19 ms·
Trust in hardware supply chains when manufactring a PCB for a product can be quite fragile: when one component operates outside of spec, the entire device could
by kregasaurusrex 6y ago
Trust in hardware supply chains when manufactring a PCB for a product can be quite fragile: when one component operates outside of spec, the entire device could be rendered useless. In the case of the DS18B20, the author states in the 'Warning' section that the primary way of determining counterfeit sensors is to check the ROM output compared to a known format. When counterfeit parts like this are added, it creates vulnerabilities in the entire system due to the ability for a bad actor to leverage this vulnerability and cause one part in an entire system to fail.
For example, the company FTDI snuck in code that was in a series of Windows updates that was able to detect counterfeit FTDI and brick them via software to send back all 0's.[0][1] This anti-consumer behavior on behalf of comapnies can a be a headache for end-users and programmers alike.
[0] https://hackaday.com/2014/10/22/watch-that-windows-update-ftdi-drivers-are-killing-fake-chips/ https://hackaday.com/2014/10/22/watch-that-windows-update-ft...
[1] https://hackaday.com/2016/02/01/ftdi-drivers-break-fake-chips-again/ https://hackaday.com/2016/02/01/ftdi-drivers-break-fake-chip...
- robomartin 6y ago> This anti-consumer behavior on behalf of companies I strongly disagree with this. I see no way to rationalize that a company should be responsible for ensuring that counterfeit devices work correctly by releasing drivers that are tolerant of them or do not stop them from functioning. FTDI's products are the combination of their hardware with their drivers. Both are required in order to delivery functionality and reliability to meet their specifications. Imagine your drivers are used in some sort of a critical application and a counterfeit device causes a failure that, in turn, causes harm to someone. An example might be a wired remote control for an industrial machine. It seems to met that bricking that device as soon as possible before harm is done is what we would want from a company that delivers a quality product. Another way to put it is: Let the counterfeiters engineer a real product and be responsible for their own drivers, quality and safety. The way to see clearly through some of these problems is to extend the definition towards extremes. Let's forget FTDI for a moment and generalize the problem to a microprocessor and a vendor-provided RTOS used to run the flight system of an airliner. This is a contrived hypothetical, forgive me for taking artistic license. Imagine counterfeit processor make it into the supply chain. Should the avionics OS do its best to work with every possible fake or should it brick it on power-up before that potentially dangerous aircraft gets off the ground? Another hypothetical could be one where we eliminate hardware completely. Imagine someone creates a fake Amazon, Facebook, NY Times or online brokerage site. Imagine proposing that the real companies would be anti-consumer if they created software that revealed the impostors. I could not imagine anyone who would propose they allow the fakes to continue to deceive consumers. From my perspective this isn't anti-consumer at all. It's as pro-consumer as you can get: You work hard to ensure quality, consistency, performance and reliability. The real anti-consumers are the counterfeit manufacturers. They, quite literally, could not care less. All they care about is tricking engineers and consumers into thinking they are designing and buying a quality product when, in reality, they might be dealing with dangerous junk.
- teruakohatu 6y ago> I strongly disagree with this. I see no way to rationalize that a company should be responsible for ensuring that counterfeit devices work correctly They destroyed devices that worked perfectly well, but maybe (or maybe not) had a fake FTDI branding on a chip inside the device. Even the manufacturer may have been a victim of commingled inventory. For this reason I stopped buying anything with FTDI in it, because I didn't want to take the chance it would be bricked because the smalltime seller on Tindie.com bought from a bad supplier. I would hate to think what you would have Apple do to Hackintosh hardware.
- robomartin 6y ago> I would hate to think what you would have Apple do to Hackintosh hardware. You are looking at it precisely backwards. The key question here goes something like this: Is Apple responsible for ensuring that fakes function correctly as it issues software updates for its own hardware? In other words, just because someone decided to make a Hackintosh or a fake iPhone is Apple now instantly saddled with having to support this hardware for the lifetime of the fake products? And this is the case whether there's just one clone or 100 different variants? As I have asked others, in what alternate reality does this make any sense? My guess is that none of you have ever designed or manufactured hardware products at scale and don't fully comprehend the implications of what you so vehemently believe. No hardware manufacturer would ever take the side of having to ensure fakes work correctly; this would be sheer insanity.
- teraflop 6y agoNobody's complaining that FTDI didn't make their drivers compatible with counterfeit hardware. They're complaining that FTDI deliberately took actions in their driver code to damage any supposedly counterfeit devices that were plugged into a system. To use your example, imagine if Apple released an update to iOS that would scan any jailbroken iPhones on the same network, and if it detected one, would use a backdoor to send it malware that wipes the device's bootloader.
- analog31 6y agoIf I recall correctly, FTDI took some well deserved heat, but quickly discontinued this practice.
- voltagex_ 6y agoBoth FTDI and Prolific have done this kind of thing. I switched to the CH340 a while back without any issues.
- omgtehlion 6y agohow about cp2102? I prefer it to ch340, for no reason though ))
- pantalaimon 6y agoI found both cp2102 and ch340 seem to use less power too than ft232r. At least there are some boards I can power with the 3.3V output of the cp2102 and ch340 dongles, but which will brown-out with the old ft232r ones.
- janekm 6y agoIt's my go-to part for this purpose also (and I don't believe I've encountered any clones so far, knock on wood). Another part I've used in a high-volume application is the Holtek HT42B534 which is great because it's CDC class and hence doesn't need a driver for Win/Mac/Linux. It's EOL sadly. There's HT42B564 which is a HID-class replacement. The other alternative is using a cheap micro with USB interface.
- analog31 6y agoAha, I didn't know about the CP2102. Looks like I'll have to give one a whirl, and there's even a breakout board at Adafruit. I've used relatively few VCP adapters since I've been using microcontrollers with built-in VCP. I was nervous about the CH340 because the Windows drivers seemed to come from some weird place in China, but maybe US sourced drivers aren't any more of a comfort in these times.
- IAmEveryone 6y agoThat's a lot of fancy words for essentially restating that old adage about three million parts being required to launch a rocket, all of them being delivered by the cheapest bidder. And yet, these rockets (mostly) got off the ground quite safely! Because these statistical vulnerabilities are rather obvious, and it isn't quite just the "cheapest bidder", and because their parts are tested, and because people took care to allow for 2 million of those 3 million parts to fail without disaster being inevitable. The risks of remote-bricking counterfeits are rather obvious, indeed. But it's just as trivially obvious that it is intended to protect the supply chain. Or, for the cynical: that its intend to protect these companies' profits is aligned with protecting the supply chain. It's a trade-off, unlikely to have a single, generic best answer.