Investigating Foreign Tech from Online Retailers

Michael Portera (VP of Cyber Solutions · Sequoia)

Recon Village @ DEF CON 33 · Day 1 · Recon Village

Overview

In this compelling talk from Recon Village, Michael Portera, VP of Cyber Solutions at Sequoia, delves into the often-overlooked security and privacy implications of purchasing inexpensive, unbranded electronics from major online retailers like Amazon. Titled "Investigating Foreign Tech from Online Retailers" (or, as Portera lightheartedly suggests, "buying cheap stuff off of Amazon and breaking it"), the presentation meticulously tracks the supply chain of a foreign-made smartwatch, revealing a complex web of opaque manufacturers, questionable business practices, and significant consumer risks.

Watch on YouTube

Visual summary for Investigating Foreign Tech from Online Retailers by Michael Portera
Visual summary for Investigating Foreign Tech from Online Retailers by Michael Portera

Key moments

  1. 0:00 Introduction to 'Investigating Foreign Tech from Online Retailers'
  2. 0:26 Speaker's humorous alternative talk title
  3. 1:54 Origin story: friend's suspicious smartwatch
  4. 2:30 Scale of Chinese sellers on Amazon
  5. 2:59 Why Chinese brands use random letters for trademarks
  6. 4:20 Real dangers of cheap online products
  7. 6:00 Introducing the $30 smartwatch for analysis
  8. 7:07 Beginning OSINT investigation on smartwatch brand

Investigating Foreign Tech from Online Retailers

Speakers: Michael Portera, VP of Cyber Solutions, Sequoia

Conference: Recon Village

YouTube: https://www.youtube.com/watch?v=MAtllbHmxP4

Overview

In this compelling talk from Recon Village, Michael Portera, VP of Cyber Solutions at Sequoia, delves into the often-overlooked security and privacy implications of purchasing inexpensive, unbranded electronics from major online retailers like Amazon. Titled "Investigating Foreign Tech from Online Retailers" (or, as Portera lightheartedly suggests, "buying cheap stuff off of Amazon and breaking it"), the presentation meticulously tracks the supply chain of a foreign-made smartwatch, revealing a complex web of opaque manufacturers, questionable business practices, and significant consumer risks.

Portera's investigation, sparked by a friend's query about a seemingly innocuous $30 smartwatch, exposes the systematic challenges in identifying the true origins and security posture of these devices. He demonstrates how a combination of Open-Source Intelligence (OSINT), hardware analysis, and mobile application reverse engineering can uncover critical vulnerabilities, privacy concerns, and potential geopolitical implications inherent in products that dominate online marketplaces. This talk is crucial for anyone interested in consumer cybersecurity, supply chain integrity, and the broader impact of globalization on personal data security.

The core message underscores a critical dilemma: the allure of low prices often comes at the cost of security, privacy, and even physical safety. Portera's work serves as a stark reminder for consumers to exercise due diligence and for security professionals to understand the pervasive nature of supply chain risks, particularly in an era where digital systems are increasingly reliant on globally sourced, often untraceable, components.

Background

▶ Watch: Introduction to 'Investigating Foreign Tech from Online Retailers' (0:00)

The proliferation of foreign technology on major online retail platforms, particularly Amazon, presents a multifaceted challenge that forms the backdrop of Portera's investigation. A significant portion of the top 10,000 sellers on Amazon—an estimated 50%—are based in China. This dominance is often characterized by practices designed to circumvent Amazon's quality control measures and regulatory scrutiny. One notable tactic is the use of random strings of letters as brand names. This strategy emerged after Amazon’s 2015 mandate for sellers to possess a trademark, leading Chinese manufacturers to flood the US patent office with nonsensical applications that are more likely to be auto-approved, bypassing the due diligence required for more conventional brand names.

This environment fosters a range of abuses, including widespread fake reviews, the sale of counterfeit products, and the misuse of fake intellectual property claims to disrupt competitors. Amazon, in essence, becomes a "victim of its own success," while consumers, driven by attractive pricing, inadvertently contribute to the problem. Portera highlights numerous examples of consumer product safety commission (CPSC) recalls involving dangerous goods bought online: flammable children's pajamas, lead-contaminated cups, electric immersion heaters that catch fire, non-functional smoke detectors, and melting power banks. A key issue here is the transient nature of these sellers; once flagged, they frequently white-label or spin up new brands, making continuous enforcement an uphill battle.

The specific trigger for Portera's deep dive was a friend's purchase of a $30 smartwatch from Amazon. Despite its appealing price, numerous positive reviews, and endorsement by online influencers, initial OSINT suggested potential security risks. The talk underscores that while established brands like Samsung have had product recalls, the systemic issue with unbranded or ambiguously branded foreign tech is its inherent lack of accountability and traceability, making informed consumer choices exceptionally difficult. This context sets the stage for Portera's detailed technical analysis of how such products operate and what hidden risks they pose.

Key Findings

▶ Watch: Origin story: friend's suspicious smartwatch (1:54)

Portera's investigation yielded several critical findings, illuminating the deceptive and often insecure nature of cheap foreign electronics sold online:

  1. Opaque and Shifting Identities: Initial OSINT on the smartwatch's brand, "Rxing Eggs" (or Ring Eggs), revealed a trademark registered to "Wing Xin Ding" with an address pointing to a soccer field in China and a US-based attorney operating out of a PO box. The actual selling company, "Seway New," claiming to be the sole authorized seller, provided an email (vipvipasg.com) and a WhatsApp number (UK-based), which became crucial pivot points.
  2. Extensive White-Labeling: Further OSINT, including reverse image searches of the product, uncovered that identical watches were sold under numerous different brand names (e.g., Hake Fit, Fospat). These different brands often shared the same dubious legal representation (the attorney "Anson") and email addresses, confirming a widespread white-labeling practice where a single manufacturer produces a generic product marketed under various ephemeral brand identities.
  3. FCC Reports as a Goldmine: Acquiring the physical watch allowed Portera to locate its FCC ID. Analyzing the corresponding FCC report provided invaluable insights, including internal photos of the circuit board, details on the manufacturer, names of US importers, and even hints of regulatory scrutiny (e.g., FCC follow-ups questioning provided addresses). The reports also demonstrated that different model numbers (e.g., G35 vs. K35) often correspond to the exact same underlying hardware, further reinforcing the white-labeling strategy.
  4. Cheap, Common Hardware: A physical teardown of the smartwatch revealed it was strictly Bluetooth-enabled with no Wi-Fi capabilities. The internal components were standard, inexpensive parts: a Realtek chipset (Taiwanese) and a Puya Semi firmware chip (Shanghai). While these components are common, their combined use in a low-cost product often indicates a lack of investment in robust security features.
  5. Egregious Software Security Flaws: The most alarming findings emerged from the analysis of the associated Android mobile application, "Deep Fit" (among others). Using Mobile Security Framework (MobSF), Portera demonstrated that the app requested excessive permissions (e.g., background location, ability to answer phone calls) and, critically, transmitted all user data in clear text traffic (unencrypted HTTP) rather than secure HTTPS. This data, including sensitive health and activity metrics, was observed being exfiltrated to foreign infrastructure, specifically Chinese servers identified by the "QQQ" domain.
  6. Intentional Obfuscation: Portera concluded that the complex web of shifting brand names, dubious addresses, and opaque supply chains is not accidental but rather a deliberate strategy to make tracking and accountability extremely difficult for consumers and regulators alike. This intentional obfuscation serves to protect manufacturers and sellers from legal repercussions for product defects or privacy violations.

Technical Deep Dive

▶ Watch: Why Chinese brands use random letters for trademarks (2:59)

The investigation into the foreign smartwatch employed a multi-pronged technical approach, combining OSINT, hardware analysis, and software reverse engineering to uncover its true nature and security posture.

OSINT Techniques

The initial phase leveraged publicly available information to trace the product's origins.

  • Trademark Search: Portera began by identifying the brand name ("Rxing Eggs") and searching the US Patent and Trademark Office (USPTO) database. This revealed the trademark holder, "Wing Xin Ding," and an associated address in China that mapped to a soccer field – an immediate red flag. The attorney of record, "Jen Lu Leu" (dubbed "Anson"), was also identified, with a US PO Box address.
  • Email and WhatsApp Pivoting: The product listing provided an email address (vipvipasg.com) and a WhatsApp number. These became crucial pivot points. Searching these identifiers led to other seemingly unrelated brands, such as "Hake Fit" (which had a YouTube channel with product manuals) and "Fospat," all seemingly connected through the same attorney or shared infrastructure. This revealed the extensive white-labeling strategy. The WhatsApp number, identified as UK-based, and claims of Italian operations further complicated the geographical tracing.
  • Reverse Image Search: Visual analysis played a significant role. Reverse image searches of the smartwatch product photos revealed identical devices being sold under different brand names, often with only minor stylistic changes to the marketing materials. This visually confirmed the re-branding of a common, generic product.
  • FCC ID Lookup: Once the physical watch was acquired, locating its FCC ID was paramount. The FCC (Federal Communications Commission) requires most electronic devices that emit radio frequency (RF) signals above 9 kHz in the US to have a certification. The FCC database (accessible via the FCC ID) provides a wealth of information:
  • Internal Photos: Detailed images of the circuit board and internal components, crucial for hardware analysis.
  • Confidentiality Requests: Information on what details the manufacturer requested to keep confidential (e.g., schematics).
  • Importer Names: Identification of the US entities responsible for bringing the product into the country.
  • Model Numbers: Confirmation that different model numbers (e.g., G35, K35) often share identical hardware, indicating re-branding.
  • Regulatory Correspondence: In some cases, the FCC report included communications, such as the FCC questioning the validity of a German European group's address, highlighting the lax verification processes that can occur.
  • Shipping Data: Portera mentioned resources like Panga (now acquired) and Import Yeti (free) for investigating shipping data. While not directly linked to this specific watch's shipment, these tools can provide insights into where components or finished products are being shipped from and to, offering another layer of supply chain visibility.

Hardware Analysis

A physical teardown of the smartwatch provided concrete details about its internal architecture.

  • Connectivity: The analysis confirmed that the device relied solely on Bluetooth for communication with the smartphone app; no Wi-Fi module was present. This simplifies the attack surface but also means all data transfer is mediated through the paired phone.
  • Components: The primary chipsets were identified:
  • Realtek: A common Taiwanese manufacturer, often found in a wide array of consumer electronics. Portera noted that while Realtek chips can have associated vulnerabilities, they were not the primary concern in this specific investigation.
  • Puya Semi: A Shanghai-based company, identified as the source of the firmware chip. This further confirmed the Chinese origin of core components.
  • LCD Screen: Tracing the LCD screen proved difficult, leading to multiple potential Chinese manufacturers, again highlighting the opaque nature of the supply chain.
  • Bluetooth Manufacturer: The Bluetooth module was traced to a Shenzhen-based Chinese company.
  • Operating System: The device was confirmed to be running a variant of Android.
  • Firmware Extraction (Attempted): Portera attempted firmware extraction by connecting to the device's soldering pads. He candidly admitted to "barking the crap out of those soldering pads," indicating the challenges of reverse engineering inexpensive, often poorly documented hardware. Despite the physical damage, they were able to power the device and perform Bluetooth analysis, confirming chip manufacturers but not discovering any "crazy exploits or vulnerabilities" directly on the device firmware itself. This shifted the focus to the more accessible software layer: the mobile application.

Software Analysis (Android App)

The critical phase of the investigation involved analyzing the Android companion application, "Deep Fit." Android was chosen due to its relative ease of analysis compared to iOS.

  • Tools and Environment:
  • Linux VM: Recommended for hosting the analysis environment.
  • APK Files: The Android application package (.apk) file was obtained from public repositories.
  • Mobile Security Framework (MobSF): Portera highlighted MobSF as an "absolute best friend" for mobile application security analysis. It's an open-source tool that automates static and dynamic analysis of Android and iOS applications, providing a comprehensive report. MobSF can be easily run in a Docker container.
  • AI Tools: Portera acknowledged the emergence of AI tools with reverse engineering capabilities but noted he had not personally used them, humorously adding, "job security for now."
  • MobSF Report Highlights: The analysis of the "Deep Fit" app using MobSF revealed several concerning findings:
  • SSL Certificates and Infrastructure: MobSF provided details on SSL certificates and the underlying infrastructure the app communicated with, allowing for further pivoting during OSINT.
  • Permissions: The report detailed all requested permissions, flagging those that were potentially excessive or unnecessary for a smartwatch app (e.g., background location, ability to answer phone calls). MobSF provides a status for each permission, indicating potential risks.
  • Clear Text Traffic: This was a major finding. MobSF clearly showed that the app was transmitting sensitive user data (activity, health metrics) using unencrypted HTTP protocols, rather than secure HTTPS. This means any data exchanged between the app and its backend servers could be intercepted and read by anyone on the same network segment. Portera emphasized this as a "blocker" in 2025, highlighting the severe lack of basic security.
  • Data Exfiltration Targets: The analysis identified specific backend servers and domains to which the data was being sent. Notably, a significant portion of the traffic was directed to Chinese infrastructure, specifically "QQQ" domains. This confirms that personal health and activity data collected by the smartwatch and processed by the app was being transmitted to servers located in China, raising significant privacy concerns given the different geopolitical and data privacy regimes.

In summary, the technical deep dive uncovered a systematic pattern of obfuscation, cost-cutting hardware choices, and alarmingly poor software security practices, all designed to facilitate the sale of cheap products while minimizing accountability and potentially compromising user data.

Demo / Proof of Concept

▶ Watch: Real dangers of cheap online products (4:20)

While the talk primarily focused on presenting the findings from extensive research, Michael Portera did incorporate a live demonstration and tangible proof-of-concept elements throughout his presentation. Crucially, he showcased the output of the Mobile Security Framework (MobSF) report for the "Deep Fit" Android application directly during the talk.

This live demonstration highlighted the critical security flaws identified in the app. Portera navigated the MobSF report, pointing out specific sections that detailed:

  • Excessive Permissions: He showed the list of permissions the app requested, discussing which ones were unnecessary or potentially intrusive for a smartwatch application.
  • Clear Text Traffic: Most significantly, he demonstrated the MobSF finding that the app was indeed sending all its data, including potentially sensitive personal information, over unencrypted HTTP. He emphasized that this is a severe security vulnerability in modern application development.
  • Foreign Infrastructure Endpoints: Portera also used the MobSF report to illustrate the identified backend servers, specifically highlighting the "QQQ" domains, confirming that user data was being exfiltrated to Chinese infrastructure.

Beyond the live MobSF report, the "proof of concept" extended to the physical realm. Portera confirmed that he and his team had purchased the actual smartwatch from Amazon for their investigation. This allowed for the physical hardware analysis and teardown, where internal components were identified and photographed. Though he admitted to some difficulties in the firmware extraction attempt (due to damaged soldering pads), the ability to physically inspect the device and confirm its internal components was a key part of the investigative process. The combination of OSINT, physical teardown, and live software analysis provided a comprehensive validation of his findings regarding the product's origins, construction, and security posture.

Defensive Implications

▶ Watch: Beginning OSINT investigation on smartwatch brand (7:07)

The findings from Michael Portera's investigation carry significant defensive implications for both individual consumers and organizations grappling with supply chain cyber security.

  1. Consumer Due Diligence is Paramount: For individuals, the talk serves as a stark warning: "buyer beware." The allure of cheap electronics from online retailers often comes with hidden costs in terms of privacy and security. Consumers must exercise extreme due diligence, looking beyond attractive pricing and influencer endorsements. This includes scrutinizing seller information, reviewing product safety recalls (e.g., via the Consumer Product Safety Commission website), and being skeptical of unbranded or ambiguously branded items.
  2. Privacy Awareness: The discovery of clear text traffic and data exfiltration to foreign (Chinese) infrastructure for sensitive health and activity data is a major privacy concern. Consumers should understand that using such devices essentially forfeits control over their personal information. Defenders should educate users about the risks of connecting these apps to their smartphones and the potential for unauthorized data collection and misuse, especially given different geopolitical data privacy standards.
  3. Physical Safety Risks: Beyond cyber security, the talk reiterated the very real physical dangers associated with poorly manufactured foreign products, citing examples like flammable goods, lead contamination, and melting power banks. Defenders, especially those in corporate or educational settings, should advise against the use of such products in professional environments where they could pose a fire hazard or other safety risks.
  4. Supply Chain Security is Critical: For organizations, the talk underscores the complexity and fragility of global supply chains. The prevalence of white-labeling and intentional obfuscation makes it incredibly difficult to trace the true origin and security integrity of components or finished products. This is particularly relevant for organizations incorporating IoT devices or consumer-grade electronics into their networks. Defenders need robust supply chain cyber security frameworks to vet devices, components, and associated software, understanding that geopolitical tensions and the reliance on digital systems make these attractive targets for adversaries.
  5. Leverage Open-Source Tools: Tools like Mobile Security Framework (MobSF) are invaluable for defenders. Security teams can use MobSF to quickly analyze third-party mobile applications, especially those associated with IoT devices, for common vulnerabilities like clear text communication, excessive permissions, and suspicious network endpoints. Similarly, Import Yeti can provide some visibility into shipping data for hardware components.
  6. Advocate for Stronger Regulation and Enforcement: While individual action is important, the systemic issues highlighted (trademark abuse, easy evasion of bans) point to a need for stronger regulatory oversight and enforcement from platforms like Amazon and government bodies. Defenders can contribute by raising awareness of these issues and advocating for policies that mandate greater transparency and accountability in the electronics supply chain.

In essence, the defensive posture against these threats requires a multi-layered approach: empowering informed consumers, strengthening organizational vetting processes for hardware and software, and advocating for systemic improvements in supply chain transparency and product safety.

Key Takeaways

  • Buyer Beware: The tempting low prices of unbranded or ambiguously branded foreign electronics often come at the cost of significant security, privacy, and even physical safety risks.
  • Opaque Supply Chains: Intentional white-labeling, trademark abuse (e.g., random letter brands), and dubious company addresses create an incredibly complex and difficult-to-trace supply chain, making accountability almost impossible.
  • OSINT Power: Tools and techniques like FCC ID lookups, reverse image searches, and email/WhatsApp pivoting are powerful OSINT methods for uncovering hidden details about manufacturers and their networks.
  • App Security Failures: Companion mobile applications for these devices frequently exhibit critical security flaws, most notably clear text traffic (unencrypted HTTP) for sensitive data and excessive permissions, leading to potential data exfiltration to foreign infrastructure.
  • Supply Chain Cyber Security: The pervasive nature of these issues highlights the urgent need for robust supply chain cyber security strategies, both for consumers in their personal purchases and for organizations integrating third-party hardware and software.
  • Leverage MobSF: Mobile Security Framework (MobSF) is an indispensable open-source tool for quickly analyzing Android applications to identify vulnerabilities and understand data handling practices.

About the Speaker(s)

Michael Portera is the Vice President of Cyber Solutions at Sequoia, a mid-sized defense contractor based out of DC, with Portera himself located in Huntsville, Alabama (distinct from the venture capital firm of the same name). He brings a wealth of experience to the field, having worked eight years in Big Four Consulting. His background also includes significant red teaming experience, particularly with a Department of Defense red team at a company called Millennium. In 2020, he founded his own company, which was successfully acquired in 2023. Michael Portera is an established speaker at major conferences and has contributed to numerous open-source projects, demonstrating a deep commitment to the cybersecurity community and practical, hands-on security research.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent consumer security investigation that walks through OSINT, FCC database mining, hardware teardown, and MobSF analysis on a $30 Amazon smartwatch. The methodology is sound and accessible, but the findings — cleartext HTTP, excessive permissions, white-label obfuscation, data to Chinese servers — are exactly what anyone who's done this class of work already expects to find. Nothing here moves the needle for a technically experienced audience.

Heather Calloway (CISO) — WEAK

Competent consumer OSINT research that surfaces real product safety and privacy concerns, but stops well short of anything a security leader, policymaker, or institutional defender can act on. The findings are accurate and the methodology is solid — the talk just never escapes the frame of an individual hobbyist investigation.

→ Top-rated talks at Recon Village @ DEF CON 33

All talks from Recon Village @ DEF CON 33