Android devices with backdoored firmware found in US schools
securityweek.com
securityweek.com
> A Chinese manufacturer (possibly many manufacturers) builds a wide variety of Android-based devices, including phones, tablets, and CTV boxes. At some point between the manufacturing of these products and their delivery to resellers, physical retail stores and e-commerce warehouses, a firmware backdoor— based on Triada malware—gets installed and the product boxes are sealed in plastic, priming these devices for fraud on arrival at their destination.
Isn't it OK to name that manufacturer and affected brands?
US brands deal all the time with dilution due to counterfeits made in sketchy factories.
Why protect the manufacturer/brands in this one case? Especially when there's a particularly problematic supply chain problem involving the manufacturer, and to which they might be especially vulnerable (if not complicit or even the perpetrator)?
In addition to the obvious reason of providing negative feedback to parties involved and in a position to improve, the last sentence of the article demonstrates how not naming them hurts legitimate but lesser-known/upstart brands who are not involved and who don't deserve the negative feedback:
> recommending that users choose familiar brands when purchasing new products.
Any US Companies targeting the US education system as clients comes with insane markup (anything iPad). The US based companies are still going to data collect (see chromebooks) the schools are so underfunded, their only choice is to use cheap Non-US knock offs.
The second you want any educational specific SKUs, though, holy shit.
It is probably not the case in this instance, but the NSA TAO does this for a living.
Why not ? Especially given the case that they were bought in bulk so this made life more easier.
Ciscos are also made in China but i don't see people blaming China for Cisco's backdoors.
Because it doesn't matter. It costs 0.01USD to change the name of the manufacturer and brand tag, or even to no-name at all. The entire factory line and staff can be renamed/reallocated by the customer's wish.
I disagree, it does matter. It might not be a silver bullet that prevents this problem from ever happening again, but it helps the public stay away from devices that are already in the market and provides the necessary information to track and avoid manufacturers.
> It costs 0.01USD to change the name of the manufacturer and brand tag, or even to no-name at all.
It's still the same device. You can identify it by looking at it. It might not prevent further abuses, but it helps counter the ones already in place.
There is zero reasons to not name the manufacturer.
Also, the article might just as well avoid mentioning that the brand is Chinese. Like this, this article can be dismissed as slander against Chinese brands in general.
Good luck with that. I have a friend that only buys no-name AliExpress specials, boasts about how cheap they are, and then bitches to me about all the problems he has with them.
> Amazon regularly delivers what I ordered,
Given that Amazon's biggest problem is counterfeits, are you sure?
There's a reason their return policy is so generous.
Any good way to detect if their firmware has been backdoored once you got one in your hands?
This. I recall I bought an Orange Pi Zero 512MB out of AliExpress for about $5. Great deal, but I would definitely not trust it to do anything with private info though.
Nothing gets past the Portmaster.
kinda reminiscent of the mess with id and ssn.
I'd love to see a foolproof solution that makes it so that only the (non-tech-savvy) person who actually purchased the device and owns it gets to install third-party software without risking a supply chain attack before it gets in their hands.
Apple's restrictions exist to protect their 30% cut of all software revenue. Any other benevolence you perceive to be there is naive.
One of which is checking for private API usage which would allow developers to cause all sorts of unchecked havoc.
And because of the way Objective-C apps work i.e. dynamic dispatch you can't statically check for it in the binary when the app is launched. Nor can you realistically check it at runtime since that code path is the hottest there is and needs to be highly optimal.
I suspect that there will be an App Store SDK that third party stores will need to use that incorporates these sort of checks.
This is simply not true. The security boundary is not at that layer. Calling private methods doesn't escape the sandbox.
0: https://github.com/nst/iOS-Runtime-Headers/blob/fbb634c78269...
1: https://github.com/nst/iOS-Runtime-Headers/issues/32
2: https://github.com/nst/iOS-Runtime-Headers/tree/fbb634c78269...
After some exploit gets patched is when all the inventory sitting in logistics become at risk of interception and compromise.
They don't need the App Store to do that. Xbox and Playstation have retail stores selling their software and they get a cut all the same because if they refuse to sign your game executable ... it won't run on end user machines.
(About the same as Chromebooks, actually)
Apple puts a lot of effort into having a secure, verified supply chain. That costs money. Unfortunately, the benefits of all that effort are hard for most people to measure. Apple measures it by looking at their overall reputation. They'd rather be known for having expensive products than for faulty or untrustworthy ones.
As a counter-example, consider the Precursor[1] who's CPU is "... an SoC on an FPGA, which means you can compile your CPU from design source and verify for yourself that Precursor contains no hidden instructions or other backdoors."
Device manufacturers could ship firmware as FPGA images, such that end-users can start with a "blank slate" and then install arbitrary firmware upon delivery. They choose not to.
I'd also add that computers have multiple CPUs, and an FPGA and an M1, for example, could coexist, with the FPGA serving as the BIOS and firmware repository. I think there are real and frankly chilling reasons why manufacturers will not take this approach, and it's not because of economics. A truly free device is a threat to the establishment.
For very good reason. Last I checked, FPGAs capable of running any sort of fast, modern core are typically more expensive than a new iPhone.
But “it’s FPGA and you can see the code”… ok, fucking lol though. HeartBleed OpenSSL was an issue for how many years and the code was open to a hundred million people who could read it in some language. I know FPGA developers they couldn’t even remotely follow a softcore CPU configuration. You are talking about less than 100,000 people in the world, and even that is probably way generous, maybe 30k?
It's also true that, because of historical accidents, we have several more examples of https://xkcd.com/2347/. However, that's not an argument against open source. It's an argument that we all should take ownership of what we ship, all the way down, without exception. An open CPU definition is a necessary, but not sufficient, requirement for this level of ownership.
This is a strawman - people want to be able to buy from Apple's manufacturers at the component level, i.e. they want to be able to buy the $5 charge port instead of being forced to buy the $1300 mainboard the charge-port is soldered onto. Apple deliberately prevents their manufacturers from selling the exact same part to third party repairers, while simultaneously refusing to sell it themselves.
Apple has two satisfactory options here: either stop actively blocking their manufacturers from selling direct, or start selling the components themselves.
During boot, display a message: "Bootloader unlocked. Non-Apple-approved software has been installed. Unless you did this, the device may be compromised. To factory-reset the device, do the following.."
There are already phones that notify you of bootloader lock state. In fact, tamper-evident devices are a very old technology. It is only because it is profitable to them, does Apple pretend they don't exist.
(Ideally it should also allow to install user owned keys for verification and display their fingerprints, but that's the next step...)