258 points•edandersen•10 days ago•211 comments•

211 comments

Aurornis9 days ago
There were sellers buying the smallest RAM units, changing the RAM chips, and then reselling them as the higher RAM SKUs. The sellers who do this don’t always care to use good RAM chips and may even use QA reject parts. When the unit doesn’t work correctly, the anger and RMA requests are directed back at the Raspberry Pi foundation.
Tepix9 days ago
The user friendly option would be to print the amount of RAM in very large letters on the PCB. There happens to be a lot of suitable surface on the PCB to the right of the text "Raspberry Pi 5" on the PCB anyway (§). Right now the amount of RAM is hard to read and easy to modify (move a little tiny SMD resistor).

Drawback: You need different silkscreens for different amounts of RAM.

Btw, if you're worried about RAM-swapped units you can already verify them as described at https://geekworm.com/blogs/news/prevent-ram-swapped-raspberr...

--

(§) as can be seen here https://pip-assets.raspberrypi.com/categories/1129-pcn/docum...

buildsjets9 days ago
A little bit of acetone and a q-tip will remove the silkscreen, and then the PCB can easily re-marked by the scammer. Having a new silkscreen made is pocket change.
nomel9 days ago
No, this is not sufficient, since it would still allow you to swap to shite ram of the same size. This is an age-old problem for counterfeits. The ink on the chip/PCB isn't worth anything. The only way to actually catch this is to do a IQC that runs a full RAM test and hope that if you can't see a difference in performance (throughput, BER, timings, etc), then the chip is correct, with a bit of periodic de-lidding for anything suspicious/sampled. Then, if you can afford it, you blacklist the vendors that are caught changing things.

They also added a bit of internal ink, which is worth just a little more:

> we now also program in some other device attributes, meaning that switching parts of the same size may not work.

Working with vendors in China is entirely adversarial (mostly because their supply chain is vulnerable too), at this scale.

kiicia9 days ago
it can be very easily done by burning it with laser on prepared blank box on silkscreen - even iPhones are marked this way with their own serial numbers

the only reason why pis are not marked this way is because raspberry didn't wanted to (so far)

ryukoposting8 days ago
Embedding it on the board won't work. Fraudsters are really good at doctoring chip and board makings nowadays, even below the solder mask. It's hard to imagine as a westerner, but the necessary equipment to do that kind of thing is trivially available in most of east Asia.

On-chip fuses would be a good solution. Which, of course, is already what they're using to lock chips to specific memory. There's just not a good reason to brick the board when the memory doesn't match. Have the firmware flash a warning on the screen before boot. Problem solved.

renonce9 days ago
Just make the RAM mismatch a warning that voids warranty rather than a hard error. This is no excuse for forcing hardware pairing
gosub1009 days ago
That won't stop scammers from reselling modified boards.
frenchtoast89 days ago
Mac Minis used to have soldered on SSDs, but the 2024 model is upgradable. A lot of people purchased a cheaper Mac Mini and upgraded the storage themselves. Most people would argue this is a good thing, even if some of those Mac Minis were resold. This is no different.
wolrah9 days ago
> Mac Minis used to have soldered on SSDs, but the 2024 model is upgradable. A lot of people purchased a cheaper Mac Mini and upgraded the storage themselves. Most people would argue this is a good thing, even if some of those Mac Minis were resold. This is no different.

Replacing a socketed component that is modular by design, even if it's not officially intended to be upgraded outside the factory, is worlds different from replacing BGA components on a densely packed PCB.

That said, there could also be a middle ground by just providing some way to look up the hardware specs of a given serial number. Post the part numbers of the components that you're concerned about being replaced and provide tools to verify as many of them through software as is practical. Allow owners to know if their device has been modified and how so, but allow them to choose what to do with that information.

Combating fraudsters trying to pass off modified and/or refurbished devices as genuine is valid, but preventing owners from modifying or repairing their own or knowingly purchasing such devices from honest resellers is not.

steve_taylor9 days ago
This is very different. The Raspberry Pi 5 RAM upgrades are arbitrage, involving soldering on dodgy RAM, at the expense of the unsuspecting retail buyer vs. people upgrading their own Mac Minis for themselves and without any soldering.
snapetom9 days ago
It absolutely is different. You just said the Mac Mini is upgradable but the Pi is still soldered on. Desoldering and soldering a new RAM unit carries huge risks no matter how skilled people claim they are at it.
solarkraft9 days ago
> There were sellers buying the smallest RAM units, changing the RAM chips, and then reselling them as the higher RAM SKUs

That’s awesome. If it’s economical to do, it’s clearly good for consumers.

> The sellers who do this don’t always care to use good RAM chips and may even use QA reject parts.

That’s clearly on the sellers.

> When the unit doesn’t work correctly, the anger and RMA requests are directed back at the Raspberry Pi foundation

That’s a bit of a conjecture and easily solved in ways that preserve user freedom.

kotaKat9 days ago
But bricking retroactively in the field is a bad move, and sends even more anger and RMA requests back towards parties.

https://github.com/therealdreg/ftdibrick

Pepperidge Farm remembers the FTDI driver bricking.

kiicia9 days ago
gateway 3ds tried to brick 3ds-es of users of cloned cards, bricked whole swaths of actual users instead

https://www.eurogamer.net/3ds-flashcard-includes-secret-kill...

undersuit9 days ago
It's not bricked retroactively from what I've read.
RandomGerm4n9 days ago
I think they should instead just introduce a clear system for verifying that a Raspberry Pi is genuine. For example, a code printed directly on the device. If you enter that code on the website, you can see exactly which model it belongs to and how often it has been used. That way, you could determine whether a Raspberry Pi is new or used and whether it has been modified. I saw that once at a thermal paste manufacturer. They used it to solve the problem of counterfeit thermal paste.You just have to get people to actually use the system and tell anyone else who asks for support but doesn't have an original copy to GTFO.This would allow them to avoid the increased support burden without limiting people's ability to upgrade their Raspberry Pi.
colejohnson669 days ago
Chinese scammers have gotten good at abusing those "codes" by having a list of "known good" codes and printing them on multiple units. And because those holographic codes some companies used are printed in China, the scammers just use the same equipment during the night shift.

https://www.bunniestudios.com/blog/2010/microsd-card-failure...

indrora9 days ago
There are methods of doing so that identify multiple, harder to falsify things.

One that I have seen is HMAC(serial||SKU) as a datamatrix/QR, laser-etched onto the top silkscreen and burned into a PROM.

echoangle9 days ago
Just show everyone who looks up the code how often the code has already been checked. If you get a new product but the code has been checked 628 times, it’s probably a reused code.
arrowleaf9 days ago
Package the product with a low denomination paper currency, lookup based on the banknote's serial number.
kiicia9 days ago
fun fact is that some chinese electronics manufacturers do exactly that with their products (even simple ones like led night lights), holographic qr-code on box that can be scanned and verified without opening box and second code inside box to verify box wasn't swapped
squeegeeninja9 days ago
The real story here is that people are selling modded Pis as higher-memory versions. And this check actually caught them + is circumventable. The restriction is somewhat annoying to a small subset of enthusiasts but seems to catch genuine fraud.
Wowfunhappy9 days ago
If it's circumventable, how does it prevent fraud? Seems like it would likely just hurt the enthusiasts.

You can already check whether the RAM has been swapped via https://geekworm.com/blogs/news/prevent-ram-swapped-raspberr....

solarkraft9 days ago
> Unfortunately, some unscrupulous sellers swap the RAM modules of low-capacity models to pass them off as high-capacity ones for illegal profits

What the fuck are they talking about?

solarkraft9 days ago
I feel like a genuine fraudster would know those circumventions while an enthusiast (who BOUGHT the device) would be hurt.
locknitpicker9 days ago
> The restriction is somewhat annoying to a small subset of enthusiasts but seems to catch genuine fraud.

What fraud are you speaking of?

alibarber9 days ago
The memory that they are placing in it has to be cheap enough to be worth their while. Which in this climate is highly probably faulty memory, or memory that runs at a different speed/spec to the one advertised to come with the RPi. That is fraud.
Brian_K_White9 days ago
Selling a unit as something that it's not.

A unit that rpi themselves sold with 8g is different than a unit that someone else modified. The reworked unit is not sold with the disclosure that it has been hacked and no longer covered by any warranty, and the memory installed is of totally unknown provenance and quality, timing specs, failed qa, etc. Even the simple process of heating everything up to desolder & resolder temps is not free, it degrades everything, the pcb itself, the epoxy holding the traces and pads down, and all the components, and means higher chance of some failure happening sooner than it would have. But it's sold as a real rpi unit for real rpi price or a little less to beat real ones.

That is the fraud they speak of.

You should be free to do this to your unit if you like of course, and rpi has infinite other possible ways they could have chosen to address the problem and didn't have to do it this way. I'm only saying there is actually a problem.

petu9 days ago
Selling modded board as official 8GB SKU with reliability/warranty expectations.
Grombobulous9 days ago
Whether it’s fraud depends heavily on how it’s sold.

If it’s represented as a new product or offered with manufacturer’s warranty, that would cross into fraud.

maltris9 days ago
If they can block it, they should be able to warn about it with an opt-in option.
zamadatix9 days ago
Is there a way to circumvent it other than use ancient firmware?
jorritposthuma9 days ago
I love how we think we own our hardware, but secretly we don't. Surprised though that even a Raspberry Pi now thinks this as well. They grew big _because_ of tinkering...
aeve8909 days ago
Doesn't matter. At the current RPI prices is just better to buy a mini PC or any of the alternative SBC like the orange pi.
geerlingguy9 days ago
Reading through the EEPROM repo issue[1] makes me a little more sympathetic to the "feature", but I still don't like it at all.

It might help in the short term to stop dodgy resellers who mod the boards with cheap upgraded RAM to make a buck or two...

But the Pi itself is always taking one step forward, one step back in terms of firmware. I've been tinkering with some Qualcomm boards from Radxa and things are slightly better there, though you don't have anywhere near the ecosystem you get with Pi (or onboarding niceties).

[1] https://github.com/raspberrypi/rpi-eeprom/issues/761

winkelmann9 days ago
I am incredibly unsympathetic to statements like the first reply to the issue "This sounds like a hardware issue. Please can you contact the reseller for a refund." from the "Software Engineering Manager at Raspberry Pi, working on firmware, bootloader, security and low-level Linux software." (Read: I suspect this person knew exactly what happened here)

If the reply was along the lines of "This is a new firmware check to curb fraud related to undisclosed aftermarket RAM upgrades with potentially unreliable chips." - I'd be fine with it, but basically just coming out to gaslight the user about the issue leaves a very sour taste in my mouth. In the end, they had to come clean anyway, big surprise.

I say this as someone who has been loving Pis despite their price for the straightforward and reliable long-term software support. Not gonna pretent like I'll never buy a Pi again, but it's another strike moving me to explore other options in the future.

imtringued9 days ago
>(Read: I suspect this person knew exactly what happened here)

Yes they knew everything about how training DDR4 RAM works, they knew everything including that the seller doesn't know how their training code works and bailed out and no longer exists but still got paid and that it was worth it for the reseller.

geerlingguy9 days ago
One thing I like here is Raspberry Pi still lets engineers have interactions with end users like this (despite them not doing the best PR all the time).
bri3d9 days ago
Really? I found that issue and all of the related ones really disingenuous from the Pi folks; they just stonewalled everyone with "contact your hardware seller" rather than explaining what was going on even at the glossed-over level they managed in the forum thread.

I do feel for them; they're between a rock and a hard place with mis-labeled clone boards. But their implementation seems to be the most hostile and opaque possible way to achieve these goals (which I also understand from an anti-cloning standpoint, but especially anymore, it's going to get reversed anyway).

alibarber9 days ago
I dunno - I think the victims in a lot of these cases aren't stupid. They can't contact the seller because they bought it from 'some guy' who's disappeared into the night. They know they've been had and are trying to get a knock-off board working at the expense of [the time of] someone completely unrelated to this.

It's pretty normal for the first port of call / warranty claim for a busted item to be the dealer that sold it to you.

Read the full thread on Hacker News →

Related stories