To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the che…
We X-Rayed a Suspicious FTDI USB Cable
71–80 of 88 posts
Re: We X-Rayed a Suspicious FTDI USB Cable
#72After they infamously started going after clones, anything branded FTDI is automatically suspicious. USB-serial adapters are not particularly special. Dozens of other manufacturers make them.
This was a huge own-goal for their brand image. If I buy a FTDI based adapter, it might brick, and I lack the detection skill or supply chain control to be sure that it won't happen. If I buy a CH340 or PLwhatever based adapter, that doesn't enter the calculus. Unless I had some explicit "only FTDI can possibly do it" need, I'm going elsewhere.
I am not nearly sophisticated enough as an end user to spot a counterfeit FTDI usb-to-serial device so I am not going to risk buying that brand and end up with their drivers intentionally bricking the device.
Re: We X-Rayed a Suspicious FTDI USB Cable
#73Earlier quoted context omitted.
Probably there is someone somewhere trying to make Linux boot on a thunderbolt cable.
It would be a pretty amusing demonstration to plug in the cable to a display, then pretend to plug the other end into an imaginary computer sitting nearby and have something boot up on the display.
Re: We X-Rayed a Suspicious FTDI USB Cable
#74To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the che…
I felt the same way reading this. A fake FTDI cable? I mean there's no way right? I've never bothered to verify but I'm pretty sure I don't actually even have a single authentic one. I wouldn't know where to order from if I wanted an authentic one.
Amazon, ebay, and similar others for the (cheaper) counterfeits.
Re: We X-Rayed a Suspicious FTDI USB Cable
#75Earlier quoted context omitted.
that defeats the point, having the "keys" allows malicious actors to perform the same kind of attacks... trust is protected by trusted companies... certificate companies sell trust, not certificates.
Me managing my own (for example) secure boot keys does not inherently enable malicious actors. Obviously unauthorized access to the keys is an attack vector that whoever holds them needs to account for. Obviously it's not risk free. There's always the potential that a user could mismanage his keys. There's absolutely no excuse for hardware vendors not to provide end users the choice. > trust is protected by trusted c…
asus gives out keys to sign bios firmware, now aliexpress can not only counterfeit, but provide tampered hardware.
you can enroll your own secure boot keys so that's not really relevant.
Re: We X-Rayed a Suspicious FTDI USB Cable
#76Earlier quoted context omitted.
It would be a pretty amusing demonstration to plug in the cable to a display, then pretend to plug the other end into an imaginary computer sitting nearby and have something boot up on the display.
It'd be a cool physical demonstration at a cybersecurity roadshow. A concern: with all this computing onboard, does this mean a malicious USB-C cable could record screen and keystroke? Often the keyboard receiver is plugged into the monitor's USB hub and so screen and HID are both going along a single cable ... Which also does power delivery. Such cables are a definite "sales category" and could be a target for suppl…
Re: We X-Rayed a Suspicious FTDI USB Cable
#77Earlier quoted context omitted.
Me managing my own (for example) secure boot keys does not inherently enable malicious actors. Obviously unauthorized access to the keys is an attack vector that whoever holds them needs to account for. Obviously it's not risk free. There's always the potential that a user could mismanage his keys. There's absolutely no excuse for hardware vendors not to provide end users the choice. > trust is protected by trusted c…
the hardware is made by asus, asus signs with their key backed by a trusted company. asus gives out keys to sign bios firmware, now aliexpress can not only counterfeit, but provide tampered hardware. you can enroll your own secure boot keys so that's not really relevant.
I'll grant that if the user is given control then compromise within the supply chain does become possible. However the same hypothetical malicious aliexpress vendor could also enroll a custom secure boot key, install "definitely totally legit windows", and unless the user inspects he might well never realize the deception. Or the supply chain could embed a keylogger. Or ...
Re: We X-Rayed a Suspicious FTDI USB Cable
#78Earlier quoted context omitted.
Lumifield quite recently showed on Adam Savage's Tested again, with some literal insights on a reasonably-diverse array of different 18650 cells: https://www.youtube.com/watch?v=AD5aAd8Oy84 It's a good watch, and I learned some new stuff about some things that I only knew a little bit about before.
I think you meant to link to https://www.youtube.com/watch?v=-Y23nfAOiXQ
Thanks!
Re: We X-Rayed a Suspicious FTDI USB Cable
#79Earlier quoted context omitted.
the hardware is made by asus, asus signs with their key backed by a trusted company. asus gives out keys to sign bios firmware, now aliexpress can not only counterfeit, but provide tampered hardware. you can enroll your own secure boot keys so that's not really relevant.
Secureboot was being used as an example to illustrate the issue with your claim that a user controlling the keys must necessarily undermine security. I'll grant that if the user is given control then compromise within the supply chain does become possible. However the same hypothetical malicious aliexpress vendor could also enroll a custom secure boot key, install "definitely totally legit windows", and unless the us…
Re: We X-Rayed a Suspicious FTDI USB Cable
#80Earlier quoted context omitted.
It would be a pretty amusing demonstration to plug in the cable to a display, then pretend to plug the other end into an imaginary computer sitting nearby and have something boot up on the display.
It'd be a cool physical demonstration at a cybersecurity roadshow. A concern: with all this computing onboard, does this mean a malicious USB-C cable could record screen and keystroke? Often the keyboard receiver is plugged into the monitor's USB hub and so screen and HID are both going along a single cable ... Which also does power delivery. Such cables are a definite "sales category" and could be a target for suppl…