5 ms·
>At this point, we identified that it was also possible to access customer information and run vehicle commands on Honda, Infiniti, and Acura vehicles in additi
by twojacobtwo 4y ago
>At this point, we identified that it was also possible to access customer information and run vehicle commands on Honda, Infiniti, and Acura vehicles in addition to Nissan.
>We reported the issue to SiriusXM who fixed it immediately and validated their patch.
Nice to see that it was addressed quickly, but it's frightening that such a shoddy system design was accepted by auto manufacturers with seemingly no oversight.
- julianlam 4y agoAre you surprised? I have seen companies prepare for a SOC2 compliance audit, and I get the feeling that these companies like vendors because the audit doesn't apply to vendors, so all they really have to do is ask the vendor to pinky swear that the software is safe.
- endtime 4y agoWhy would they spend money on that? This severe vulnerability isn't going to hurt their bottom line, even if it "should". (I'm not endorsing this perspective, to be clear, just recognizing that it exists.)
- User23 4y agoIndeed. Everyone says that they care about online security, but revealed preferences show that virtually nobody actually does. On the other hand revealed preferences tell a completely different story about physical security.
- ticviking 4y agoIsn't doing that math and seeing how heartless corporations the opening premise of "Fight Club"?
- spookthesunset 4y agoIf Fight Club was filmed today, I’m pretty sure the final scenes would be blowing up the media buildings and not the banks/credit card buildings…
- Retric 4y agoAs in Twitter/Facebook/Google or CNN/Fox News?
- philsnow 4y ago> This severe vulnerability isn't going to hurt their bottom line, even if it "should". When there's damnable, devastating security news for some publicly-traded company that makes it to the big news sources, the stock takes a 0-10% dive and then completely recovers within a couple weeks. Even if the company's response is completely bungled, mismanaged, or miscommunicated, the market doesn't understand security issues and it seems like the company just benefits from the news exposure. I wish I kept notes on the last few times I've seen this happen so that I could cite examples.
- mughinn 4y agoIt's not the market, the customers don't care. They won't stop buying the product because of security issues, it's because of THAT that the price recovers, not because "the market" doesn't understand security If the customers cared, there would be significant drop in the price of the stock because a vulnerability like this would result in lower sales
- kube-system 4y agoWell, some traders are selling on the news, which is what causes the dip. Most investors don't really have a deep technical grasp of the situation and don't fully realize how common software vulns are, don't understand their impact, or don't understand the effort to remediate them.
- hamburglar 4y agoI scooped up a bunch of SolarWinds stock on this theory but just barely made my money back a year later, and wouldn't have if I'd held it until now...
- kahrl 4y agoIdiotic claim with no proof. SiriusXM is a publicly traded company. If they were found responsible for vulnerabilities that lead to stolen cars, the lawsuits and public sentiment ABSOLUTELY would affect their bottom line. Just look at Kia and Hyundai right now. What are you even talking about?
- sofixa 4y agoWouldn't the same argument apply to Equifax?
- ethbr0 4y agoEquifax's customers aren't about to stop buying Equifax products because they leaked a bunch of PII.
- kahrl 4y agoNO IT WOULD NOT. One business is dependent on their media image to sell cars, one business would rather you forget they exist because they are selling your identity to third parties. WHAT ARE YOU TALKING ABOUT?
- mschuster91 4y ago> Nice to see that it was addressed quickly, but it's frightening that such a shoddy system design was accepted by auto manufacturers with seemingly no oversight. That's thanks to the old tale of "outsourcing what is not a core business". I get it, it's fine when you have the capacity and capability to do oversight - but in most cases, the beancounters eventually decide that this capacity is not needed, and then shit like this happens.
- TedDoesntTalk 4y ago> outsourcing what is not a core business Except that this telematics product is a core business unit for SiriusXM.
- mschuster91 4y agoYeah but not for the car maker. So the suppliers cut corners whenever they can, and the demands from the manufacturers tend to be insane as well.
- TedDoesntTalk 4y agoThe vulnerability was in a Sirius product. If you’re suggesting auto manufacturers don’t write their own telematics software because it’s not core to their business, then… hallelujah! Can you imagine what kind of crap they’d deliver? I’d you’re suggesting something else, then I don’t understand.
- hackernewds 4y agoImagine the risk when cars can also drive themselves, as 6 ton battering rams that can also self implode the evidence.