• sugar_in_your_tea
      link
      fedilink
      English
      arrow-up
      7
      ·
      11 hours ago

      Does it count as “China made” if the firmware is FOSS and I load it myself? NICs and boards are pretty much all made in China, but how far does this go?

      • earphone843
        link
        fedilink
        English
        arrow-up
        4
        ·
        8 hours ago

        Yes, it counts. Hardware backdoors are absolutely a thing.

      • remotelove@lemmy.ca
        link
        fedilink
        English
        arrow-up
        8
        ·
        10 hours ago

        It depends on how bad China wants your porn. There could be secondary MCUs that are designed to completely bypass the original firmware. (Think Intel ME)

        That is not very practical for consumer grade gear, but still possible.

        • Ajen
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          9 hours ago

          Wifi chips have their own firmware that could have a backdoor. If it’s connected to the CPU over PCI-E or another interface that supports DMA then it’s also able to inject code into the main system even if it’s running FOSS firmware.

          • remotelove@lemmy.ca
            link
            fedilink
            English
            arrow-up
            3
            ·
            7 hours ago

            It seems that a few router types have WiFi + SoC setups now. (Like ones using the IPQ4019, for example.)

            While that doesn’t significantly reduce the risk of something nasty, it would limit places for nasty code to hide. Well, “hide” in the traditional sense, like on another chip entirely.

            However, I haven’t really looked into any drivers to see how these SoC’s are segmented to see if its really any different than the old MCU + WiFi chipset setups.