8 ms·
We X-Rayed a Suspicious FTDI USB Cable
- invokestatic 9mo agoI have a slow burn project where I simulate a supply chain attack on my own motherboard. You can source (now relatively old) Intel PCH chips off Aliexpress that are “unfused” and lack certain security features like Boot Guard (simplified explanation). I bought one of these chips and I intend to desolder the factory one on my motherboard and replace it with the Aliexpress one. This requires somewhat difficult BGA reflow but I have all the tools to do this. I want to make a persistent implant/malware that survives OS reinstalls. You can also disable Intel (CS)ME and potentially use Coreboot as well, but I don’t want to deal with porting Coreboot to a new platform. I’m more interested in demonstrating how important hardware root of trust is.
- Nextgrid 9mo ago> persistent implant/malware that survives OS reinstalls Try attacking NIC, server BMC or SSD firmware. You will achieve your goal without any hardware replacement needed.
- invokestatic 9mo agoYeah, but that doesn’t give me a reason to use the hot air station and hot plate collecting dust on my desk ;)
- cbsks 9mo agoNothing drives more creativity from me than a tool in need of a project.
- da_chicken 9mo agoI mean, you could also do smartphone repairs.
- mschuster91 9mo ago> I want to make a persistent implant/malware that survives OS reinstalls. You want to look into something called "Windows Platform Binary Table" [1]. Figure out a way to reflash the BIOS or the UEFI firmware for your target device ad-hoc and there you have your implant. [1] https://news.ycombinator.com/item?id=19800807 https://news.ycombinator.com/item?id=19800807
- ronsor 9mo agoOnly works if the target is running Windows (paranoid people might be on Linux), so you'd probably want to slip in a malicious UEFI driver directly. Tools like UEFITool can be used to analyze and modify the filesystem of a UEFI firmware image.
- baby_souffle 9mo ago> You want to look into something called "Windows Platform Binary Table" [1]. Is this how various motherboard manufacturers are embedding their system control software? I was helping a family friend with some computer issues and we could not figure out where the `armoury-crate` (asus software for controlling RGB leds on motherboard :() program kept coming from
- Nextgrid 9mo agoThat most likely comes from Windows Update though. It now has the ability to download "drivers". It actually had said ability for a long time (back from Vista days if I remember right) but back then it was only downloading the .inf file and associated .sys files/etc, where as nowadays it actually downloads and runs the full vendor bloatware.
- BobbyTables2 9mo agoLikely so. I think that’s actually the intended use of this “feature”
- phatskat 9mo agoHave your friend grab https://github.com/seerge/g-helper https://github.com/seerge/g-helper which can disable armory crate. It’s also a lot lighter on your system - I was having constant gradual frame drops (games would start find and performance would slowly degrade) until I tried this and used the option to disable the AC processes.
- userbinator 9mo agoI don't want Boot Guard or any of that DRM crap. I want freedom. I want to make a persistent implant/malware that survives OS reinstalls. Look up Absolute Computrace Persistence. It's there by default in a lot of BIOS images, but won't survive a BIOS reflash with an image that has the module stripped out (unless you have the "security" of Boot Guard, which will effectively make this malware mandatory!) I’m more interested in demonstrating how important hardware root of trust is. You mean more interested in toeing the line of corporate authoritarianism.
- taneq 9mo ago> You mean more interested in toeing the line of corporate authoritarianism. That’s not what I got from their post. After all, they’re putting in some effort to hardware backdoor their motherboard, physically removing BootGuard. I read it as “if your hardware is rooted then your software is, no matter what you do.”
- invokestatic 9mo agoWell, this project is literally about me circumventing/removing Boot Guard so I don’t know how it’s corporate authoritarianism. I’m literally getting rid of it. In doing so I get complete control of the BIOS/firmware down to the reset vector. I can disable ME. To me, that’s ultimate freedom. As a power user, do I want boot guard on my personal PC? Honestly, no. And we’re in luck because a huge amount of consumer motherboards have a Boot Guard profile so insecure it’s basically disabled. But do I want our laptops at work to have it, or the server I have at a colocation facility to have it? Yes I do. Because I don’t want my server to have a bootkit installed by someone with an SPI flasher. I don’t want my HR rep getting hidden, persistent malware because they ran an exe disguised as a pdf. It’s valuable in some contexts.
- taneq 9mo agoSome days you’re the anarchist, some days you’re the corporate authority. :D
- fc417fc802 9mo agoI want an equivalent of boot guard that I hold the keys to. Presented only with a binary choice certainly having boot guard is better than not having it if physical device security is in question. But that ought to be a false dichotomy. Regulation has failed us here.
- yjtpesesu2 9mo agoDeath approaches. Slow burn until. When Death arrives, what you are doing now will be obviously irrelevant.
- gregsadetsky 9mo agoYeah - these [0] kinds of cables are so extremely scary. "The O.MG Cable is a hand made USB cable with an advanced implant hidden inside. It is designed to allow your Red Team to emulate attack scenarios of sophisticated adversaries" "Easy WiFi Control" (!!!!!) "SOC2 certification"? Dawg, the call is coming from inside the house... [0] https://shop.hak5.org/products/omg-cable https://shop.hak5.org/products/omg-cable
- mschuster91 9mo ago> "SOC2 certification"? Dawg, the call is coming from inside the house... Helps corporate red teams in environments where the purchase department is... a bunch of loons.
- stainablesteel 9mo agoit's a serious problem they could be regulated to expose their chip with transparent covering rather than plain dark wiring
- trinsic2 9mo agoJeese. I was not sure which image was the suspect one.
- blibble 9mo agothe one which looks cheaper to manufacture which is definitely the second
- llbbdd 9mo agoThis is how I ID'd it; I have next to zero experience with ICs, but I've opened up a lot of devices for fun or repair and the cheap stuff always has wiring haphazardly contorted like the left side on the counterfeit, like someone had to force it in there and squeeze it shut just to get it out the door.
- kps 9mo agoThey gave it away by saying the genuine cable was a 234 series (small basic UART) and not a 232 (big ol' 28-pin chip).
- deleted 9mo ago[deleted]
- Neywiny 9mo agoIf you've read the docs, which I'm not saying anyone is expected to, FTDI tends to put buffers on their outputs. That's what gave it away for me. The little sot-23-5 footprints.
- trinsic2 9mo agoI wanted to try and figure out out before I did that. No dice.
- mjevans 9mo agoI got it backwards because I expected the counterfeit part to use a newer process IC (less silicon area) than a possibly more reliable and perfectly suitable for serial connection speeds 'vintage' process on some long stable spin of silicon. Why allow for newer processes on the counterfeit? They'd implement it using the least expensive, most mass produced chips possible, which are more likely to be cut from wafers hitting the sweet spot of size / feature and price crossover.
- commandersaki 9mo agoJust to be clear suspicious in this sense is a cable that is likely counterfeit and wasn't able to do high speed transfer unlike the genuine known good one.
- androng 9mo agothis is an advertisement for the company
- gnabgib 9mo agoRelated USB-C head-to-head comparison (389 points, 2023, 219 comments) https://news.ycombinator.com/item?id=37929338 https://news.ycombinator.com/item?id=37929338
- ChrisMarshallNY 9mo agoTo be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this). But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time. BTW: I “got it right,” but not because of the checklist. I just knew that a single chip is likely a lot cheaper than a board with many components, and most counterfeits are about selling cheap shit, for premium prices. But if it were a spy cable, it would probably look almost identical (and likely would have a considerably higher BOM).
- woleium 9mo agoMy apple thunderbolt 4 cable has a computer more powerful than my firs computer in it (ARM Cortex‑M0 core running at up to 48 MHz vs a 286 at 25mhz)
- shagie 9mo agoThat tickled a memory of a video... and I hunted it up. Adam Savage's Tested : Look Inside Apple's $130 USB-C Cable - https://www.youtube.com/watch?v=AD5aAd8Oy84 https://www.youtube.com/watch?v=AD5aAd8Oy84 (1 minute in "we've been saying that our phones have more computing power than the Apollo guidance computer but I'm positive now that this cable has more computing power than the Apollo guidance computer") That video is a look at cables (not just Apple's) with Lumafield's CT Scan.
- ssl-3 9mo agoLumifield quite recently showed on Adam Savage's Tested again, with some literal insights on a reasonably-diverse array of different 18650 cells: https://www.youtube.com/watch?v=AD5aAd8Oy84 https://www.youtube.com/watch?v=AD5aAd8Oy84 It's a good watch, and I learned some new stuff about some things that I only knew a little bit about before.
- Thorrez 9mo ago
- userbinator 9mo agoAfter they infamously started going after clones, anything branded FTDI is automatically suspicious. USB-serial adapters are not particularly special. Dozens of other manufacturers make them.
- hakfoo 9mo agoThis was a huge own-goal for their brand image. If I buy a FTDI based adapter, it might brick, and I lack the detection skill or supply chain control to be sure that it won't happen. If I buy a CH340 or PLwhatever based adapter, that doesn't enter the calculus. Unless I had some explicit "only FTDI can possibly do it" need, I'm going elsewhere.
- alyandon 9mo agoExactly - the FTDI drivers refusing to work would have been reasonable and emitting a log or error message that my device was counterfeit would have actually been helpful. Instead, they vandalized end user equipment by permanently bricking the devices which is arguably illegal. I am not nearly sophisticated enough as an end user to spot a counterfeit FTDI usb-to-serial device so I am not going to risk buying that brand and end up with their drivers intentionally bricking the device.
- nanolith 9mo agoI could spot the clone because I'm familiar with the form factor of the FTDI IC, and I'm familiar enough with the datasheet to spot the expected passives. I'm not too keen these days with FTDI's reputation for manipulating their Windows device drivers to brick clones. So, while I'm familiar with their IC, I don't give them any more money. The next time I need a USB to serial cable, I'll bust out KiCad to build it using one of the ubiquitous ARM microcontrollers with USB features built in. Of course, this is easier for me, since I can write my own Linux or BSD device driver as well. Those using OSes with signing restrictions on drivers would have a harder time, unless they chose to disable driver signing.
- Liftyee 9mo agoIt helps that USB to serial is a solved problem. Plenty of manufacturers make parts that work well and don't need to try and imitate FTDI.
- deleted 9mo ago[deleted]
- LiamPowell 9mo agoYou don't actually need your own driver, you can just use the CDC device class.
- nanolith 9mo agoThat's true. The only advantage of writing a driver in this case is if I wanted to add functions, such as a programmable level shifter.
- the_biot 9mo agoI think that's what happened here. I spotted the fake because it has a large number of unused pins, which would not be the case with an FTDI chip that was literally made for this. I think it's just some generic microcontroller emulating FTDI's protocol in software, but it can't keep up with high-speed transfers of course, and that's how they noticed there was a problem.
- dotancohen 9mo agoThe suspect cable actually seemed to have better strain relief for wire connections and more solder on the USB A connector (transfers mechanical stress better), even though the author pointed them out as features of the authentic cable.
- sandworm101 9mo agoThat tangle is not strain relief. Those wires are buried in injection-molded plastic. Pull on them and those loops will not stretch as they are in solid plastic. What they will do is potentially result in unwanted cross-talk between wires as loops start acting as antennas.
- dotancohen 9mo agoThank you. If I may, is injection molded plastic not solid plastic? To many potential voids?
- sandworm101 9mo agoIt is solid, which is why the wires cannot move. Molding the thing as one unit overtop the electronics is cheaper than making many parts to clamp over them as a box. A solid block is also generally better for strength and thermal.
- d0ublespeak 9mo agoThis is such a nothing burger corporate ad. They purchased a cheap cable and it sucks. So let’s X-ray it and make a thought piece post about implants…
- deleted 9mo ago[deleted]
- avadodin 9mo agoI couldn't tell a thing about the naqqadah resistor positron-brain whattamajig on the right answer but the wrong answer looked too neat for something actual people would design.
- tamimio 9mo agoInteresting, not too useful as I doubt most of the readers here have that Xray machine. I remember years ago I had similar issue, I got one of those FTDI USB cable to interfere with a drone payload, and it was simpler to just plug in the USB cable into the jetson rather than having a small exposed circuit around, but I ended up having performance issues and interruptions that eventually I replaced it with traditional FTDI exposed circuit, I still have the cable till now but I don’t have the X ray machine to check!
- MiiMe19 9mo agoThe bottom one is suspicious because it is bigger !!!!!
- thesaintlives 9mo agoWe bought an x-ray machine and need customers...
- hex4def6 9mo agoI'm failing to see the smoking gun here. There are two ways you could interpret "counterfeit". 1. Fake IC (identifies as FTDI 232 IC), fake cable (FTDI logo on it) 2. Real IC, fake cable (eg, I buy the FTDI IC and make the cable, and sell it as an "official" FTDI cable). (1) is I assume what they mean in this instance., but you could argue (2) is also possible. However, they make no mention of the packaging both calling them "FTDI" cables. Instead, I assume they're going off what they report to the OS as. FTDI have been around for decades, and the offhand "old cable we had kicking around" could easily mean its 15+ years old. That might easily explain the chip size difference. In this case, FTDI did make TSSOP 28-pin chips for a long time. They're now obsolete, superseded by SSOP package variants (like in the "Real" picture). Put another way, this is like comparing an i5-10400 to a Pentium II that I found in my storage closet and declaring the Pentium II fake. The actual fake chips visually look identical to the real ones. Obviously, otherwise they wouldn't get mixed into the supply chain. The only real conclusion they can realistically make from these x-rays are that they're not the same cable (but even then, I don't know if FTDI real cables have silently upgraded the internals while retaining the same SKU).
- krater23 9mo agoThey only wanted to say 'Hey look, we have borrowed a x-ray mashine'
- sllabres 9mo agoFrom the article: "The consequences for a consumer buying a shady USB cable likely aren’t too bad". I can't second that, but more to the software/driver side. Without my knowledge, I once had a counterfeit cable that costed several days of my life. At that time, the FTDI drivers recognized (and as I read did some other things [1]) that a counterfeit cable was connected, but instead of simply disabling the function, they impeded it. In my case: After pressing the first few keys on terminal connection, the transmission from the device to the PC worked, but not the reverse direction. A long search for the error came to an end after I replaced the USB/RS232 with a new one. This was with windows, with Linux even the counterfeit worked. [1] https://www.elektroda.com/qa,ftdi-ft232-scandal-driver-bricking-2024.html https://www.elektroda.com/qa,ftdi-ft232-scandal-driver-brick...
- kundejenny 9mo ago[dead]