As these desktop pick and place machines come down in price, I hope that the OpenPnP software package becomes more developed: https://openpnp.org/ It was originally intended for full DIY PnP machines, but it’s a perfect candidate for converting these existing machines to open source software control.
We purchased a machine from China and it came with malware preinstalled
61–70 of 342 posts
Re: We purchased a machine from China and it came with malware preinstalled
#62Given that Windows 7 _Ultimate_ was installed on what is essentially an OEM machine, it's very likely that it's a pirated copy with a "home brewed" license key. I think the most reasonable explanation is that either the OS was sourced already infected, or the crack tool they used was infected.
You know what? I don't care anymore. When this type of thing happens it's almost always China. Whether it's intentional malware or a lack of QA, how could one tell? They have such a reputation for both I don't know why we still let their electronics into our countries.
Re: We purchased a machine from China and it came with malware preinstalled
#63Is this anything new? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…
Re: We purchased a machine from China and it came with malware preinstalled
#64The malware analysis report they've ordered ( https://www.rmcybernetics.com/files/pdf/Malware-analysis-Fly... ) is extremely light on details. Yes, some things look suspicious (packing, lack of signatures, hardcoded IP addresses/hostnames, network traffic) - but I'm not seeing any clear-cut evidence that this is malware?
It looks like an instance of 'xred': https://s.tencent.com/research/report/880.html
Which seemingly infects .exes (ie., is not just a worm), so it's totally possible that the OEM here isn't acting maliciously, but they just got infected themselves.
Re: We purchased a machine from China and it came with malware preinstalled
#65"The malware would collect user data and send it to a remote address." unpopular question, but how is this any different than mistakenly forgetting to disclose 'telemetry' in your code? or backdoors that routinely get disclosed in US embedded hardware products like firewalls and routers? or Discord scanning your entire hard disk? Ill admit the product seems pretty poorly designed from the get-go, but the tactics at w…
I know this is the HN crowd and not the general population, but I think most of HN would agree that undisclosed telemetry is super bad / malicious, and that disclosed / configurable telemetry is much better...but still often must be disabled because the Well is Poisoned by inappropriately utilized telemetry.
Re: We purchased a machine from China and it came with malware preinstalled
#66Here's the article: https://habr-com.translate.goog/ru/post/575626/?_x_tr_sl=ru&...
Re: We purchased a machine from China and it came with malware preinstalled
#67I do wonder if this really was sabotage or if someone building these machines accidentally got their installer USB infected with some unrelated malware. If this was a targeted attack, I'd expect the manufacturer to ship the infection in the zip file with the replacement program as well. The old components and the lack of modern drivers is a problem many industrial tools seem to suffer from. It's crap like the bad cap…
Is that any kind of excuse? Supply Chain infection is a sidechannel way to infect YOUR network...what's your intellectual property worth? What's it worth if through the unintentional infection you find yourself figuring out how to get cash into bitcoin to pay a ransom? Relying on an ancient card and drivers seems like a cop-out...they managed to create the solution once, they're obligated to do it again, lest your co…
You'll be surprised how common these "house of cards an intern cobbled together for another company 12 years ago, that only works with the September 2008 drivers" situations really are when it comes to specialised hardware. As long as the machine keeps working, it can be sold, software security and maintenance be damned. There's a reason hospitals and factories pay Microsoft for the last few Windows 7 updates it'll release this year and it's not that management doesn't like the theme Microsoft put on Windows 10.
That's even more likely to be the case for industrial machines purchased off AliExpress, where hardware is often either old, second hand stuff or made as cheaply as possible from available parts. The standard of quality there is minimal, I'm surprised they risked buying this thing through AE in the first place.
Re: We purchased a machine from China and it came with malware preinstalled
#68Earlier quoted context omitted.
You know what? I don't care anymore. When this type of thing happens it's almost always China. Whether it's intentional malware or a lack of QA, how could one tell? They have such a reputation for both I don't know why we still let their electronics into our countries.
Quoted post unavailable.
This is the biggest weakness of the West - and it all stems back to "share holder value".
Companies, US ones, in particular, seem to have some absurd drive to pay endless dividends to shareholders, and drive 'value' via share price, by appearing to be profitable.
In other words, get stuff from the cheapest provider.
It didn't help that at the same time people like Carl Icahn came along and stripped a company that was cheap to buy, but also sat on a pile of cash. And again, if he could 'drive value' for the share holders, said company was a target.
Eventually state-level politics appear - artificially low-prices Chinese goods because the CCP fix the exchange rate, or subsidise an entire market to corner it globally.
Rinse repeat, and that's where we're at now.
Re: We purchased a machine from China and it came with malware preinstalled
#69Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…
This is one of the big reasons that Apple locked down its Lightning/USB ports so hard.
There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems. It was a huge topic in tech circles, and on HN, at the time. I even have a few "data condoms" leftover from those years. (If you don't remember, they're little dongles you put between your USB cable and the USB charger that only have the power lines connected.)
The fact that it also locked out bad cops was a bonus.