Live data from Hacker News

Manufacturer 'make worthless' users devices after some stolen from a warehouse

phasenoise.livejournal.com

41–50 of 70 posts

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#41
If they can do this before it is sold (eg: theft) and remotely prevent the device from working, how do users defend against having this done later for more capricious reasons?

Everything I've learned, is that for capabilities like this, the good reasons are the justifications, and then the owners migrate to less good reasons. The overall distrust I have with these kinds of systems are that they are Treacherous Software/Hardware. This capability is something that shouldn't be implemented. No user in their right mind would - but the companies that wish to retain ownership rights after sale do.

I would also object to this 'hacking of these devices' as violations of CFAA. Yes, the devices had lost chain of custody, and were reported as stolen. That doesn't allow any entity to then engage in more illegal behaviors exigent to the initial situation. If I am being robbed, I am allowed to defend myself and my goods. However I cannot stalk the robber, and then bash his/her kneecaps in after the fact. 2 wrongs, separated by time, do not make a right.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#42
post #35

Those who bought stolen devices should return them and ask for a refund from EBay. You are generally not allowed to resell stolen goods, although I am not sure if EBay is liable here. > Back in October 2014, the FDTI manufacturer shipped a device driver that ... would make any operating system stop seeing the device by setting its USB product ID to 0 , basically killing the USB device. Well, if that id can be set to…

If I recall correctly, it didn't get recognised as a USB device anymore so you couldn't reflash it.

Linux was able to allow connections to VID:0 PID:0 for usbserial.h about 3 days after the initial reports. From there, it was possible to rewrite the FTDI firmware to restore functionality.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#43

> Those that do and assist us in tracking down the thieves will be treated VERY sympathetically. Does that mean they'll unbrick their hardware? That's about the only sympathy I'd expect after purchasing a product in good faith, and discovering that it was bricked or disabled by the manufacturer.

Buying the discounted hardware on eBay is somewhat marginal as "good faith". That said, RTL-SDR hardware barely exists in the normal supply chain so consumers often have little choice but to roll the dice on eBay.

The one I bought came delivered in a plastic baggie in a padded envelope. It could have been stolen for all I know.

Is there a way to check which serial numbers were stolen? Can I demand a seller post a picture of the device with the serial number so I can check? How can I be sure they won't lie?

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#45

I can't bring myself to be bothered by this - and wouldn't be even if I were using these devices. For crying out loud, equipment with unique recorded serial numbers was stolen, so the company is blocking the specific stolen devices. That makes perfect sense to me. Objecting to how they do it (bulking up software with a list of serials, requiring software to phone home, whatever) is fine and their customers have a leg…

How far can we take this? Theft is a big deal for manufacturers. They spend good money on preventing it. But will they continue to spend good money on prevention if instead they can just brick any lost devices? The nightmare is a manufacturer turning to a whitelist model, one where post-purchase the consumer must legitimize their purchase before use of the device. That DRM. There is massive overlap between the community of people who purchase SDR products and the group that will riot in the streets in protest of DRM.

Anyone who purchases tech devices owns some "pirate" content. When you buy a motherboard you don't know the pedigree of its hundreds of components. Trace each one and you will find a licensing or counterfeit issue somewhere. Should everyone be able to automagically brick counterfeit or stolen devices when those devices have been integrated, resold three times, and are now in the hands of innocent consumers? There are policy-based principals in western law that have long prevented such behavior in other arenas.

See: https://www.law.cornell.edu/ucc/2/2-403

Not exactly on point, but an example of how we protect good-faith purchasers, even black-market purchase of "stolen" goods.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#46
I used to always be pro-consumer in cases where the manufacturer does something like that to clones (Salae and FTDI cases)

After slowly getting into the manufacturing game myself and after USPS auctioned some of my cute early engineering samples that ended up on ebay, I definitely think this is totally reasonable from the manufacturer. Also the title of the article is already attacking the manufacturer. If you brick the devices, you hurt the person stealing and indeed it seems that this wasn't the first time it happened to them. On the consumer side maybe a discount would also be a nice gesture.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#47
post #19

> Those that do and assist us in tracking down the thieves will be treated VERY sympathetically. Does that mean they'll unbrick their hardware? That's about the only sympathy I'd expect after purchasing a product in good faith, and discovering that it was bricked or disabled by the manufacturer.

https://blogs.findlaw.com/blotter/2014/08/can-you-get-arrest... If you buy stolen good, you don't get to keep them. These are stolen goods, why would you ever expect the company to simply allow you to use it?

The company gets to prevent future thefts, they've most likely written off the loss already (they're not going to reuse those goods as new items at v. least), they can get PR and more "column inches" on a new story about buyers helping them and then getting gifted the device.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#48

> Those that do and assist us in tracking down the thieves will be treated VERY sympathetically. Does that mean they'll unbrick their hardware? That's about the only sympathy I'd expect after purchasing a product in good faith, and discovering that it was bricked or disabled by the manufacturer.

Buying the discounted hardware on eBay is somewhat marginal as "good faith". That said, RTL-SDR hardware barely exists in the normal supply chain so consumers often have little choice but to roll the dice on eBay. The one I bought came delivered in a plastic baggie in a padded envelope. It could have been stolen for all I know. Is there a way to check which serial numbers were stolen? Can I demand a seller post a pic…

Kind of; they posted the list on a forum and appear to have tweeted about it: https://www.sdrplay.com/community/viewtopic.php?f=6&t=3225

There isn't really a centralized or standardized way to do this, though. I guess if I'm buying some smart-ish hardware, I just have to google around for the company and hope I did a good job.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#49
post #19

> Those that do and assist us in tracking down the thieves will be treated VERY sympathetically. Does that mean they'll unbrick their hardware? That's about the only sympathy I'd expect after purchasing a product in good faith, and discovering that it was bricked or disabled by the manufacturer.

https://blogs.findlaw.com/blotter/2014/08/can-you-get-arrest... If you buy stolen good, you don't get to keep them. These are stolen goods, why would you ever expect the company to simply allow you to use it?

I take issue with the fact that the company has any say in the matter at all, tbh. I dislike devices that phone home and can be disabled remotely as a matter of principle.

But you're right, in the end they are stolen goods.

Re: Manufacturer 'make worthless' users devices after some stolen from a warehouse

#50

Earlier quoted context omitted.

Yeah, the burden is on the buyer not to purchase stolen goods. The manufacturer is certainly under no obligation to support them. In many states even unknowing possession of stolen goods is a crime, so many of the "users" here are in fact getting off lightly.

> Yeah, the burden is on the buyer not to purchase stolen goods. 1 party has 100% of the information, 1 party has 0% of the information, and the burden is on the party with 0% information. That's absurd. > The manufacturer is certainly under no obligation to support them. Not support and bricking are two different things. > In many states even unknowing possession of stolen goods is a crime Generally the state has to…

> Not support and bricking are two different things.

I wouldn't expect a stolen car to be maintained for me, and I would expect it to be stopped by the police and taken away - which I would consider to be effectively bricking it. This would still, and sadly does regularly happen, even if I didn't know it was stolen when I bought it. It doesn't need to be stolen too, if the owner is in fact still a finance company (for example) and it was sold to me without their agreement - they would be within their rights to take it away, and as I understand it without any police involvement (if it's publicly accessible and they don't use force)

Post reply on HN