9 ms·
People who do not work in hardware seriously underestimate how often counterfeit components enter the supply chain. Even trustworthy distributors like digikey a
by ATsch 5y ago
People who do not work in hardware seriously underestimate how often counterfeit components enter the supply chain. Even trustworthy distributors like digikey and mouser have had regular cases of their supplies becoming contaminated. It is just way too easy to do and rarely discovered as long as you mix them with enough legitimate components to avoid suspicion. Unless you're unlucky and they happen to reach someone with an affinity for chip photography, the worst case is they'll just think a few components were DOA or out of spec.
It mostly affects low complexity components that are easy to clone so a BMC would be unlikely, but even that is not safe as sometimes used components de-soldered from other products make it back into the supply chain too.
- xondono 5y agoI’m still haunted by nightmares of fake FTDI chips
- ATsch 5y agoThat's a good public example, here's a post for anyone that missed it: https://zeptobars.com/en/read/FTDI-FT232RL-real-vs-fake-supereal https://zeptobars.com/en/read/FTDI-FT232RL-real-vs-fake-supe...
- kragen 5y agoThe bigger supply-chain problem there wasn't the fake FTDI chips, which actually worked reasonably well; it was the totally genuine and authorized FTDI driver update which FTDI designed to brick your customers' hardware if they installed it, if you had been so unfortunate as to get fake FTDI chips.
- ComputerGuru 5y agoOr worse: if they mistakenly thought you had a non-genuine FTDI component when you really didn’t.
- kragen 5y agoWhile clearly that's a thing that could happen when FTDI goes around injecting malware into the supply chain, I'm not aware of any accounts that it actually did happen. Did it?
- prutschman 5y agoIf I remember correctly, in the FTDI case that was very unlikely to happen. It wasn't a case of `if (looks_fake) do_brick()`. Rather, it accessed registers in a way that they knew their implementation supported but that was buggy in a widely counterfeited version. (And I understand it they did this knowing the effect it would have. It wasn't some accident.)
- ComputerGuru 5y agoYou’re right - I think I was misremembering the details and it was something like a poisoned supply chain leading to people who thought they had bought the real thing shipping devices that ended up breaking or something.
- kragen 5y agoWell, it was "a poisoned supply chain leading to people who thought they had bought the real thing shipping devices that ended up breaking"; it's just that FTDI was the company that poisoned the supply chain and broke the devices.
- prutschman 5y agoI was misremembering the specifics too, it turns out. It was much closer to do_brick(). Ugly.
- garaetjjte 5y agoI think ironically it was other way around - they issued write in such way that due to quirk in genuine chip it was no-op but actually worked on the clone.
- 5y ago
- ATsch 5y agoI look at it the other way around, the driver update is a rare case where it was publicly exposed just how widespread of an issue forgery is in the electronics industry. FTDI likely expected the number of fake devices already in the field to be significantly lower than they actually were. If that was the case, it is unlikely it would have become the story it did.
- jjoonathan 5y ago> "And I would have gotten away with it too, if it weren't for you meddling kids!" No, I don't think that was the thought process. I think they wanted to send a message and I think they wanted to test the waters to see if anyone would hold them accountable for deploying first party malware.
- xondono 5y agoGiven some of the devices I’ve seen these ICs, the fact that they were fake is a problem, no matter if they work reasonably well.
- yjftsjthsd-h 5y agoSure, and they would have gotten precious little criticism if they had displayed a big warning message on detecting a questionable part. The problem was that they decided to unilaterally destroy customer property.
- kragen 5y agoMuch worse: FTDI's customers are the distributors, whose customers are (usually) board assembly houses, whose customers are electronics vendors, whose customers are electronics users. FTDI decided to unilaterally destroy the property of their customers' customers' customers' customers. Or, rather, the customers of people who thought they were FTDI's customers' customers' customers, but whose suppliers' suppliers were actually cheating them. The miraculous thing is that FTDI escaped criminal prosecution for this.
- ClumsyPilot 5y agoSo as a customer, first i get scammed by getting fake prodiuct, then I become a target of wanton vandalism by FTDI? How is this legal?
- marcan_42 5y agoThe "fake" product might be legal if it doesn't have an FTDI logo; then it's just a compatible clone. The vandalism though, that's definitely illegal, and outright criminal.
- sitkack 5y agoIt wasn't that the chips were fake, they could only be fake if they claimed to be FTDI. They could have been merely FTDI compatible, at which point did FTDI have any grounds to destroy compatible parts?
- kragen 5y agoThey were using FTDI's USB VID. Probably most of them also were marked as "FTDI" on the chip package, but of course that's not what FTDI's drivers looked at.
- marcan_42 5y agoThere is no law against using someone else's USB VID, as long as you don't put a USB certification logo on your product. What FTDI did, on the other hand, is malware and clearly illegal. It is destroying private property and I guarantee violated multiple laws in many countries.
- chithanh 5y agoI don't know the laws elsewhere, but here in Europe trademark holders absolutely have the right to demand counterfeit products be seized and destroyed. Even if the owner acquired them in good faith. Also it would be interesting whether any compatible chips exist that use FTDI USB VID but were not marked with the FTDI logo. Of course this kind of vigilante justice by FDTI is illegal, but who is going to press charges if that means they will get their devices taken from them and destroyed?
- marcan_42 5y agoRight, we're talking about clones that don't use FTDI's logo. I don't know if they exist, but they well might. The point is that the VID itself doesn't have any legal protection.
- kragen 5y agoI didn't mean to imply that the clone vendors were breaking a law by using FTDI's VID. As far as I know you are correct that they were not.
- marcan_42 5y agoNightmares? They work better than the originals! There's this: https://twitter.com/marcan42/status/695292366639378433 https://twitter.com/marcan42/status/695292366639378433 And also, the way FTDI bricked the clones (only) was by exploiting the fact that they also implement the EEPROM write command in the sane way other FTDI chips do, instead of having the write staging quirk of the "genuine" FT232RL that they introduced when they wired the internal 32-bit EEPROM block to a 16-bit interface. So all around, the clones work better than the originals in several ways.
- xondono 5y ago> Nightmares? They work better than the originals! Yeah, nightmares. It doesn’t matter if they’re crap if it’s what you have to work with. I really never understood why the open source world went with FTDI when the CP210X was perfectly available (I’ve been using them for ~12 years now), in fact I found about the FTDI chips later and I was very confused of why would I even pay more for an inferior part. But whatever appears in hobby boards is bound to appear in some products.