastructure; applying updates and patches on a regular basis in an effort to keep other would-be hackers out. The security consultant discloses all of this to the company. Well, the story ends with the company making a business decision to leave things as they are. They were effectively getting free IT.

Re: We purchased a machine from China and it came with malware preinstalled

#283

Earlier quoted context omitted.

It's fair play to act like any gov is doing this. E.G: Microsoft being American (and them being part of PRISM), I just assume the OS has a backdoor for the US gov. Now with Windows 10 heavy telemetry, it's even easier. I work for a client doing chips for credit cards. Did you know they are now full blown computers that can run a light version of Java (Java Card) ? The company is building their own hardware and softwa…

It's pretty absurd to both sides something like this. Do you have evidence that the US government is doing this on computers it sells overseas, or is this just magical speculation?

Not precisely the same thing, but even more insidious (or brilliant, depending on who you ask):

> Operation Rubicon (German: Operation Rubikon), until the late 1980s called Operation Thesaurus, was a secret operation by the West German Federal Intelligence Service (BND) and the U.S. Central Intelligence Agency (CIA), lasting from 1970 to 1993 and 2018, respectively, to gather communication intelligence of encrypted government communications of other countries.[1][2] This was accomplished through the sale of manipulated encryption technology (CX-52) from Swiss-based Crypto AG, which was secretly owned and influenced by the two services from 1970 onwards.[1] In a comprehensive CIA historical account of the operation leaked in early 2020, it was referred to as the "intelligence coup of the century" in a Washington Post article.

https://en.wikipedia.org/wiki/Operation_Rubicon_(Crypto_AG)

Re: We purchased a machine from China and it came with malware preinstalled

#284
post #220

About 8 years ago one of our devs purchased a couple Android tablets from China to test if they would work as a host for Smoothieware (and/or 3d printers). It had malware prebundled at the ROM level. You could not remove it by wiping Android (IIRC..our dev that tracked the issue said he had to block what it was doing). The tablet forced your homepage...regardless of what you set it to...and I believe he said it was p…

Ok...response from the dev who did the work. I was a bit mistaken but here are his copied words.

" well it wasn;t actually a ROM malware it was the seller installing their own version of Android, which would reinstall their browser and would not let you change the browser, this browser had a hard coded home page which it forced you too, and it was a home page basically that sells you stuff. if you stopped their browser from getting installed, then the tablet went into a demo mode and displayed huge DEMO text across the whole screen. Eventually I was able to replace several Android core system modules which removed their check that their browser was active. and yea I could see it phoning home whenever it was turned on."

I know I have this device in a box. If anyone would like to analyze it and see if there was more/less than what we found I am willing to send it to someone in the US via ground shipping (LIPO batteries). I believe it was not charging the last time I used it though.

Re: We purchased a machine from China and it came with malware preinstalled

#285
In 2019 the Chinese covered up the early spread of COVID then later repeatedly stonewalled anyone doing serious research into the disease's origin. By letting COVID spread for months unchecked the Chinese effectively ensured that there was no way to stop this thing from going global, which it did, ultimately killing over 5M people and counting.

If we're unwilling to hold the Chinese to account for that in any meaningful way, I can't imagine we're going to do anything whatsoever about a little (or even a lot of) industrial espionage.

We'll gladly let the Chinese run roughshod over us and humiliate us repeatedly if it means we can still by our iPhones on the cheap.

Re: We purchased a machine from China and it came with malware preinstalled

#286
post #285

In 2019 the Chinese covered up the early spread of COVID then later repeatedly stonewalled anyone doing serious research into the disease's origin. By letting COVID spread for months unchecked the Chinese effectively ensured that there was no way to stop this thing from going global, which it did, ultimately killing over 5M people and counting. If we're unwilling to hold the Chinese to account for that in any meaning…

[deleted]

Re: We purchased a machine from China and it came with malware preinstalled

#287

Earlier quoted context omitted.

Airgapping wouldn’t be enough here since it infects any USB device plugged in. You’ll have to run the USB through some antivirus any time you want to use a new design from a “good” computer.

You could buy a big box of flash drives and use them as a disposable commodity that is one-time-use. E.g. these flash drives are $3.49. https://smile.amazon.com/Verbatim-Pinstripe-Flash-Drive-4906...

But then you're getting into a bit of an e-waste problem.

Re: We purchased a machine from China and it came with malware preinstalled

#288
post #48

Earlier quoted context omitted.

To be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation. [1] https://en.wikipedia.org/wiki/Proprietary_software Edi…

>the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And you cannot do that on open source either. Both cases require a chain of trust, and empirically, neither is significantly more secure.

I think the context somehow gets lost in this discussion. You indeed need a chain of trust in general, and can't inspect all the software alone even if it's FLOSS, but I'm talking about odd specialized programs shipped by hardware manufacturers (like the one TFA talks about) and similar one-off ones that come from an untrusted source: there's no trust there, no reliance on others inspecting it, but if you have the source code, it's often reasonable to read. Also occasionally desirable to fix or otherwise modify, to integrate into your overall system (that's what I tend to do pretty much each time when interacting with such sotfware+hardware, sometimes reverse engineering and reimplementing it, so maybe my view is a bit skewed). So FLOSS is good, closed source and proprietary is less trustworthy and less usable.

Re: We purchased a machine from China and it came with malware preinstalled

#289
post #265

Earlier quoted context omitted.

TBH, this sounds like nonsense. What kind of ROM? There are not many ROMs in tablet SoCs. And how would it affect Android install in such a specific way? Wipe the whole eMMC and install a fresh, clean AOSP build and something is forcing a home page in a browser? Without a lot more detail, this sounds all kinds of improbable.

Android uses an A/B partition scheme. Either the bootloader can be infected or both partitions can have the malware. With the A/B split, even if you blow away eg B, A can reinfect B. It would be trivial to add extra circuitry to reinfect both partitions as well.

Right I guess I assumed 'wiping android' meant starting over: erasing the eMMC via TRIM and flashing a new bootloader/repartitioning/etc. via BROM USB mode or something like that.

I guess OP might have meant just 'factory reset'. Which is not really 'wiping the android' at all.

Re: We purchased a machine from China and it came with malware preinstalled

#290

Earlier quoted context omitted.

>the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And you cannot do that on open source either. Both cases require a chain of trust, and empirically, neither is significantly more secure.

I think the context somehow gets lost in this discussion. You indeed need a chain of trust in general, and can't inspect all the software alone even if it's FLOSS, but I'm talking about odd specialized programs shipped by hardware manufacturers (like the one TFA talks about) and similar one-off ones that come from an untrusted source: there's no trust there, no reliance on others inspecting it, but if you have the so…

>I'm talking about odd specialized programs shipped by hardware manufacturers (like the one TFA talks about

In that case, open source rarely has even one possible replacement, so there's no comparison.

>but if you have the source code, it's often reasonable to read

As someone working in code daily, I disagree. I find lots of open source projects once you get out of the few big ones to be a massive mess of code.

And most programs of much use are simply too big to do any sort of audit. I have lots of friends in open source - I doubt a single one has ever read over the source for an entire program to inspect.

Have you honestly read over an entire open source program to check it? Or is this a myth that gets repeated but no one does it....

As to modification, I've reverse engineered many, many programs to add hooks and interoperability. It's not that terribly difficult once you've done a few and get to know how to do it.

So sure, nice clean code is good. But open source software I find to be crappy for all but the few big uses. GIMP vs photoshop? No real good OS CAD, or finance, or comparing Octave to Mathematica? Buggy video editor of the week to DaVinci Resolve? Tax software? Inkscape vs AI? So as a result of lacking quality in OS, I prefer closed source solutions since paying for them gets me vastly better quality for a lot of things I want software for.

And in the rare case I want to hack something, I still can and do.

Open source is honestly a you-get-what-you-paid-for solution for most stuff.

Post reply on HN