Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.
Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.
How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromised Intel Management Engine firmware signing key to put firmware rootkits in cheap hardware sold to individual consumers.
On an embedded system like the OpenWRT Two where the entire BOM of the system will be public and the OS has full control over the raw flash memory, a purely software-based supply chain attack would be extremely difficult, and a hardware-based supply chain attack would be expensive. Do you think an intelligence agency would really bother with this for a device that is mostly going to be shipping to nerdy hobbyists?
There's more to a threat model than just recognizing that an attack may be technically feasible.
Based on their track record? Pretty fucking reasonable.
I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and swore it was so full of holes to be unusable.
The ingrained extreme cheapness of Chinese culture doesn't help. Security is viewed as a luxury - why waste time and money on it when that could be better spent elsewhere?
That said, the incompetence gives them plausible deniability when the intelligence agencies take advantage to exploit the holes for their own use.
Shipping telco hardware with a massive bespoke software stack implementing an impossibly-complex pile of standards is very different from what we're talking about here.
If your MSI motherboard is installing Nahimic without an internet connection, it is doing so through a mechanism where the installer is made available to the OS in an ACPI table that Windows checks. That check can be disabled with a registry key to prevent such software from being re-installed, and the motherboard may have a BIOS option to disable the anti-feature (though the registry key method is generally more effective, since BIOS settings often get reset to defaults).
Historically remote code execution in the IME.
> an incompetent PC OEM
And then it never gets patched.
That's only a problem if the Active Management Technology feature is correctly supported by the OEM including wiring it up to a supported NIC, and the feature is enabled and provisioned by default, and the NIC in question is connected to a network that is a potential attack vector.
From what I can tell, the current NIC of choice for Chinese router PCs is the Intel i226-V, and such PCs come with 4-8 of those. In order to work with the Active Management Technology feature, those would have to be the more expensive i226-LM or i226-IT parts. So AMT is impossible to enable on those PCs and there's no part of the boot firmware that continues interacting with any NIC after the OS has taken over managing PCIe peripherals.
Are you sure about that? Because I remember something called ACPI that gets executed by the OS every time some configuration changes, such as power levels.
Do you see the problem here?
Which ACPI table do you expect to be used for delivering malicious executable code?
Do you have a link? Would be nice to know more technical details.
As opposed to the US, where it's the other way around [1]. You prefer that?
On HN there is an echo chamber with the shunning of companies who have experienced incompetence based breaches. Your average consumer does not know (beyond the news cycle) or generally even really care.
I think you can even look at FBI and NSA public service announcements and guides about consumer electronics security as a sort of ''shit this industry stuff is pretty bad we need to think about our goal differently,'' with regards to them trying to pick up some of the security slack that US companies shit out with their products.
When you’ve got the sort of reach and resources they have, it does you no good if script kiddies or unsophisticated attacks are causing problems and you don’t need the easily preventable attack vectors they’d use.
No one stops you from doing so, just know you will probably be part of a botnet sooner or later.
The problem seems to be that this firmware doesn’t really get updated once the machine is sold.
That’s legitimate criticism for a security-critical network component.
Running an up-to-date OpenWRT or pfSense on a normal PC hardware platform with outdated UEFI firmware is still a big step up in security compared to running factory firmware+OS on a cheap consumer wireless router.
We need adversarial competitive firmware that comes from different sources the same as we have for software.
I know why we don't have that. It doesn't change the fact that that is what we need.
Don’t bother importing. They should start seizing these at the port
As I said, GL.iNet is a popular company.
I didn't say that having a Wikipedia page proves that a company is legitimate.
I know how Wikipedia works.