4 ms·
How long do you set? How much do you test? At some point, you just have to say "enough is enough". It was a few years back, but I think (not entirely sure) the
by bArray 10y ago
How long do you set? How much do you test? At some point, you just have to say "enough is enough".
It was a few years back, but I think (not entirely sure) the requirement time aligned with the time it took to hack bluetooth or something. I think there was a case about hacking car wheels that reported their tire pressure via bluetooth and that was used as a time to be better than. Perhaps this story [1]. I think they were using it to get people to pull over and hijack their vehicle.
But that could be wrong, I just remember there was some discussion about that around the time we were talking about the security requirements. That's the best I can do.
[1] http://arstechnica.com/security/2010/08/cars-hacked-through-wireless-tyre-sensors/ http://arstechnica.com/security/2010/08/cars-hacked-through-...
- raesene9 10y agoOf course all security assessments are time limited, but 15 minutes isn't a time frame I recognise from 10 years as a security consultant... Security assessments are usually measured in days or weeks or for large projects months
- bArray 10y agoI don't think 15 minutes is the limit of vulnerability discovery, I think it's the limit for the exploitation. I think it was weeks instead on months, time was really tight. I honestly can't remember whether they get the source code to work with. If I remember rightly they test the CAN and all wireless signals. I think one of the things they were worried about is an owner re-flashing the on-board software and selling on the car as it might still be under warranty. But of course now that the vehicles are both online and moving towards self-driving, the threat space is completely changing. I think we're approaching the days where a computer virus actually takes lives. "from 10 years as a security consultant..." Out of interest what area do you consult in?