3 ms·
>"Hackers will be able to pull the data off the USB stick and reverse-engineer it. They'll get an insight into how these cars receive their software updates and
by Ninn 11y ago
>"Hackers will be able to pull the data off the USB stick and reverse-engineer it. They'll get an insight into how these cars receive their software updates and may even find new vulnerabilities they can exploit," he told the BBC.
So? Never thought I would hear a "Security Expert" argue for, and not against security through obscurity. Perhaps this is not the best source for critique.
- pixelcort 11y agoIf the USB stick accidentally contains private keys for signing, that might be of concern. The more important concern is the phishing issue.
- mmarx 11y ago> If the USB stick accidentally contains private keys for signing, that might be of concern. That would still be a problem if the updates were only distributed to repair shops, however (you'd need someone on the inside, but given the number of people involved, that probably wouldn't be too hard).
- Ninn 11y agoSure, but there is no evidence of that, so why even bring it up as an example/excuse as to why anyone would argue this way? It is totally unfair to assume that the content has not already been signed prior to distribution without evidence.
- jamesbrownuhh 11y agoUnfortunately modern "news" is not based on evidence, merely the event of a claim.
- venomsnake 11y agoAlso they could download the bin from the car itself.
- Ninn 11y agoNo, that's not how it works. In some cases sure, but this is not something you just do out of the blue like plugging in a USB.