• ChrisMarshallNY 3 hours ago

    To be fair, this story is basically an ad, but a pretty good one, and many featured HN stories are really marketing. Personally, I don’t mind marketing stuff, if it’s interesting and relevant (like this).

    But the fact that most comms cables, these days, have integrated chips, makes for a dangerous trust landscape. That’s something that we’ve known for quite some time.

    BTW: I “got it right,” but not because of the checklist. I just knew that a single chip is likely a lot cheaper than a board with many components, and most counterfeits are about selling cheap shit, for premium prices.

    But if it were a spy cable, it would probably look almost identical (and likely would have a considerably higher BOM).

    • woleium 2 hours ago

      My apple thunderbolt 4 cable has a computer more powerful than my firs computer in it (ARM Cortex‑M0 core running at up to 48 MHz vs a 286 at 25mhz)

      • quietsegfault an hour ago

        Huh! I originally thought the bottom one was authentic because the main IC looked a lot “nicer”. Then I saw the jumble of wires to the right and rethought.

        • bragr 19 minutes ago

          If you look closely at the bottom one, almost all the components are slightly askew, while the top one has everything at neat 90 degrees. And a smaller IC almost always means the more modern/expensive IC. Same for the other components. In fact, the top one has a much higher component count, the small components just don't show up well (look at the pads though).

      • invokestatic 4 hours ago

        I have a slow burn project where I simulate a supply chain attack on my own motherboard. You can source (now relatively old) Intel PCH chips off Aliexpress that are “unfused” and lack certain security features like Boot Guard (simplified explanation). I bought one of these chips and I intend to desolder the factory one on my motherboard and replace it with the Aliexpress one. This requires somewhat difficult BGA reflow but I have all the tools to do this.

        I want to make a persistent implant/malware that survives OS reinstalls. You can also disable Intel (CS)ME and potentially use Coreboot as well, but I don’t want to deal with porting Coreboot to a new platform. I’m more interested in demonstrating how important hardware root of trust is.

        • userbinator 3 hours ago

          I don't want Boot Guard or any of that DRM crap. I want freedom.

          I want to make a persistent implant/malware that survives OS reinstalls.

          Look up Absolute Computrace Persistence. It's there by default in a lot of BIOS images, but won't survive a BIOS reflash with an image that has the module stripped out (unless you have the "security" of Boot Guard, which will effectively make this malware mandatory!)

          I’m more interested in demonstrating how important hardware root of trust is.

          You mean more interested in toeing the line of corporate authoritarianism.

          • invokestatic an hour ago

            Well, this project is literally about me circumventing/removing Boot Guard so I don’t know how it’s corporate authoritarianism. I’m literally getting rid of it. In doing so I get complete control of the BIOS/firmware down to the reset vector. I can disable ME. To me, that’s ultimate freedom.

            As a power user, do I want boot guard on my personal PC? Honestly, no. And we’re in luck because a huge amount of consumer motherboards have a Boot Guard profile so insecure it’s basically disabled. But do I want our laptops at work to have it, or the server I have at a colocation facility to have it? Yes I do. Because I don’t want my server to have a bootkit installed by someone with an SPI flasher. I don’t want my HR rep getting hidden, persistent malware because they ran an exe disguised as a pdf. It’s valuable in some contexts.

            • taneq an hour ago

              Some days you’re the anarchist, some days you’re the corporate authority. :D

            • taneq 2 hours ago

              > You mean more interested in toeing the line of corporate authoritarianism.

              That’s not what I got from their post. After all, they’re putting in some effort to hardware backdoor their motherboard, physically removing BootGuard. I read it as “if your hardware is rooted then your software is, no matter what you do.”

            • yjtpesesu2 14 minutes ago

              Death approaches. Slow burn until. When Death arrives, what you are doing now will be obviously irrelevant.

              • Nextgrid 4 hours ago

                > persistent implant/malware that survives OS reinstalls

                Try attacking NIC, server BMC or SSD firmware. You will achieve your goal without any hardware replacement needed.

                • invokestatic 4 hours ago

                  Yeah, but that doesn’t give me a reason to use the hot air station and hot plate collecting dust on my desk ;)

                  • cbsks 3 hours ago

                    Nothing drives more creativity from me than a tool in need of a project.

                    • da_chicken 3 hours ago

                      I mean, you could also do smartphone repairs.

                  • mschuster91 4 hours ago

                    > I want to make a persistent implant/malware that survives OS reinstalls.

                    You want to look into something called "Windows Platform Binary Table" [1]. Figure out a way to reflash the BIOS or the UEFI firmware for your target device ad-hoc and there you have your implant.

                    [1] https://news.ycombinator.com/item?id=19800807

                    • baby_souffle 2 hours ago

                      > You want to look into something called "Windows Platform Binary Table" [1].

                      Is this how various motherboard manufacturers are embedding their system control software? I was helping a family friend with some computer issues and we could not figure out where the `armoury-crate` (asus software for controlling RGB leds on motherboard :() program kept coming from

                      • Nextgrid 2 hours ago

                        That most likely comes from Windows Update though. It now has the ability to download "drivers". It actually had said ability for a long time (back from Vista days if I remember right) but back then it was only downloading the .inf file and associated .sys files/etc, where as nowadays it actually downloads and runs the full vendor bloatware.

                        • BobbyTables2 2 hours ago

                          Likely so. I think that’s actually the intended use of this “feature”

                        • ronsor 3 hours ago

                          Only works if the target is running Windows (paranoid people might be on Linux), so you'd probably want to slip in a malicious UEFI driver directly. Tools like UEFITool can be used to analyze and modify the filesystem of a UEFI firmware image.

                      • gregsadetsky 4 hours ago

                        Yeah - these [0] kinds of cables are so extremely scary.

                        "The O.MG Cable is a hand made USB cable with an advanced implant hidden inside. It is designed to allow your Red Team to emulate attack scenarios of sophisticated adversaries"

                        "Easy WiFi Control" (!!!!!)

                        "SOC2 certification"? Dawg, the call is coming from inside the house...

                        [0] https://shop.hak5.org/products/omg-cable

                        • mschuster91 4 hours ago

                          > "SOC2 certification"? Dawg, the call is coming from inside the house...

                          Helps corporate red teams in environments where the purchase department is... a bunch of loons.

                        • commandersaki 4 hours ago

                          Just to be clear suspicious in this sense is a cable that is likely counterfeit and wasn't able to do high speed transfer unlike the genuine known good one.

                          • nanolith 2 hours ago

                            I could spot the clone because I'm familiar with the form factor of the FTDI IC, and I'm familiar enough with the datasheet to spot the expected passives.

                            I'm not too keen these days with FTDI's reputation for manipulating their Windows device drivers to brick clones. So, while I'm familiar with their IC, I don't give them any more money. The next time I need a USB to serial cable, I'll bust out KiCad to build it using one of the ubiquitous ARM microcontrollers with USB features built in. Of course, this is easier for me, since I can write my own Linux or BSD device driver as well. Those using OSes with signing restrictions on drivers would have a harder time, unless they chose to disable driver signing.

                            • LiamPowell 19 minutes ago

                              You don't actually need your own driver, you can just use the CDC device class.

                              • nanolith 9 minutes ago

                                That's true. The only advantage of writing a driver in this case is if I wanted to add functions, such as a programmable level shifter.

                              • Liftyee an hour ago

                                It helps that USB to serial is a solved problem. Plenty of manufacturers make parts that work well and don't need to try and imitate FTDI.

                              • userbinator 3 hours ago

                                After they infamously started going after clones, anything branded FTDI is automatically suspicious.

                                USB-serial adapters are not particularly special. Dozens of other manufacturers make them.

                                • trinsic2 4 hours ago

                                  Jeese. I was not sure which image was the suspect one.

                                  • blibble 3 hours ago

                                    the one which looks cheaper to manufacture

                                    which is definitely the second

                                    • llbbdd 25 minutes ago

                                      This is how I ID'd it; I have next to zero experience with ICs, but I've opened up a lot of devices for fun or repair and the cheap stuff always has wiring haphazardly contorted like the left side on the counterfeit, like someone had to force it in there and squeeze it shut just to get it out the door.

                                    • Mawr 28 minutes ago

                                      You don't need any specialized knowledge, just pick the one that looks "cleaner" and "neater" than the other.

                                      It's sufficient to look at something as basic as the arrangement of cables on the left. The crooked electrical elements on the right are also a big tell.

                                      This works because good—and bad—qualities correlate with each other.

                                      • kps 3 hours ago

                                        They gave it away by saying the genuine cable was a 234 series (small basic UART) and not a 232 (big ol' 28-pin chip).

                                        • Neywiny 4 hours ago

                                          If you've read the docs, which I'm not saying anyone is expected to, FTDI tends to put buffers on their outputs. That's what gave it away for me. The little sot-23-5 footprints.

                                          • mjevans 3 hours ago

                                            I got it backwards because I expected the counterfeit part to use a newer process IC (less silicon area) than a possibly more reliable and perfectly suitable for serial connection speeds 'vintage' process on some long stable spin of silicon.

                                            Why allow for newer processes on the counterfeit? They'd implement it using the least expensive, most mass produced chips possible, which are more likely to be cut from wafers hitting the sweet spot of size / feature and price crossover.

                                            • trinsic2 4 hours ago

                                              I wanted to try and figure out out before I did that. No dice.

                                          • gnabgib 3 hours ago

                                            Related USB-C head-to-head comparison (389 points, 2023, 219 comments) https://news.ycombinator.com/item?id=37929338

                                            • androng 3 hours ago

                                              this is an advertisement for the company

                                              • stainablesteel 4 hours ago

                                                it's a serious problem

                                                they could be regulated to expose their chip with transparent covering rather than plain dark wiring