LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience

LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
Joe FitzPatrick’s LABScon 2025 talk explains how overseas-manufactured networked devices have become essential in small-business labs and critical infrastructure, while the safeguards meant to control their risks often fail in practice. He argues that hidden connectivity, supply-chain workarounds, and product activation requirements make import bans ineffective, and he proposes right to repair, offline-use guarantees, hardware and firmware bills of materials, and privacy legislation instead. #LABScon #JoeFitzPatrick #SentinelLABS

Keypoints

  • Joe FitzPatrick’s presentation focuses on the growing dependence on overseas-manufactured networked devices.
  • He highlights undocumented cellular radios found in solar inverters used in U.S. highway infrastructure.
  • He notes that adding connectivity to a device with an exposed serial port can be done in minutes by a manufacturer, installer, or later attacker.
  • The talk describes how banned hardware still enters supply chains through relabeling and FCC-certified modular components.
  • It also examines mandatory product activation in consumer devices such as drones and 3D printers and the difficulty of using them without phoning home.
  • FitzPatrick argues that small businesses and infrastructure operators rely on imported hardware because it is affordable and functional, with no clean domestic substitute.
  • He concludes that trade restrictions are not the right fix and instead recommends right to repair, offline-use guarantees, hardware/firmware bills of materials, and privacy legislation.

MITRE Techniques

  • T0853 Unauthorized Hardware Modification – Connectivity can be added to an exposed device after manufacture, installation, or later tampering (‘adding that kind of connectivity to a device with an exposed serial port takes minutes and can be done by anyone’).

Indicators of Compromise

  • [Device Type] undocumented connectivity in infrastructure equipment – solar inverters, cellular radios
  • [Device Category] consumer and industrial products with mandatory activation – drones, 3D printers
  • [Organization/Event] presentation venue and host context – LABScon 2025, SentinelLABS


Read more: https://www.sentinelone.com/labs/labscon25-replay-please-connect-to-the-foreign-entity-to-enhance-your-user-experience/