Live data from Hacker News

We X-Rayed a Suspicious FTDI USB Cable

eclypsium.com

31–40 of 88 posts

Re: We X-Rayed a Suspicious FTDI USB Cable

#31

To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the che…

Huh! I originally thought the bottom one was authentic because the main IC looked a lot “nicer”. Then I saw the jumble of wires to the right and rethought.

Re: We X-Rayed a Suspicious FTDI USB Cable

#32

I have a slow burn project where I simulate a supply chain attack on my own motherboard. You can source (now relatively old) Intel PCH chips off Aliexpress that are “unfused” and lack certain security features like Boot Guard (simplified explanation). I bought one of these chips and I intend to desolder the factory one on my motherboard and replace it with the Aliexpress one. This requires somewhat difficult BGA refl…

I don't want Boot Guard or any of that DRM crap. I want freedom. I want to make a persistent implant/malware that survives OS reinstalls. Look up Absolute Computrace Persistence. It's there by default in a lot of BIOS images, but won't survive a BIOS reflash with an image that has the module stripped out (unless you have the "security" of Boot Guard, which will effectively make this malware mandatory!) I’m more inter…

Well, this project is literally about me circumventing/removing Boot Guard so I don’t know how it’s corporate authoritarianism. I’m literally getting rid of it. In doing so I get complete control of the BIOS/firmware down to the reset vector. I can disable ME. To me, that’s ultimate freedom.

As a power user, do I want boot guard on my personal PC? Honestly, no. And we’re in luck because a huge amount of consumer motherboards have a Boot Guard profile so insecure it’s basically disabled. But do I want our laptops at work to have it, or the server I have at a colocation facility to have it? Yes I do. Because I don’t want my server to have a bootkit installed by someone with an SPI flasher. I don’t want my HR rep getting hidden, persistent malware because they ran an exe disguised as a pdf. It’s valuable in some contexts.

Re: We X-Rayed a Suspicious FTDI USB Cable

#33

Earlier quoted context omitted.

I don't want Boot Guard or any of that DRM crap. I want freedom. I want to make a persistent implant/malware that survives OS reinstalls. Look up Absolute Computrace Persistence. It's there by default in a lot of BIOS images, but won't survive a BIOS reflash with an image that has the module stripped out (unless you have the "security" of Boot Guard, which will effectively make this malware mandatory!) I’m more inter…

Well, this project is literally about me circumventing/removing Boot Guard so I don’t know how it’s corporate authoritarianism. I’m literally getting rid of it. In doing so I get complete control of the BIOS/firmware down to the reset vector. I can disable ME. To me, that’s ultimate freedom. As a power user, do I want boot guard on my personal PC? Honestly, no. And we’re in luck because a huge amount of consumer moth…

Some days you’re the anarchist, some days you’re the corporate authority. :D

Re: We X-Rayed a Suspicious FTDI USB Cable

#34

I could spot the clone because I'm familiar with the form factor of the FTDI IC, and I'm familiar enough with the datasheet to spot the expected passives. I'm not too keen these days with FTDI's reputation for manipulating their Windows device drivers to brick clones. So, while I'm familiar with their IC, I don't give them any more money. The next time I need a USB to serial cable, I'll bust out KiCad to build it usi…

It helps that USB to serial is a solved problem. Plenty of manufacturers make parts that work well and don't need to try and imitate FTDI.

Re: We X-Rayed a Suspicious FTDI USB Cable

#35
post #6

Jeese. I was not sure which image was the suspect one.

You don't need any specialized knowledge, just pick the one that looks "cleaner" and "neater" than the other.

It's sufficient to look at something as basic as the arrangement of cables on the left. The crooked electrical elements on the right are also a big tell.

This works because good—and bad—qualities correlate with each other.

Re: We X-Rayed a Suspicious FTDI USB Cable

#36
post #18
post #6

Jeese. I was not sure which image was the suspect one.

the one which looks cheaper to manufacture which is definitely the second

This is how I ID'd it; I have next to zero experience with ICs, but I've opened up a lot of devices for fun or repair and the cheap stuff always has wiring haphazardly contorted like the left side on the counterfeit, like someone had to force it in there and squeeze it shut just to get it out the door.

Re: We X-Rayed a Suspicious FTDI USB Cable

#37
post #34

I could spot the clone because I'm familiar with the form factor of the FTDI IC, and I'm familiar enough with the datasheet to spot the expected passives. I'm not too keen these days with FTDI's reputation for manipulating their Windows device drivers to brick clones. So, while I'm familiar with their IC, I don't give them any more money. The next time I need a USB to serial cable, I'll bust out KiCad to build it usi…

It helps that USB to serial is a solved problem. Plenty of manufacturers make parts that work well and don't need to try and imitate FTDI.

[deleted]

Re: We X-Rayed a Suspicious FTDI USB Cable

#38

I could spot the clone because I'm familiar with the form factor of the FTDI IC, and I'm familiar enough with the datasheet to spot the expected passives. I'm not too keen these days with FTDI's reputation for manipulating their Windows device drivers to brick clones. So, while I'm familiar with their IC, I don't give them any more money. The next time I need a USB to serial cable, I'll bust out KiCad to build it usi…

You don't actually need your own driver, you can just use the CDC device class.

Re: We X-Rayed a Suspicious FTDI USB Cable

#39

To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the che…

Huh! I originally thought the bottom one was authentic because the main IC looked a lot “nicer”. Then I saw the jumble of wires to the right and rethought.

If you look closely at the bottom one, almost all the components are slightly askew, while the top one has everything at neat 90 degrees. And a smaller IC almost always means the more modern/expensive IC. Same for the other components. In fact, the top one has a much higher component count, the small components just don't show up well (look at the pads though).

Re: We X-Rayed a Suspicious FTDI USB Cable

#40

I have a slow burn project where I simulate a supply chain attack on my own motherboard. You can source (now relatively old) Intel PCH chips off Aliexpress that are “unfused” and lack certain security features like Boot Guard (simplified explanation). I bought one of these chips and I intend to desolder the factory one on my motherboard and replace it with the Aliexpress one. This requires somewhat difficult BGA refl…

Death approaches. Slow burn until. When Death arrives, what you are doing now will be obviously irrelevant.
Post reply on HN