Live data from Hacker News

We purchased a machine from China and it came with malware preinstalled

rmcybernetics.com

71–80 of 342 posts

Re: We purchased a machine from China and it came with malware preinstalled

#71
post #57

I always wondered, how safe from tampering during manufacturing are devices 'designed in US/Europe/etc' that are built in China? Can anyone shed some light on the processes/practices that keep these devices safe, both from HW and SW points of view?

Measures could be put in place, like installing the OS only when it arrives from the Chinese construction site or shipping pre-installed SSDs with Bitlocker enabled (with unique keys per customer) so that the drives cannot be tampered with unnoticed.

In practice, I've never heard of companies actually investing in these checks. There are a few "assembled in the USA" products that probably flash their install image outside China, but who says the American intelligence agencies in turn won't tamper with those? They've done it before, after all.

I'm a little surprised there aren't any viable open source programs for what is essentially a precise plotter with a complicated plot head. A bunch of plants could work together to construct a system free of vendor lock-in and expensive replacement parts if they would just work together.

Re: We purchased a machine from China and it came with malware preinstalled

#72
post #51

Earlier quoted context omitted.

>I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If you spend just a small bit of effort, you can look for items not made in China. They are usually higher quality. Japanese companies (and increasingly large American ones) are moving / have moved their production elsewhere due to an increasingly hostile business environment in Chi…

Is there a reliable way to research non-Chinese manufactured products? I know to just look for the “made in” somewhere on the page or product, but it’s not as simple as including a search tag in a field, either.

I've noticed lately that in the Q&A section of the majority of the items I look at on Amazon, someone asks where the item was made.

That's helpful. I've always wanted to know where my stuff comes from, from my food to my gadgets. So I encourage other people do ask the same questions on Amazon. It helps other people.

Re: We purchased a machine from China and it came with malware preinstalled

#73

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. This is one of the big reasons that Apple locked down its Lightning/USB ports so hard. There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems. It was a huge topic i…

>There were tons of fake Apple chargers flooding the market that contained exfiltration circuitry, among other problems. It was a huge topic in tech circles, and on HN, at the time.

source? I've heard of fake charges being planted with exfiltration circuitry as part of a targeted attack (eg. by red teams or actual bad guys), but I haven't heard of aliexpress vendors shipping them out en-masse.

Re: We purchased a machine from China and it came with malware preinstalled

#74
or maybe they don’t give a fuck about your tiny company that’s too cheap to buy a decent pic n’place? maybe the malware was actually intended getting ip from the company that manufactured machines like yours in the thousands. why do you always assume US companies are the only ones being copied from?

Re: We purchased a machine from China and it came with malware preinstalled

#75
post #29

I've bought systems off of Amazon that had pirated Windows licenses on them (otherwise a great little fanless box) In a previous life I was an infosec consultant. We did some work for a hospital that found malware on the control hosts shipped with a brand new turnkey MRI system from a German manufacturer.

What did the malware do precisely? The definition is so broad and context-sensitive, that just saying malware doesn't really say anything. Some people would consider TPM and it's code malware, others would consider anything they don't like malware (like telemetry collection in Windows or whatever).

It was one of the big Microsoft worms from ~10 years ago plus a few random ones.

Re: We purchased a machine from China and it came with malware preinstalled

#76

Hug of death probably so I cannot read the article. Anyway that's the reason why I don't buy Chinese crap anymore. I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If something doesn't match the description send it back, if you find random executables that you cannot identify send it back, if you are asked to register on some weird…

>I'm not saying that I don't buy anything made in China, almost everything is made in China, but everyone should avoid Chinese crapware. If you spend just a small bit of effort, you can look for items not made in China. They are usually higher quality. Japanese companies (and increasingly large American ones) are moving / have moved their production elsewhere due to an increasingly hostile business environment in Chi…

If you buy a Sony product made in Thailand, what protects you from encountering crap like in the article is not that it's made in Thailand instead of China, but that Sony has a reputation to protect and the expertise to do proper quality control.

If you buy stuff directly from a Thai company that you never heard of before just because their product was the cheapest, you'll have to do your own testing and will likely discover some sharp edges.

Re: We purchased a machine from China and it came with malware preinstalled

#77
post #4

Is this anything new? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

I'm a little bothered by the article title because it implies it's related to the manufacturer being from China, despite ample evidence that pretend-reputable software vendors like Google, Amazon and Microsoft all bundle universal backdoors with their systems. Google infamously pushed settings changes on their phone lines without user consent via the Google Play Services backdoor. Amazon removed the (bought) book 198…

I was royally pissed off when I suspected my brand new Lenovo laptop was acting strange. The only in the end to stop it was to reinstall the OS, I then later found out it was the superfish issue

https://slate.com/technology/2015/02/lenovo-superfish-scanda...

I will never buy Lenovo again

Re: We purchased a machine from China and it came with malware preinstalled

#78
post #17

> Presumably it would be a way to steal company information such as designs, accounts, and so on. Does it collect user metrics like a lot of software does or does it actually steal designs? The report is absolutely not clear about this. I have not read many reports like this but are they all like the one they link to? Is that what a malware analysis looks like? I'm completely behind the idea of calling every single s…

malware is any software that hides its existence from user. The windows telemetry is on edge of being malwere, even if its of no consequence to you. You cant say it will always stay that way.

I'm going to broaden your definition to "malware is any software that hides its existence or its behaviour from the user". There's little value in knowing that a certain piece of software exists on your machine if you don't know what it's for.

Re: We purchased a machine from China and it came with malware preinstalled

#79
post #48

Earlier quoted context omitted.

> proprietary (with constant risk of malware, indeed) being proprietary has nothing to do with risk of malware, indeed

To be precise, I had in mind closed-source software: the software you can't inspect with reasonable effort/time before running, to ensure that it's not malicious. And especially in case of specialized software, that wasn't inspected by others either. Though these terms seem to be used interchangeably quite commonly [1], likely because of a strong correlation. [1] https://en.wikipedia.org/wiki/Proprietary_software Edi…

Proprietary or open sourced doesn't matter much if you're not verifying the checksums of all the binaries that come per-installed on your system. If the majority of tech savvy people can't be bothered to do it, then average joe is doomed.

Re: We purchased a machine from China and it came with malware preinstalled

#80
post #68

Earlier quoted context omitted.

Quoted post unavailable.

> "efficient" MBA eloi outsourced everything to morlocks a long time ago. This is the biggest weakness of the West - and it all stems back to "share holder value". Companies, US ones, in particular, seem to have some absurd drive to pay endless dividends to shareholders, and drive 'value' via share price, by appearing to be profitable. In other words, get stuff from the cheapest provider. It didn't help that at the s…

People don't realize that the US defense budget is practically the only thing keeping American manufacturing alive.
Post reply on HN