Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

41–50 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#41

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

>I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware.

If you spend just a small bit of effort, you can look for items not made in China. They are usually higher quality. Japanese companies (and increasingly large American ones) are moving / have moved their production elsewhere due to an increasingly hostile business environment in China.

Sony makes their phones in Thailand, speakers/headsets in Malaysia. Panasonic produces a lot of consumer electronics in Malaysia. Samsung makes some of their phones in Vietnam, and the high-end ones in Korea. Their fridges are also made in Thailand/Korea. Google makes their Nest line of products in Thailand/Vietnam now. Some Netgear Arlo products are made in Indonesia, (some?) Netgear switches are made in Thailand.

On the enterprise side, Cisco has moved production of a lot of lines to Thailand for example.

This trend is only going to accelerate after the SARS-COV-2 pandemic subsides.

Re: We purchased a machine from China and it came with malware preinstalled

#42
post #15

Given that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.

Or it's just malware that's "around" the company since nobody cares what they download, which USB keys they plug, etc

Autorun USB malware is very common

Re: We purchased a machine from China and it came with malware preinstalled

#43
post #24

The malware is a cherry on top, but the story before that is pretty awful already, and unfortunately seems to be representative of specialized software like that: proprietary (with constant risk of malware, indeed), awkward, poorly (if at all) documented, likely the protocols to speak to the hardware without it are kept in secret, and occasional shipment of Windows machines where just software would do (but probably…

> proprietary (with constant risk of malware, indeed)

being proprietary has nothing to do with risk of malware, indeed

Re: We purchased a machine from China and it came with malware preinstalled

#44
post #34

Earlier quoted context omitted.

> After a while you'll notice you are sending everything back. What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.

> Surely buyers can't possibly afford sending everything back. What country you live in with so poor online protections you can't return things within the return window without incurring extra costs for doing so? Sounds broken.

In France, for example, it's legal for the customer to be on the hook for return shipping. This is often the case with smaller merchants, but even bigger ones have this policy. Example: Darty [0]

So if you have to pay for the crap to be shipped all the way back to China, I can see how that may become expensive.

[0] Darty return policy, in French: https://www.darty.com/achat/services/retour-retractation/ind...

Re: We purchased a machine from China and it came with malware preinstalled

#45
post #17

> Presumably it would be a way to steal company information such as designs, accounts, and so on. Does it collect user metrics like a lot of software does or does it actually steal designs? The report is absolutely not clear about this. I have not read many reports like this but are they all like the one they link to? Is that what a malware analysis looks like? I'm completely behind the idea of calling every single s…

> Does it collect user metrics like a lot of software does or does it actually steal designs?

The reports mark it as a Trojan/backdoor. This means it gives the company remote access to the machine. They can do whatever they want with it.

This isn’t anything like analytics reporting.

Re: We purchased a machine from China and it came with malware preinstalled

#47
post #34

Earlier quoted context omitted.

> After a while you'll notice you are sending everything back. What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.

> Surely buyers can't possibly afford sending everything back. What country you live in with so poor online protections you can't return things within the return window without incurring extra costs for doing so? Sounds broken.

> What country you live in with so poor online protections you can't return things within the return window without incurring extra costs for doing so? Sounds broken.

The sellers are in China and the products are ordered internationally. The sellers don’t care about your local return laws.

Re: We purchased a machine from China and it came with malware preinstalled

#48
post #24

The malware is a cherry on top, but the story before that is pretty awful already, and unfortunately seems to be representative of specialized software like that: proprietary (with constant risk of malware, indeed), awkward, poorly (if at all) documented, likely the protocols to speak to the hardware without it are kept in secret, and occasional shipment of Windows machines where just software would do (but probably…

> proprietary (with constant risk of malware, indeed) being proprietary has nothing to do with risk of malware, indeed

To be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation.

[1] https://en.wikipedia.org/wiki/Proprietary_software

Edit: wording.

Re: We purchased a machine from China and it came with malware preinstalled

#49
post #34

Earlier quoted context omitted.

> After a while you'll notice you are sending everything back. What about shipping costs? When you're buying something the seller is usually paying for that in bulk and including it in the retail price to boast "0-cost shipping". Surely buyers can't possibly afford sending everything back.

> Surely buyers can't possibly afford sending everything back. What country you live in with so poor online protections you can't return things within the return window without incurring extra costs for doing so? Sounds broken.

Return shipping is usually up to the customer and shipping back to China is much more expensive than the initial China to the US charges. Sometimes it exceeds the cost of the item itself to try to send it back so it's just cheaper to eat the loss.
Post reply on HN