8 ms·
An insurance company’s API exposed customers’ car location histories
- draw_down 9y agoWhen my insurance company offered a discount to use one of these devices a few years back, I smelled a rat. I figured they would use it to observe how fast I drive vs the speed limit so they can decide how "safe" of a driver I am or whatever. But also my insurance is very inexpensive so discounts on it are not a big motivator. I guess location tracking would make sense too, so they can bust you if the car stays in a place other than where it's insured for. Or god knows what else. All of this shit is only going to get worse, a lot worse.
- kosma 9y agoUntil there is some kind of law in place that makes companies financially responsible for this kind of blunder, it will proliferate. In the current state of affairs it's simply not economically justified to implement proper security.
- proaralyst 9y agoI have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!
- jacquesm 9y agoHere's an interesting thought: what with the money there is to be made in security these days programmers that actually know everything there is to know about security will leave applications development. There is a good chance that the lure of security consultancy $ is resulting in a degradation of the quality of the applications.
- saral 9y agoApart from this time to market is also one of the reasons that such things get released to end customers.
- bkkssnn 9y agoAre you saying developers in general are subconsciously making low security products to raise the $ in security jobs globally, because they might some day switch career?
- klez 9y agoNo, they're saying that if the money is in security, developers that know about security will go to security, and whoever remains as a developer will not be good at security.
- sillysaurus3 9y agoThere's not nearly as much money in security as most security consultants would like you to believe. It's in their best interest for most people to believe there's a huge amount of money waiting for you if you switch to security. Unless you're someone with specialized experience (crypto), you as a pentester are worth around $100k/yr. That's excellent money, but it's not the massive margin that would drive people away from webdev.
- pwg 9y agoActually, the parent is correct. If the company providing the service were financially liable for these blunders, they would be careful to select contractors that are capable of meeting the security needs. As it is now, there is no financial incentive to select the "security aware" contractor, and the "non-aware" one is so much cheaper...
- toyg 9y agoOr rather they would hire more pentesters to make sure the sw they get is robust. On paper everyone can write "secure" apps...
- haburka 9y agoThere are extensive laws in place that protect the personal information of patients and students. If a hospital had this same issue, then it would be fined and depending on the state, it would have to inform all of it's users that it may have leaked personal information. Similarly, educational instituons will not share your educational record with your parents no matter how much they beg unless you're a minor. It's not a stretch that there should be laws that affect all companies that collect data on their users. I hope it happens soon! These companies should be paying quite a bit in fines for these mistakes, not just a few thousand for a bug bounty. Otherwise our personal information will most likely leak and be all over the web.
- pyre 9y ago> Until there is some kind of law in place that makes companies financially responsible for this kind of blunder, it will proliferate. It will still be out there. For example, in a startup that's trying to get off the ground, going bankrupt because of security issues isn't that much different than going bankrupt because you failed to gain traction. It will still be put off to "later." That said, with significant financial penalties there will be a point where the startup assesses the cost of security to be worth it (vs. now where there is no downside other than bad PR).
- sofaofthedamned 9y agoIt's a shame he can't name the telematics company. I have a suspicion it's one I interviewed at a few years ago.
- jacquesm 9y agoFunny, you don't name it either.
- GavinMcG 9y agoNaming it on a suspicion alone would be irresponsible.
- jacquesm 9y agoThat's a qualified statement, there is nothing irresponsible about that. Telematics companies bear close watching anyway. Right now it is as far as I'm concerned a content free statement.
- GavinMcG 9y agoIt's absolutely irresponsible, even with qualifications, given what we now know about how people use that information. Witch hunts happen even with qualified statements, and down the road people who read qualified statements tend to forget the qualification and give the negativity more weight than it deserves.
- sofaofthedamned 9y agoThank you. Knowing like most industries, the layers of ODMs and OEMs etc, it's hard to pin down who exactly is responsible for a security cockup. And, funnily enough, having an interview there I wasn't inclined to do a recce on their infrastructure. Also, not having a device, I didn't have endpoints or traffic to test.
- sofaofthedamned 9y ago
- jstanley 9y agoSo they had this vulnerability live for 3 years, didn't even pay a bounty, and they still don't get named or shamed? What incentive is there to do a better job if they can just do a shitty job and nobody finds out? Name and shame, please!
- KennethWilliams 9y agoshe was a waitress in a cocktail bar now she owns a BMW car... http://bit.ly/2jdTzrM http://bit.ly/2jdTzrM
- deleted 9y ago[deleted]
- leephillips 9y agoTerrible, but they did fix it rather quickly once the flaws were disclosed. Given many other such stories, the almost expected outcome would be to deny the problem, have the discloser prosecuted or sued, and put out a fix six months later that made things worse.
- OliverJones 9y agoThe EU and its member countries are still interested in personal privacy. Do they regulate insurance providers? Could EU, or Italy, exact a penalty against this provider for failing to do the most elementary of penetration tests on this system? Perhaps some of the penalty should be a return of premium payments to customers whose information was potentially exposed. The point is to make the business-risk managers in other provider companies say to their executives: "We cannot take the risk of skipping cybersecurity hardening. If we do skip it and we get caught, our business will be forced into bankruptcy."
- Beltiras 9y agoPost-GDPR this would have resulted in a 20 million euro fine.....
- bkkssnn 9y agoOr 4% of total global revenue ;)
- Beltiras 9y agoWhichever is higher.
- EwanToo 9y agoCould have, not "would" have - the fine is variable. I doubt it'll get enforced regularly.
- Beltiras 9y agoThe GDPR is vague but the description details shockingly vulnerable APIs that do not come close to "industry best practices". They would have been made an example of.
- red_hairing 9y agoit's really sad how young online political activists have adopted privacy issues instead of adopting issues like workers rights, vacation time, pay, a strong welfare state, universal healthcare etc...
- bbzealot 9y agoThe struggle for privacy and for workers rights, vacation time etc. can coexist, I don't see anything wrong in that.
- pjc50 9y agoGenerally they have adopted a lot of those, but privacy is kind of our specialisation as tech people. Often we see it as a necessary prerequisite to the others. Especially worker's rights: mass surveillance is used against worker organisation. Dismissing people focusing on "X" instead of "Y" is useless and disruptive.
- aphexbr 9y agoWhy would he be capable of only addressing one issue at a time? If I fight against racial discrimination, for example, why does that mean I'm not also battling for workers' rights?
- qntty 9y agoThe guy who wrote this is Italian... maybe he's satisfied with the state of many of these things in Italy.
- Spooky23 9y agoI can't believe that anyone would voluntarily sign up for this. Frankly, insurance isn't that expensive. Having a little third party controlled snitch hooked to your car is a security issue, period. The fact that the implementation is a shitshow is just icing on the cake.
- deleted 9y ago[deleted]
- emiliobumachar 9y agoWell, it seems a lot more reasonable than the popular default of trading all your data for free services that either have very cheap alternatives, or would have if there was a market for it. I'm speaking from guilt.
- Normal_gaussian 9y agoat £1400 last year my insurance is expensive. Partly due to living in a city and using on street parking but mostly due to my age (<25). My mother, who had the same model, paid £250. The 15% discount for taking a black box still isn't worth it for me however.
- gambiting 9y agoI drive a car with 380bhp, so while the insurance without the black box is about £300 more than the one with it, I'm pretty sure it's not worth getting the box. I pay about £1000/year at the moment.
- Spooky23 9y agoWow! Being part of a late 30s couple with pretty boring driving history in a small city pays I guess. I pay like $700-850 (depending on how you break out umbrella liability cost) for maxed out coverage in an above average cost US state. I think I paid around $1200 when I was a dumb kid with tickets. :) Even if there were siginifciant savings, it wouldn't be worth it to me to have that kind of telemetry being gathered. It can only be used against you in a accident situation.
- scarface74 9y agoNo mention of the irony of someone who doesn't use Google Play Services because he only uses open source software being willing to attach a device to his car, running closed source software, that tracks everything he does in his car?
- TillE 9y agoI think I have a similar attitude. I have Google's location tracking on, but search history, YouTube history, etc turned off. I'm much more sensitive to digital privacy because it has complex, wide-ranging implications, whereas my location is a limited set of data that I'm more comfortable sharing with a semi-trusted company.
- chopin 9y agoI wouldn't want to know a company when, how often and which doctors I consult for one. If you don't want to share your search history you may not want to share your location data either. I would see these as equivalent.
- pyre 9y ago> I wouldn't want to know a company when, how often and which doctors I consult for one. Depends. A lot of doctor's offices are in "medical parks," so it's entirely possible they don't know which doctor you are seeing or why. They have easier access to that information via your calendar (if you use it) than your location.
- stronglikedan 9y agoAlso, even if you did go to a doctor's office in the middle of nowhere with nothing else around and only one doctor working there, that doesn't mean you are there to see the doctor. For that matter, your location data couldn't be proven to be yours on merit alone. Anyone can be using my car, and anyone can have my phone, at any given time.
- whiskeySix 9y ago
- libeclipse 9y agoWhat's the point of hiding the identity of the company here? The issue has apparently been fixed and I'd rather know which company had it so that I can avoid them.
- wtbob 9y agoNote that with the latest changes to Android, using mitmproxy to analyse the behaviour of apps has become impossible: apps refuse to accept personally-installed certificates. In the future, we'll see less revelations about this sort of thing, not because it has become rarer but because Google have chosen a course of action which obscures it. (it also breaks things like personal or corporate CAs, but that's a different problem)
- mhils 9y ago+1 to this. We (mitmproxy) see the changes in Android Nougat as a very unfortunate development for this kind of privacy research. :( Some context: https://github.com/mitmproxy/mitmproxy/issues/2054 https://github.com/mitmproxy/mitmproxy/issues/2054
- pyre 9y agoIt's also hardening against malware basically doing the same thing that mitmproxy does though.
- mhils 9y agoFor Android < N, if you install a custom CA, you'll get a permanent "Network may be monitored by an unknown third party" notification that cannot be dismissed and stays across reboots. Android wasn't really "insecure" in that regard beforehand. Your point is valid, but I think it's a negligible improvement that comes in hand with severe implications for privacy research.
- thavch 9y agoHaving worked in the connected car/telematics industry for a while as a contractor, I can very well relate to this and can confirm that the security systems in place inside the car's telematics unit is not good enough. For example, in one of the oauth process of authenticating a car with the cloud, the VIN was passed around as a client secret and MDN of the modem as the username ! We recommended to immediately stop this practice, but the "IT" dept of the automotive maker said, " You know we sell cars, not security software." There is no budget to rewrite the mechanism, and the telematics unit cannot be updated OTA. The upgrade requires customers bringing the car to a dealer and USB stick updates etc. I believe the frequent bursts of data from the car was given to insurance companies. Or they were trying to package insurance deal along with the car sale or something.