Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

51–60 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#51

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

>I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If you spend just a small bit of effort, you can look for items not made in China. They are usually higher quality. Japanese companies (and increasingly large American ones) are moving / have moved their production elsewhere due to an increasingly hostile business environment in Chi…

Is there a reliable way to research non-Chinese manufactured products? I know to just look for the “made in” somewhere on the page or product, but it’s not as simple as including a search tag in a field, either.

Re: We purchased a machine from China and it came with malware preinstalled

#52
post #4

Is this anything new? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

China is next level though. If that bothers anyone, that’s understandable; it should.

Re: We purchased a machine from China and it came with malware preinstalled

#53
post #15

Given that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.

A bit off topic, but the last time I needed a Windows laptop for business reasons (a long time ago) I bought a laptop directly from Microsoft and it appeared to be secure and also not loaded with advertising junk. The price seemed OK, fairly competitive.

When buying a Windows machine, you can purchase "Signature Edition" versions through Microsoft which will come with only the crapware selected by Microsoft, and not by the manufacturer

https://www.microsoft.com/en-gd/store/b/signaturepcs

Re: We purchased a machine from China and it came with malware preinstalled

#54
post #15

Given that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.

You know what? I don't care anymore. When this type of thing happens it's almost always China. Whether it's intentional malware or a lack of QA, how could one tell? They have such a reputation for both I don't know why we still let their electronics into our countries.

Re: We purchased a machine from China and it came with malware preinstalled

#55
post #17

> Presumably it would be a way to steal company information such as designs, accounts, and so on. Does it collect user metrics like a lot of software does or does it actually steal designs? The report is absolutely not clear about this. I have not read many reports like this but are they all like the one they link to? Is that what a malware analysis looks like? I'm completely behind the idea of calling every single s…

malware is any software that hides its existence from user. The windows telemetry is on edge of being malwere, even if its of no consequence to you. You cant say it will always stay that way.

Why is it not malware? The Wikipedia definition of malware lists "steals data".

Last time I tried the amount of deep registry hacks to turn everything(?) of was silly.

Windows obviously ships with malware nowadays. I think you need enterprise edition for a supported way to turn all the BS off.

Re: We purchased a machine from China and it came with malware preinstalled

#56
post #27

The story here is not the fact of the malware - it is the purpose of the malware: industrial espionage. China is well-known in industry for its sheer volume and brazenness of industrial espionage. A pick-and-place machine is especially well placed for this since it will, by necessity, have access to PCB designs and BOMs.

I have seen enough stories of supply-line sabotage to think that if you are going to build your infrastructure with Chinese hardware, air-gapping it is a necessity. Probably a good idea to air-gap your pick and place machine even if it is not Chinese.

It's really tough to air-gap these days. Are you really going to set up a perimeter where every phone, watch, and computer is dropped off before entry?

Re: We purchased a machine from China and it came with malware preinstalled

#57
I always wondered, how safe from tampering during manufacturing are devices 'designed in US/Europe/etc' that are built in China? Can anyone shed some light on the processes/practices that keep these devices safe, both from HW and SW points of view?

Re: We purchased a machine from China and it came with malware preinstalled

#58
post #30

The malware analysis report they've ordered ( https://www.rmcybernetics.com/files/pdf/Malware-analysis-Fly... ) is extremely light on details. Yes, some things look suspicious (packing, lack of signatures, hardcoded IP addresses/hostnames, network traffic) - but I'm not seeing any clear-cut evidence that this is malware?

I have seen a (badly written?) router firmware that behaved suspiciously just like you describe, but the only provable thing was that they checked for updates from the vendor in a rather non-optimal way.

Until today, I am not sure whether this was malice (=malware) or incompetence (=hey, let us phone home every 5 seconds and go crazy if the connection fails for any reason).

Re: We purchased a machine from China and it came with malware preinstalled

#59
"The malware would collect user data and send it to a remote address."

unpopular question, but how is this any different than mistakenly forgetting to disclose 'telemetry' in your code? or backdoors that routinely get disclosed in US embedded hardware products like firewalls and routers? or Discord scanning your entire hard disk? Ill admit the product seems pretty poorly designed from the get-go, but the tactics at work here are pretty standard when you consider things like Alexa and Ring get a pass for similar chicanery.

Re: We purchased a machine from China and it came with malware preinstalled

#60
post #59

"The malware would collect user data and send it to a remote address." unpopular question, but how is this any different than mistakenly forgetting to disclose 'telemetry' in your code? or backdoors that routinely get disclosed in US embedded hardware products like firewalls and routers? or Discord scanning your entire hard disk? Ill admit the product seems pretty poorly designed from the get-go, but the tactics at w…

It isn't, and those things are just as bad.

As a concrete example of just how far the creeping acceptance of surveillance has come. Remember BonziBuddy[1], and the absolute shit storm over that and the lawsuits and all that?

Well what they did nearly indistinguishable from what Alexa does, and Cortana, and Siri, and Google Assistant. But it's just the way things are now. And no, it's not fine because everyone is doing it. It's still just as bad as it was then.

[1] https://www.youtube.com/watch?v=L958sMz1kWs

Post reply on HN