Joe FitzPatrick’s LABScon 2025 talk explains how overseas-manufactured networked devices have become essential in small-business labs and critical infrastructure, while the safeguards meant to control their risks often fail in practice. He argues that hidden connectivity, supply-chain workarounds, and product activation requirements make import bans ineffective, and he proposes right to repair, offline-use guarantees, hardware and firmware bills of materials, and privacy legislation instead. #LABScon #JoeFitzPatrick #SentinelLABS
Keypoints
- Joe FitzPatrick’s presentation focuses on the growing dependence on overseas-manufactured networked devices.
- He highlights undocumented cellular radios found in solar inverters used in U.S. highway infrastructure.
- He notes that adding connectivity to a device with an exposed serial port can be done in minutes by a manufacturer, installer, or later attacker.
- The talk describes how banned hardware still enters supply chains through relabeling and FCC-certified modular components.
- It also examines mandatory product activation in consumer devices such as drones and 3D printers and the difficulty of using them without phoning home.
- FitzPatrick argues that small businesses and infrastructure operators rely on imported hardware because it is affordable and functional, with no clean domestic substitute.
- He concludes that trade restrictions are not the right fix and instead recommends right to repair, offline-use guarantees, hardware/firmware bills of materials, and privacy legislation.
MITRE Techniques
- T0853 Unauthorized Hardware Modification – Connectivity can be added to an exposed device after manufacture, installation, or later tampering (‘adding that kind of connectivity to a device with an exposed serial port takes minutes and can be done by anyone’).
Indicators of Compromise
- [Device Type] undocumented connectivity in infrastructure equipment – solar inverters, cellular radios
- [Device Category] consumer and industrial products with mandatory activation – drones, 3D printers
- [Organization/Event] presentation venue and host context – LABScon 2025, SentinelLABS