5 ms·
Neither Dell nor HPE manufactures switches (the former never has, the latter hasn't for the past few years). So, these are all sourced from an OEM like Edgecore
by Am_I_Right 5y ago
Neither Dell nor HPE manufactures switches (the former never has, the latter hasn't for the past few years). So, these are all sourced from an OEM like Edgecore.
And, someone at that OEM ordered a bunch of misspelled stickers. Easy mistake to make, if the latin alphabet is literally foreign to you.
And if you think that sticker is bad? Wait until you see the actual firmware, oh boy... (I had some fun Edgecore LACP bugs take down an pretty sizable network. Things got slightly better once they moved to Linux-based firmware, but never to the point that their kit was, like, entirely reliable...)
- bluedino 5y agoIsn't the fear that they are imitation parts?
- mxxx 5y agoYes, but they’re not. It was just a typo.
- Am_I_Right 5y agoI'm not entirely sure what the fear is. The AST2600 the sticker seems to have been pasted to is a pretty complicated IC with (and this is the important part) user-upgradeable flash to begin with. So, you want to do a supply-chain attack? Simply reflash the genuine modules. No need to spend more. On the other hand: you want to save a few bucks? Possibly do a knock-off chip, but you're definitely not going to bother with the firmware. Too expensive! This is definitely a case of "trying to save a few bucks". Both Dell and HPE are in a race to the bottom, and the sticker being indicative of anything significant beyond that is... unlikely...
- NAR8789 5y agoI think so, but assuming that is the case... what's to stop a shady chipmaker from printing properly-spelled "American Megatrends" stickers? More generally... are there any actual protections offered by genuine stickers? The article makes this out to be a major supply chain security issue, and that only makes sense if branding stickers are actually reliable for validation purposes. But that seems... nonsensical? Wouldn't stickers be very easy to forge? But, I don't work in supply chains. Anyone with better expertise in this area able to chime in? I will admit I skimmed the article, because it is long and overly-detailed for my level of interest, and because it lacks summary sections.
- jcrawfordor 5y agoIt's not at all that a properly spelled sticker gives assurance that it's not counterfeit... it's just that a misspelled sticker is such an obvious sign of a potential counterfeit that it's basically the #1 thing that any counterfeit/suspect items program teaches people to look for. Most people working on counterfeits don't speak English so it's very easy for these kinds of mistakes to slip through, and on the other hand they're rarely made by the genuine manufacturer which usually has a process to check for this kind of thing even if the engineering work is done in a non-English speaking country (most of all that the logos usually come from off-the-shelf art files from the marketing department, so no one's even typing the name to make a mistake). Almost any corporate or institutional counterfeit or supply chain security program will explicitly teach you: if anything is misspelled or shows other obvious mistakes, hold the part as a suspected counterfeit. It's a pretty good quality indication. So of course manufacturers do genuinely make spelling mistakes sometimes, but this context makes it a pretty embarrassing and serious thing to do. It's like your bank misspelling their name in an account notification: sure, in some extremely theoretical sense it doesn't mean anything, but in practice they're giving you exactly the signal that everyone tells you to check for to identify phishing, and it raises questions about their processes that they let it slip through.
- ksec 5y agoWell, for many stickers, they have to be ordered from original vendor / AMI. I guess this is not the case here. Turns out it is coming from AMI, but AMI Taiwan. >AMI Taiwan needed to get license stickers for the local market. Instead of using the “American Megatrends” MegaRAC PM sticker template, it decided to make its own that had the misspelling.
- hef19898 5y agoSo really nothing to see here, other than an AMI subsidiary got a bunch of stickers with a typo and distributed hose to suppliers.
- walrus01 5y agoedgecore is just a marketing name, the actual company is accton they're generally a competitor of companies like compal, clevo, quanta. All well known in Taiwan if you're in the business of having 3rd parties manufacture your stuff.
- alliao 5y agoI'm pretty sure accton's compal's communications subsidiary
- walrus01 5y agothat is a good point, not something I'd had reason to think about since 2006 or so. Compal is quite a behemoth. https://en.wikipedia.org/wiki/Compal_Electronics https://en.wikipedia.org/wiki/Compal_Electronics US $26 billion revenues. Most people have never heard of it, only its consumer facing brands like Ignitenet.
- merb 5y agoit's crazy how much tech companies taiwan has. i'm pretty sure that this has conflict potential with china (i.e. china with the eu/us).
- walrus01 5y agosome 15-20 years ago most of the big taiwanese electronics manufacturing companies (top tier x86-64 motherboard makers would be a good example) moved a lot of their factory operations to mainland china, for lower cost labor. it's very interconnected now. there's a fascinating yearly trade show of taiwanese manufacturers: https://www.computextaipei.com.tw/en/index.html https://www.computextaipei.com.tw/en/index.html
- c_o_n_v_e_x 5y agoI frequently work with Taiwanese manufacturers in the industrial PC space. Depending on what the client needs, I can specify whether the equipment is made in China (Suzhou) or Taiwan. Having the equipment made in Taiwan costs at least 10 to 15% more.