FTDI driver kills fake FTDI FT232s
eevblog.com
eevblog.com
If FTDI have an issue with a company ripping off their IP then go sue that company. But what they're doing is catching consumers in the firing line, who will wind up with multiple dead USB devices. There's no reasonable way a consumer can know they are buying something with a fake chip and this could kill devices years old, which will be outside of warranty.
I am totally serious that Microsoft should step in. FTDI's driver is so defective that it is literally killing hardware, if they won't step in for this then what will they step in for?
Without access to the source code or a well-reversed disassembly of the FTDI driver, and a good grasp of the logic used in the counterfeit chip, one cannot be certain about this. And surely not to the extent of urging Microsoft to revoke driver signatures.
http://www.ftdichip.com/Drivers/FTDriverLicenceTerms.htm
"Use of the Software as a driver for, or installation of the Software onto, a component that is not a Genuine FTDI Component, including without limitation counterfeit components, MAY IRRETRIEVABLY DAMAGE THAT COMPONENT."
May cause more problems than it fixes.
Of course if they have deliberately broken people's hardware that is a different matter, that clause in the license does not give them permission to in any way (either by my reading of the wording, or my understanding of how the law usually works in such cases).
Of course they should roll back the drive and investigate, but what if the problem is due to a new feature that can't be implemented some other way, and there is no way to detect a "genuine" chip? Should users of their chips do without a feature (or have to mess around opting in) because some other manufacturer's chip has a problem with it?
The only law broken by the counterfeiters is trademark violation for printing the FTDI logo on their chips. That's it! Everything else they did was legal. Otherwise, Intel and AMD would be bricking CPUs right now.
Reverse engineering is legal. Emulation is legal. Creating hardware that's compatible with another vendor's software is legal. Flashing your hardware with another vendors firmware is legal. Modifying hardware you purchased from a vendor is legal. Modifying software you purchased from a vendor is legal.
etc... etc...
Does anyone even know what entity designed and made the fake FTDI chip?
I find many people don't seem to understand what making compatible chip means. It's very common to have legitimate, drop in replacement for popular ICs. But this fake FTDI chip is certainly not the case here.
:-)
It doesn't matter if it's trademarkable. The entire purpose of VIDs is to distinguish between different vendors' devices. If I'm allocated a VID it's not my responsibility to ensure my drivers interoperate with other vendors' products.
How many products using counterfeit FTDI chips don't advertise USB compliance?
There are legal routes available to FTDI that don't involve bricking devices. I'm guessing that FTDI didn't talk to internal counsel before making this change.
I'll be quite surprised if Microsoft doesn't pull this patch.
marcan: "In case anyone was still wondering if this is intentional and malicious... Straight out of their driver. Function/variable naming and comments mine.
https://marcan.st/transf/ftdi_evil.png
I figured out what's going on with the real chips: turns out their EEPROM is written in 32bit units. Writing to even addresses is ignored; the value is buffered and the address discarded. Writing to odd addresses writes the entire 32bits, using whatever value was last buffered for the other half. So both the PID write and the checksum write are ignored on real FTDI chips, as they are both written to even addresses. I still don't know why it works on clone chips though, since the checksum is written to the wrong place (it should normally be on an odd address); presumably they don't check it."
Basically driver is fuzzing 'chips claiming to be FTDI' with illegal instructions. Want to play clone games? better emulate me completely, otherwise tough titties. I like it. Might not work to well for FTDI in the end due to PR nightmare, but from engineering standpoint its quite brilliant.
> A company can choose to sign their own drivers rather than go through the WHQL testing process. These drivers would not qualify for the "Certified for Windows" logos, but they would install on 64-bit versions of Windows and install without a warning message on 32-bit versions of Windows Vista or Windows 7. However, it will not install without a warning message on Windows XP.
If they are, I don't know enough about how rigorous Microsoft's certification process is now to comment. It used to be just looking for things that would cause kernel instability but it seems the standards have increase a lot since its exception.
http://zeptobars.ru/en/read/FTDI-FT232RL-real-vs-fake-supere...
Exerpt:
"What's the economic reason of making software fake of well-known chip instead of making new one under your own name? This way they don't need to buy USB VID, sign drivers in Microsoft, no expenses on advertisement. This fake chip will be used right away in numerous mass-manufactured products. New chip will require designing new products (or revisions) - so sales ramp up will happen only 2-3 years later. Die manufacturing cost is roughly the same for both dies (~10-15 cents)."
http://en.wikipedia.org/wiki/Semiconductor_Chip_Protection_A...
It's also completely legal to reverse-engineer an existing IC to duplicate its functionality in a different manner, which the cloners have definitely done in this case - they are completely different.
So it appears that the only thing the fake FTDI chip is violating is the trademark "FTDI", which might not even have been put there by the fab that produced the die, since they're branded 'Supereal'.
"It seems that in this case Chinese designers implemented protocol-compatible "fake" chip, using mask-programmable microcontroller. This way they only needed to redo 1 mask - this is much cheaper than full mask set, and explains a lot of redundant pads on the die."
Besides, any legitimate compatible chip vendor will need to have their own VID, which also means they need to develop their own compatible driver.
Unless there's a valid patent at issue (and nobody's mentioned a patent at all), there is nothing about the chips themselves that violates any law.
Defending vigilantism is disgusting enough when you have a colorable argument that the target of your act is the only one harmed, and is actually guilty of some sort of legal violation.
Here, however, you're defending vigilante destruction of the property of end-users who bought a product with a chip in it that, without the user's knowledge, may or may not have passed through the hands of someone who may or may not have labeled or described it deceptively.
The deceptive party may not even exist, and even if they do, they are not the victim of the vigilante justice. A user who may not have even heard of FTDI is the victim.
Again, I'm merely trying to express my opinion that this way of making compatible chips is a very shady practice (and unlike that original comment I replied to was implying, typical market competition). Most users didn't choose the chip just because it's compatible and cheaper. They bought it thinking it's the legitimate FTDI chips with (very specific) guarantees from its manufacturer's datasheet.
Eh....... Lots of people knew/know they are/were getting counterfeit chips. It's certainly shady, but if I were a chinese company making these, I'd simply not use the logo anymore and then sue the pants off FTDI.
Counterfeit isn't the issue here so much as competing non-FTDI chips relying on FTDI to do the hard and expensive work of developing drivers for them.
Bricking non-FTDI hardware was extreme and guaranteed to make people angry. I wonder what the reaction would be if FTDI had instead made the driver not work on non-FTDI chips unless the end customer bought a license key from FTDI to use their drivers.
This will not do wonders for FTDI's credibility. Indeed, it could very well put them out of business for good (from past experience), and we already know whoever's behind these clones can make a chip that does the job at a price people want…
Takeaway lesson: End users should never touch anything remotely FTDI-like, since it's probably impossible to verify if the device is genuine or not. Wonder if FTDI thought this through.
I actually hope that this does cause an event drastic enough so that FTDI will have blood on its hands that ends in jail time for management and engineers. I don't want to see anyone hurt, especially not innocent third parties, but fuck FTDI, fuck the management who ordered this, and fuck the engineer(s) who didn't quit in protest. I'm not easily offended, but as a programmer who has been responsible for code that would result in loss of life if I made it defective by design, I have no sympathy for this sort of thing. One other thing that I could hope for is that this teaches everyone the true cost of closed source, especially drivers. Don't put up with it.
As far as unethical behavior by corporation is concerned I really not think it's even noteworthy.
We're talking infrastructure: if this was a civil engineer designing a road to spontaneously create potholes that would flatten tires on certain brands of vehicles, they'd be put in the slammer post haste. FDTI has no idea where their chips and drivers will end up, and as designers of such low-level infrastructure type devices, it is criminally negligent to intentionally brick hardware. If I designed a file I/O library to randomly corrupt data when used on Windows, I'd be criminally negligent.
As far as unethical behavior by corporation is concerned I really not think it's even noteworthy.
Destroying other people's hardware to try to ensure your profits? No, not unethical or noteworthy at all.
And if a civil engineer designs a bump in the road that will destroy your suspension if you are driving above the speed limit they have set, we'd just call it a speed bump
I said it was unethical.
I say it might not be noteworthy when you compare it to business who are actually hurting human beings right now: companies who destroy ecosystems, companies who employ underpayed workforce in sweatshops to increase their profit margin. Companies who sell tools and weapons used to oppress people in authoritarian countries. I could go on for a long time enumerating the list of unethical behaviors in the industry before I hit the "releasing drivers that willingly brick IP infringing copies". So yes I find your reaction a bit over the top even if you're right that they deserve to get some backlash for this type of shoddy behavior.
Can you picture a Linux or *BSD driver in which there is an intentional
if (counterfeit) { do_damage(); }Just because the code is available doesn't mean it does no damage. Only that you have the ability to find and fix the code.
As a side note, are there any known cases where a vendor has released open source code that intentionally bricks a device? I'd be surprised if they were not found legally liable if the intent was spelled out so clearly.
Perhaps you'll like this example better? https://www.google.com/patents/US4577289 "Hardware key-on-disk system for copy-protecting magnetic storage media"
There are physical holes on the disk. "The test program writes the sections with a test pattern which generates a change in the pattern of magnetic domains of the medium, a subsection at a time, with a subsection responding to the test pattern only in the absence of indicia thereon, to form a stored pattern on the given section. An expected pattern and the stored pattern are compared at least a subsection at a time to determine if corresponding subsections have a predetermined pattern of magnetic domains."
If you have "insert key disk now", followed by a write to the disk, and then a verification, then a standard disk/non-key disk will get corrupted.
That 'bricks' non-brand floppies by design, under the aegis of copy protection.
There's been open source with back doors in it. Eg, Firebird had one that took about 6 months to detect, after source code release.
In listening to the various accounts of GPL enforcement, it isn't always easy to track down the actual vendor. Quoting from http://www.infoworld.com/article/2617579/open-source-softwar...:
> Always keen to shave the last few cents from their bill of materials, these manufacturers tend to procure their firmware from low-cost suppliers that have in turn delivered open source software without passing on its licensing terms. It can come as a surprise to the hardware manufacturer to discover a violation of the license terms.
While that's about incorrect use of licensing terms, it shows there's no reason why the manufacturers are aware of all of the code in the software they sell.
I think intent would definitely play a role in establishing liability for damaged equipment (i.e. the user misusing the device versus the company tampering with the user's equipment).
Also your shenanigans become visible. You'd have to code extremely carefully to break the fake with plausible deniability, and even then your name as a developer would forever be mud.
Whether FTDI screwed customers is a debatable question. In any event, FTDI definitely screwed themselves.
I doubt very few vendors will realize if a fake FTDI chip is part off their manufactured product even after rigorous testing since the functionality is correct (until you get this driver).
EDIT: I doubt FTDI have thought this through. I will share this with the hardware designers I know and most will probably react like on the linked thread, and just switch to another chip to avoid any possible hassle.
- Intentionally sabotaging someone's stuff, legally, is more or less the same as intentionally taking it. Keying a car and driving it away might have different names but are on the same scale.
- There ain't no self help. If you think someone else's stuff should actually be your stuff, your path is through a court.
- We don't fix things with injunctive relief that can be fixed with money. When Apple proves that Samsung violated a patent or vice versa, we don't collect and burn all the infringing phones, we just make someone cut a check. Because we are not idiots.
- The "someone" who cuts the check is Samsung or Apple, not their customers. As far as I know no one's managed to go after end users, even in extreme cases like a $10 designer handbag where the buyer obviously knows it's not real. (And it's at best unclear whether going after the buyers would make any sense, even in those extreme cases -- if someone pays knockoff prices for a knockoff product, it's the seller and not the buyer who has ill-gotten gains. There might be some additional reputation damage and lost profits that the buyer is complicit in, but it makes a lot more sense to me -- and apparently everyone else -- to make the seller pay for those as well.)
- When you do go after the seller of trademarked goods and want to seize those goods, we actually have a procedure for that -- Section 34 of the Lanham Act.[1] Which includes a whole bunch of protections like swearing out an affidavit, getting permission from a judge, informing the attorney general, posting a bond to cover damages, conducting the seizure through government agents, and keeping the seized items in the custody of the court. It's very much unlike showing up at someone's house and breaking their stuff.
(I am a lawyer; I am not a trademark lawyer; I just googled some stuff based on vague memories from law school to write this.)
Destruction of trademark-infringing goods and copied media is quite common, though.
In the UK, deliberately sabotaging hardware with drivers could be counted as a violation of the Computer Misuse Act, but there are hardly ever any prosecutions under that law.
They aren't the first to do malicious copy-protection. It did not go well for the previous contenders. At all.
Think about it this way. Suppose the driver works like this:
``` if(counterfeit()){ // do something harmful to the identified device } ```
If you have a counterfeit chip, and you run the driver, and the driver breaks your chip, then you are in fact using the "official driver" for its "intended purpose." Its intended purpose is to break your chip, and it works just fine. It just lied to you about its intended purpose in order to persuade you to install it.
Of course if the code does something that is safe and useful to do on the legit chip, and just happens to break the counterfeit chip, that's very different. I don't claim to know which thing is happening in this case.
In what universe can them doing a preimage attack on the checksum "just happen"?
* That doesn't mean you can shoot them as they ride away.
* It also doesn't mean you can booby trap your bike.
I think in the FTDI case, though, it would be really hard to argue that the end users should (or even could) know that the chip they have is counterfeit.
I think this is totally crappy. I see what they're trying to do (create market incentive for consumers to insist on real FTDI chips) but the reality is that it's just screwing over innocent consumers who buy a device.
The consumer isn't exactly innocent.
Hold on, hear me out.
It's similar to black market goods. A consumer wants the lowest possible price. It turns out the goods he bought are stolen property. He didn't know, but he is not waived of responsibility. If he was truly unwitting he will not be prosecuted, but the goods will still be repossessed, etc.
Basically, it is the consumer's drive for the lowest price that creates the market for these illicit goods, so they are not blameless. Additionally, illicit supply chains are hard to attack and often times the consumer "really should have known better", so one of the ways to attack that supply chain is by slapping the hand of the consumer who patronized it, whether or not they actually meant to buy stolen goods.
It's hard to deal with the "Well it was cheap and he was shady but I just didn't ask too many questions" purchases; responsibility is very diffuse, with everyone doing their best to avoid responsibility.
If a Sony product happens to have a fake FTDI chip in it, this is FTDI's way of incentivizing Sony (via angry customers) to manage their supply chain, because as you say there's an incentive even for Sony to cut costs where they can- perhaps by turning a blind eye when they get some suspicious batches of chips for a great price, and claiming ignorance later...
Everyone, in demanding the lowest price no matter what (all the way up the supply chain) bears part of the blame.
We are of course witnessing a visceral response on the part of HN voters reacting to my comment, who are exemplifying why this is a hard problem to tackle. It isn't MY responsibility!
Your use of the word "blame" implies that you think there's some wrongdoing on the part of someone other than FTDI. As far as I can see, there's absolutely nothing wrong with the production and use of these clone chips except that they are being labeled with FTDI's trademark. They're piggybacking on FTDI's software work, but that's nothing that the government has an interest in stopping. If FTDI doesn't like people using their software without buying their hardware, they can resort to more traditional means like not giving out their software so freely or including DRM.
Your use of the word "blame" implies that you think
there's some wrongdoing on the part of someone other than
FTDI.
I don't see it as particularly controversial to say that, when someone selling an item claims it's a certain brand, I expect that to be the truth.For example, if I buy an apple iphone I expect to get an apple iphone and if the supplier instead sends me a fake I regard that as wrongdoing on the part of the supplier.
Likewise, if a designer has specified an FTDI part and someone in the supply chain has substituted a fake, I'd regard that as wrongdoing.
Accidental second-sourcing doesn't
really hurt anyone other than the
first source.
It hurts the entire electronics industry industry if I can't trust that a part is what it's labelled as, or if I can't trust a supplier not to deliver fake parts.If your suppliers can substitute a fake FTDI part, why not label 10% precision resistors as 1% precision, or label 1,000-operating-hour capacitors as 30,000-operating-hour, or label parts that failed temperature range binning as having passed temperature range binning?
And the people who really lose out from this aren't the Apples and Samsungs of this world, who do enough business that the promise of future work can keep the suppliers honest - it's the small manufacturers and kickstarter projects that aren't big enough to have the leverage to keep their suppliers in line.
This is FTDI's way of incentivizing companies using consumers, like I said in my original comment, and it sucks.
I didn't know. But it still gets repossessed, and I'm still out $1k.
(True story, and my first brush with the laws around black markets)
Edit: Apparently I don't proof-read
In this case, screwing the innocent purchaser of a chip that is a knock-off is entirely unwarranted. It's hard to see how it wouldn't be a breach of the Computer Misuse Act 1990 in my country (England), which would seem to make impairing the operation of the component a criminal offence here.
Edit 1: Clarify wording/citation.
Edit 2: If I'm looking at the right company web site, these guys are actually headquartered in Scotland. I'm not sure whether the exact same law applies in their jurisdiction.
These chips didn't fall off the back of a truck. They were in most cases legitimately manufactured and sold to an informal spec.
It's been about 5 years and they've still yet to actually fix it.
EDIT: just realized that I was thinking of the PL2303, which had a similar issue, not FTDI.
If they let it continue more devices may hijack their USB VID, perhaps with bugs and glitches. Should they patch their driver to protect their reputation?
FTDI's responsibility for supporting counterfeit devices ends a long way before tampering with them.
I think the moral high road to take in this situation would be to ignore the clones, but failing that, the approach which Prolific have taken (make the driver refuse to start on a known counterfeit device) seems a lot better than intentionally introducing bugs and not completely ludicrous like damaging the hardware.
=====
Hi,
I've been advised to email this address by 'XXXX' at Microsoft Support.
FTDI is shipping a malware driver for Windows; if it detects what it thinks is a counterfeit device plugged in by USB, it bricks it. Details here:
http://www.eevblog.com/forum/reviews/ftdi-driver-kills-fake-...
I've also attempted to report this by phone as suggested by XXXX. I've never experienced such difficulty trying to report a security issue; I'd have expected that you'd have processes in place, but apparently not.
My first attempt was met by a CSR who informed me that he knew of no protocol for reporting security issues, and that he couldn't help me because it wasn't directly effecting my computer. He then hung up on me when I asked to speak to a supervisor.
Second call got me a much more helpful chap, who after conferring with a supervisor, transferred me to professional services. The person I spoke with there said they also didn't have any security reporting protocol, or if they did, he didn't know about it. When I said the issue could effect thousands of devices, he transferred me through to 'corporate'.
I ended up going through an IVR system to an operator, who was no help whatsoever. She was entirely the wrong person to speak to; she was also completely ignorant of any security reporting process, and didn't know who to transfer me to.
Could you please call me on +61 XXX XXX XXX to acknowledge receipt of this report, and to discuss it? Thanks.
=====
Perhaps I’m biased, but I’d have thought that a Windows Update that ships malware that bricks thousands of consumer devices without warning would constitute a security issue.
But hey … at least they’re actioning it, and they responded so quickly. So, FYI: if you have a security issue to report to Microsoft, do it by email. Phone staff are utterly, completely useless for this.
This is where I think they are mistaken, because end users may be downloading and installing the drivers themselves. I have done this on more than one occasion: Some gadget has a USB port and I find that it uses the FTDI chip, so I go to the web page and download the FTDI drivers for it. This may happen quite frequently, for instance when an end user moves a gadget from one PC to another, and (mistakenly assumes that) they want the latest driver.
I'm disappointed because I was a big fan of FTDI and use them in a lot of my projects. I won't just go and burn all of my FTDI chips, but I am sufficiently motivated to look for an alternative. Looks like SparkFun has a couple of breakout boards for the Silicon Labs chips.
Plugging in a USB is messy, and you will sometimes get an "Unrecognized Device" error, which you simply fix by unplugging and replugging.
I could see a similar hiccup causing their driver to sometimes "brick" a legitimate device.
Then this false positive ripples back to a manufacturer who bought 50,000 of those chips on the last run, and thinks they might all be fake...
It turns everything into a huge mess.
Very poor management decision, and shame on the engineers for implementing it.
I'd never even heard of FTDI before but they can rest assured that if I ever need a USB-to-UART chip that FTDI won't be the company I choose to buy. FTDI's drivers refusing to work with the fake parts is understandable, purposely reprogramming them to make them non-functional isn't.
Dumb question maybe, but why?
To a first approximation, all code eventually runs. Relatedly, never put an error message into your product you wouldn't want customers to see, because they will.
I'm not a supporter of intellectual property laws, but we have them, so I'd also be curious of any legal ground fake chip users have to stand on.
Also, possession of the fake chip as an end user is no more illegal than owning fake Louis Vuitton stuff. It's the sale under false pretenses that gets you in trouble.
Imagine I buy a car from a dealership, and without my knowledge the dealer has swapped out the original radio for a cheap counterfeit. I guess technically you could argue that makes the car "illegal" but it would be absurd to suggest that the manufacturer has the right to come to my house and slash my tires.
As I see it, it's not about whether "fake chip users" are obeying the laws; the burden should be on FTDI to justify its willful property damage.
To the extent the violations are with manufacture and sale, the user is not generally the appropriate target, even if destruction of the device was an appropriate remedy.
Simply refusing to work - perhaps logging something to the event log about counterfeit products - would be fine.
Or they could crack down on end-users. Or let the counterfeit manufacturers free-ride off their driver development.
"It seems that in this case Chinese designers implemented protocol-compatible "fake" chip, using mask-programmable microcontroller. This way they only needed to redo 1 mask - this is much cheaper than full mask set, and explains a lot of redundant pads on the die. Fake chip was working kinda fine until FTDI released drivers update, which were able to detect fake chips via USB and send only 0's in this case. It was impossible to foresee any possible further driver checks without full schematic recovery and these hidden tricks saved FTDI profits."
[1]: http://zeptobars.ru/en/read/FTDI-FT232RL-real-vs-fake-supere...
http://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootki...
There were lawsuits and Sony ended up having to distribute a removal tool.
They didn't preserve their brand with this action, they just destroyed it.
Legally, I'd be surprised. They are re-implementing the FTDI protocol, which is completely legal. They are reusing FTDI's PID/VID, which might or might not be a violation of the USB specs or USB recommendations -- I'm not sure about that -- but I'd be really surprised if that matches the legal definition of "counterfeit" for which customs has the right (and duty) to stop imports.
Then again, the users _did_ agree to let that happen in the clickwrap agreement, so it's still uncertain.
Either way, I'm readying the popcorn. This should be interesting.
https://twitter.com/JohnnySoftware/status/525092883125506048
Let's hope that all the manufacturers are 100% certain of their supply chains, from top to bottom. And that there are no bugs in the driver that might cause inadvertent bricking.
Way to go, FTDI.
>The licence only allows use of the Software with, and the Software will only work with Genuine FTDI Components (as defined in the Licence Terms). Use of the Software as a driver for a component that is not a Genuine FTDI Component MAY IRRETRIEVABLY DAMAGE THAT COMPONENT.
IANAL but I don't believe this disclaimer can possibly be valid. Personal property rights cannot be waived away with a disclaimer.
Edit: nobody has shown that the driver is intentionally writing the ID to 0, the counterfeit chip isn't even close to the same circuitry and could be screwing up a legitimate instruction.
That's intentional and clearly malicious.
Or are they -sneakily- bricking the device by evoking an unintended reaction to a seemingly innocuous command?
The former will be easy to prove, the latter.. probably not so much.
They're being somewhat evasive, but it's clear that this is intended as a deliberate anti-counterfeiting strategy.
They are not allowed self-help in the form of destroying other pieces of hardware. If they have a problem with counterfeit chips, the solution is customs/legal process/etc
If they aren't happy with what that buys them, they should be pushing for legal change.
(5) (A) [Whoever] knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;
Now "protected computer" and the [ab]use of the Interstate Commerce Clause mean that the device with the FTDI would likely need to be connected to a network for this to apply. Plus I think they still need to show $5,000+ in damage, but it wouldn't be hard to reach that if the driver wrecked a prototype and delayed a product.
Buzz, thanks for playing. :)
That won't get them out of discovery for various torts, and the discovery (emails, code, etc) is likely to show they did this on purpose.
It's not practically impossible, it's trivially easy to disassemble and see if it does this on purpose. Then you argue it to a jury, and it's going to look really really bad for FTDI.
Over here the claimant probably would not be able to peek into the defendant's stuff.
Especially if he can't specifically claim "on march 10th, Mr. Meier sent an email to Mr. Schmidt discussing topic X".
A simple "hand over your mails about the matter at hand" would be ruled a "fishing expedition", not admissible as a motion to discover.
[1]: https://www.hwtrek.com/product_preview/VTZUZV9k [2]: http://www.seeedstudio.com/wiki/Open_parts_library
I've never used it, but Microchip's IDE for their C compiler and debugger is cross-platform and will work on Linux/Mac/Windows. I prefer to program them in JAL, a Pascal-like language that is easy to learn that has a large library of functions available. There's syntax highlighting available for it in Vim :-) .
If you're committed to Arduino, there's an open-source project (http:www.pinguino.cc) that has its own Python-based IDE that will take Arduino code, convert it to SDCC C code, compile it to assembly, then flash a Microchip chip.
Thanks for the suggestion!
[1]: http://www.reddit.com/r/arduino/comments/2ehosj/pcieduino_fe...
So I'd rather not use FTDI altogether, if I can avoid it.
I'm yet to see someone who does mass production from ebay sourced components (bad price, not enough quantity). If I get parts from Digikey or Mouser, how can I check that they are genuine? I trust them more, but is there really a logical reason to trust any reseller in this sense? Screwed either way.
FTDI action hurts everyone except the ones they were targetting.
go pid 0
Seed is a small shenzhen company, I woulndt expect them to have legit parts to begin with anyway.
PLEASE NOTE: ALL NAMES HAVE BEEN CHOSEN FREELY BY THE PERSON WHO MADE THE SCREENSHOT! So there's no name "BrickCLoneDevices()", it's probably called UpdateEEPromChksum or something like that in the original code, because it looks like that's what it does.
http://www.eevblog.com/forum/reviews/ftdi-driver-kills-fake-...
Assuming that this disassembly/decompiled code indeed is genuine, the interesting thing is explained in the 2nd comment block: A genuine FTDI device seems to be designed such that a write only to the offset that stores the PID is ignored, hence for a genuine part this code will only update the word at offset 62, and that would be matching the functionality to just update the eeprom checksum.
For comparison, here's a random mainling-list post which includes a dump of the 232 eeprom. The VID/PID is stored at word 1 and 2 of the eeprom, something that could be a checksum is down at the word with offset 0x7f (word 0x3f = 63? There's probably a off-by-one here).
http://developer.intra2net.com/mailarchive/html/libftdi/2009...
Is the subterfuge required for illegitimate cloning really that much easier than getting a website, writing docs, and supporting drivers?!
It's also cheaper; $2.44 for one and it goes down to $1.44 for 2500: http://www.digikey.com/product-detail/en/CY7C65213-32LTXI/CY...
http://www.microchip.com/wwwproducts/Devices.aspx?product=MC...
EDIT: looks like they did standardize a USB-to-serial device class [1]. Maybe they just need to update it?
I use FTDI because I can easily run comm ports at 3 Mbit/s. OSX (and I think Linux too) does support comm ports at non common baud rates. I'm looking for a way to add decently quick USB comms to a device without writing my own drivers. FTDI seems like the only option. Using HID is limited to 64KB/s.
The workaround once your chip has been flashed by the new driver is modifying the driver to communicate with devices that have a PID of 0.
Commented reverse engineering assembly: https://twitter.com/marcan42/status/525126731431038977
So they are rewriting the USB Product ID in EEPROM, only on "fake" chips, hence the Windows USB driver doesn't recognize the device anymore. It should be reprogrammable using the right tools. (https://twitter.com/marcan42/status/525134266112303104)
What allows them to do things differently on different chips: "Figured out the real/clone FTDI difference: EEPROM is written in 32bit units. Even writes are ignored (buffered), odds write both halves." https://twitter.com/marcan42/status/525194603746426881
And some wisdom:
"For those unfamiliar with embedded engineering: most USB (and other) devices can be bricked if maliciously attacked." "Assume ALL devices are brickable by evil code unless proven otherwise. This isn't news. Most devices make no attempt to protect themselves." (https://twitter.com/marcan42/status/525137221431463937 https://twitter.com/marcan42/status/525137463107272704)
Next gen FTDI clones will work around this driver detection. Next FTDI driver has new detection code.
Iterate until the counterfeit chips are indistinguishable from the real thing via software.
Will they still cost less?
Seriously, though, this just looks like extracting economic rents from the fact that their vendor ids come pre-installed in certain OSes.
Intentionally sabotaging customer equipment will lead to all sorts of data loss and consequential damages issues.
As @Someone1234 said below, FTDI needs to pursue legitimate channels to protect their IP.
Ouch...
Time for the CEO to reach for that third envelope and write to his successor.
It appears to be a fairly low level USB controller chip? Is this chip (or its ilk) in every kind of usb device? What is the impact of this?
Most of this article dives in with a fair bit of preexisting knowledge - can somebody fill me in?
In essence, FTDI's chips are the go to solution for adding USB support when you don't want to spend too much time on it. I would argue that today there are better and cheaper alternatives, but FTDI was probably the first vendor of such chips with reasonable documentation and software support.
USB 2.0 compliant, full-speed (12 Mbps)
No external crystal required
Up to 1024 Bytes of EEPROM or OTP ROM
User-programmable custom Baud rates
Supports all modem interface signals
Baud Rates: up to 2 Mbps
Industrial temperature –40 to +85 °C
Datasheet:
http://www.silabs.com/Support%20Documents/TechnicalDocs/CP21...
UPDATE: On this PDF (page 18) it talks about how to set the baud rates. I think it defaults to "normal" serial baud rates but there's a way to modify the baud rate choices. At least that's how it reads to me.
http://www.silabs.com/Support%20Documents/TechnicalDocs/AN14...
Really hope everyone starts dumping FTDI and they end up in a class-action lawsuit. USB <-> serial converters are a commodity these days, regardless of what these goons think. If they can't compete in a free market, they should find something else to do or go out of business.
Um, I don't understand what use case you have that has a microcontroller and would ever want to use an FTDI chip. As you point out, if I have a microcontroller, I have voltage regulation, and I likely have USB and a UART.
I will point out that 5V USB isn't all that useful by itself. Most microcontrollers won't work natively at 5V, so you need a regulator, and you need to obey the USB inrush specs, and you probably need a switching regulator since you only nominally have 100mA (even though everything normally supplies more nowadays), etc.
There are only two times I want to use an FTDI chip:
1) I have some old thing that I have to update that A) uses RS232 and B) is standalone.
2) Somebody Else's Problem -- the software idiots are insisting on RS232 communication to something and that idea is stupid or redundant (it already has an SPI or I2C interface that is much better and there is a microcontoller). I can slap a USB micro connector and one of these chips on the board and tell the software guys to get lost until they pull their heads out of their asses.
Wow. I haven't seen something this spectacularly dumb in a while. Should be entertaining! :)
[1]Car bodies: http://autoweek.com/article/car-news/mercedes-and-daimler-cr...
[2]Guitars: http://thehub.musiciansfriend.com/bits/feds-seize-over-185-c...
[3]Carrying bags: http://www.hamm.eu/en/aktuelles-und-presse/news/2009/2009-04...
[4]Clothing: http://www.nytimes.com/2014/01/31/nyregion/trademark-trumps-...
edit: According to a professor at the Fashion Law Institute at Fordham University, buying counterfeit goods is only illegal in France and Italy[1]. US customs even allow people to knowingly bring one counterfeit good into the country.
[1] http://bucks.blogs.nytimes.com/2010/10/28/the-legality-of-bu...
I wonder if Windows will pull the driver.
My guess is an 8am meeting in Glasgow (about 8.5 hours from now), followed by an apology and an updated driver announcement at 10am.
Feel free to ask "Suzhou Supereal Microelectronics" for a working driver for your counterfeit device.
The "counterfeiting" issue is a trademark problem only. In other words, the only thing wrong here is that the Chinese manufacturer stamped FTDI on their chips. There's nothing in trademark law that says it's OK to use these tactics to combat the issue. Why would there be? The two are completely orthogonal to each other. If there are chips out there that emulate FTDI and do not have the logo, FTDI has most certainly broken the law. As others have pointed out, this would be like Intel damaging AMD chips simply because they identify themselves in a similar manner. (again, minus the bit about trademark which is again, orthogonal to what FTDI has done here).
There is no detection, just some fuzzing with illegal instructions.