3 ms·
Yeah granted. But obfuscating the VIN in the HTTP traffic would be easy and would at least help a bit. E.g. the guy that wrote the article would have had to dig
by codeulike 11y ago
Yeah granted. But obfuscating the VIN in the HTTP traffic would be easy and would at least help a bit. E.g. the guy that wrote the article would have had to dig a lot deeper to figure out what was happening. It still would have been scoffed at, had anyone figured it out, I agree.
BTW reminds me: Jeep had this clever system whereby the password was generated randomly by the unit. But it used the system time as a seed, and that system time was always the same cos the thing had just been turned on. The rest is history...
https://blog.kaspersky.com/blackhat-jeep-cherokee-hack-explained/9493/ https://blog.kaspersky.com/blackhat-jeep-cherokee-hack-expla...
- mikeash 11y agoThat Jeep link is great. I heard about the hack when it was first floating around, but never saw the details. Using the time as a seed is a bad idea even if it actually works, of course. It's too easily guessable. But doing it and then failing to even find the current time first is completely silly. You'd think at some point in development someone would have noticed that all the generated keys were identical.
- kingosticks 11y agoDoesn't this system use https?Hence why the author used 'fiddler'.