Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

31–40 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#32

Earlier quoted context omitted.

Do you perhaps have a link about the story of amazon removing the 1984 book on all kindles? It sounds very interesting, partly because it seems so absurd.

https://www.pcworld.com/article/519855/amazon_kindle_1984_la... That story is about a lawsuit from one of the people they took it from. Amazon sold 1984 on the Kindle store without permission, and when they realized their error they deleted it from everyone's kindle and refunded their money.

That's really something entirely different than malware. You know that Amazon books on kindle are subject to that. It's not malware on the Kindle, it's their whole schtick.

Re: We purchased a machine from China and it came with malware preinstalled

#34

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

> After a while you'll notice you are sending everything back.

What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.

Re: We purchased a machine from China and it came with malware preinstalled

#35

I do wonder if this really was sabotage or if someone building these machines accidentally got their installer USB infected with some unrelated malware. If this was a targeted attack, I'd expect the manufacturer to ship the infection in the zip file with the replacement program as well. The old components and the lack of modern drivers is a problem many industrial tools seem to suffer from. It's crap like the bad cap…

Is that any kind of excuse? Supply Chain infection is a sidechannel way to infect YOUR network...what's your intellectual property worth? What's it worth if through the unintentional infection you find yourself figuring out how to get cash into bitcoin to pay a ransom?

Relying on an ancient card and drivers seems like a cop-out...they managed to create the solution once, they're obligated to do it again, lest your company's bottom line hinge on a house of cards an intern cobbled together for another company 12 years ago, that only works with the September 2008 drivers.

Re: We purchased a machine from China and it came with malware preinstalled

#36
post #34

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

> After a while you'll notice you are sending everything back. What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.

> Surely buyers can't possibly afford sending everything back.

What country you live in with so poor online protections you can't return things within the return window without incurring extra costs for doing so? Sounds broken.

Re: We purchased a machine from China and it came with malware preinstalled

#37
I am more than a little concerned that since the miniaturization and commoditization of spy hardware (miniature microphones, cameras, and wireless communication), that run-of-the-mill consumer electronics are being bugged by default. Given the cost is pennies or just a couple dollars, from an espionage perspective, it'd be worth it to spend a few hundred million or even billion putting bugs into literally everything and letting the market put them into the homes of all your political targets in other countries. Then the problem is just sifting the data, which is easy with the massive amount of computational power that every nation state has these days. That's a great dystopia.

Re: We purchased a machine from China and it came with malware preinstalled

#38
post #34

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

> After a while you'll notice you are sending everything back. What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.

He offers a simple solution in the first paragraph.

>everyone should avoid Chinese crapware.

Re: We purchased a machine from China and it came with malware preinstalled

#39
post #29

I've bought systems off of Amazon that had pirated Windows licenses on them (otherwise a great little fanless box) In a previous life I was an infosec consultant. We did some work for a hospital that found malware on the control hosts shipped with a brand new turnkey MRI system from a German manufacturer.

What did the malware do precisely? The definition is so broad and context-sensitive, that just saying malware doesn't really say anything. Some people would consider TPM and it's code malware, others would consider anything they don't like malware (like telemetry collection in Windows or whatever).

Re: We purchased a machine from China and it came with malware preinstalled

#40
post #32

Earlier quoted context omitted.

https://www.pcworld.com/article/519855/amazon_kindle_1984_la... That story is about a lawsuit from one of the people they took it from. Amazon sold 1984 on the Kindle store without permission, and when they realized their error they deleted it from everyone's kindle and refunded their money.

That's really something entirely different than malware. You know that Amazon books on kindle are subject to that. It's not malware on the Kindle, it's their whole schtick.

The best way to fix malware is to refer to it as your business model.
Post reply on HN