Live data from Hacker News

We X-Rayed a Suspicious FTDI USB Cable

eclypsium.com

61–70 of 88 posts

Re: We X-Rayed a Suspicious FTDI USB Cable

#61
post #26

Earlier quoted context omitted.

My apple thunderbolt 4 cable has a computer more powerful than my firs computer in it (ARM Cortex‑M0 core running at up to 48 MHz vs a 286 at 25mhz)

Probably there is someone somewhere trying to make Linux boot on a thunderbolt cable.

It would be a pretty amusing demonstration to plug in the cable to a display, then pretend to plug the other end into an imaginary computer sitting nearby and have something boot up on the display.

Re: We X-Rayed a Suspicious FTDI USB Cable

#63
I'm failing to see the smoking gun here.

There are two ways you could interpret "counterfeit".

1. Fake IC (identifies as FTDI 232 IC), fake cable (FTDI logo on it)

2. Real IC, fake cable (eg, I buy the FTDI IC and make the cable, and sell it as an "official" FTDI cable).

(1) is I assume what they mean in this instance., but you could argue (2) is also possible. However, they make no mention of the packaging both calling them "FTDI" cables. Instead, I assume they're going off what they report to the OS as.

FTDI have been around for decades, and the offhand "old cable we had kicking around" could easily mean its 15+ years old. That might easily explain the chip size difference. In this case, FTDI did make TSSOP 28-pin chips for a long time. They're now obsolete, superseded by SSOP package variants (like in the "Real" picture). Put another way, this is like comparing an i5-10400 to a Pentium II that I found in my storage closet and declaring the Pentium II fake.

The actual fake chips visually look identical to the real ones. Obviously, otherwise they wouldn't get mixed into the supply chain.

The only real conclusion they can realistically make from these x-rays are that they're not the same cable (but even then, I don't know if FTDI real cables have silently upgraded the internals while retaining the same SKU).

Re: We X-Rayed a Suspicious FTDI USB Cable

#64

To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the che…

I got it right too. But for an entirely naive reason. The smaller the components the more complex machines you would need - more expensive. Plus the more wiring on the io 3 vs 3+

Re: We X-Rayed a Suspicious FTDI USB Cable

#65

Earlier quoted context omitted.

Well, this project is literally about me circumventing/removing Boot Guard so I don’t know how it’s corporate authoritarianism. I’m literally getting rid of it. In doing so I get complete control of the BIOS/firmware down to the reset vector. I can disable ME. To me, that’s ultimate freedom. As a power user, do I want boot guard on my personal PC? Honestly, no. And we’re in luck because a huge amount of consumer moth…

I want an equivalent of boot guard that I hold the keys to. Presented only with a binary choice certainly having boot guard is better than not having it if physical device security is in question. But that ought to be a false dichotomy. Regulation has failed us here.

that defeats the point, having the "keys" allows malicious actors to perform the same kind of attacks... trust is protected by trusted companies...

certificate companies sell trust, not certificates.

Re: We X-Rayed a Suspicious FTDI USB Cable

#66

To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the che…

I got it right too. But for an entirely naive reason. The smaller the components the more complex machines you would need - more expensive. Plus the more wiring on the io 3 vs 3+

That's fairly close to my reasoning.

Re: We X-Rayed a Suspicious FTDI USB Cable

#67
From the article: "The consequences for a consumer buying a shady USB cable likely aren’t too bad".

I can't second that, but more to the software/driver side.

Without my knowledge, I once had a counterfeit cable that costed several days of my life. At that time, the FTDI drivers recognized (and as I read did some other things [1]) that a counterfeit cable was connected, but instead of simply disabling the function, they impeded it. In my case: After pressing the first few keys on terminal connection, the transmission from the device to the PC worked, but not the reverse direction. A long search for the error came to an end after I replaced the USB/RS232 with a new one. This was with windows, with Linux even the counterfeit worked.

[1] https://www.elektroda.com/qa,ftdi-ft232-scandal-driver-brick...

Re: We X-Rayed a Suspicious FTDI USB Cable

#68
post #61

Earlier quoted context omitted.

Probably there is someone somewhere trying to make Linux boot on a thunderbolt cable.

It would be a pretty amusing demonstration to plug in the cable to a display, then pretend to plug the other end into an imaginary computer sitting nearby and have something boot up on the display.

It'd be a cool physical demonstration at a cybersecurity roadshow.

A concern: with all this computing onboard, does this mean a malicious USB-C cable could record screen and keystroke?

Often the keyboard receiver is plugged into the monitor's USB hub and so screen and HID are both going along a single cable ... Which also does power delivery. Such cables are a definite "sales category" and could be a target for supply chain attacks. But if they now have chips onboard, doesn't that mean an attacker could even takeover a genuine cable? It seems like a real risk tbh.

Re: We X-Rayed a Suspicious FTDI USB Cable

#69

Earlier quoted context omitted.

I want an equivalent of boot guard that I hold the keys to. Presented only with a binary choice certainly having boot guard is better than not having it if physical device security is in question. But that ought to be a false dichotomy. Regulation has failed us here.

that defeats the point, having the "keys" allows malicious actors to perform the same kind of attacks... trust is protected by trusted companies... certificate companies sell trust, not certificates.

Me managing my own (for example) secure boot keys does not inherently enable malicious actors. Obviously unauthorized access to the keys is an attack vector that whoever holds them needs to account for. Obviously it's not risk free. There's always the potential that a user could mismanage his keys.

There's absolutely no excuse for hardware vendors not to provide end users the choice.

> trust is protected by trusted companies...

The less control of and visibility into their product you have the less trustworthy they are.

Re: We X-Rayed a Suspicious FTDI USB Cable

#70
post #54
post #46

Earlier quoted context omitted.

That tickled a memory of a video... and I hunted it up. Adam Savage's Tested : Look Inside Apple's $130 USB-C Cable - https://www.youtube.com/watch?v=AD5aAd8Oy84 (1 minute in "we've been saying that our phones have more computing power than the Apollo guidance computer but I'm positive now that this cable has more computing power than the Apollo guidance computer") That video is a look at cables (not just Apple's) wi…

Lumifield quite recently showed on Adam Savage's Tested again, with some literal insights on a reasonably-diverse array of different 18650 cells: https://www.youtube.com/watch?v=AD5aAd8Oy84 It's a good watch, and I learned some new stuff about some things that I only knew a little bit about before.

I think you meant to link to https://www.youtube.com/watch?v=-Y23nfAOiXQ
Post reply on HN