11 ms·
Web hackers vs. the auto industry
- bhargav 4y agoGreat finds. I always wondered how "White hat" hackers didn't land themselves in legal trouble while probing and toying around with systems like this. How do you ensure you won't be tracked down and legally charged?
- ultra_nick 4y agoThey just ask for permission.
- tester457 4y agoI don't know about the auto industry but web apps post bug bounties on hackerone. And Google's bounty program reward hackers who will find bugs in apps with over 100 million installs, or in google's open source apps. And they pay up to $30,000 per bug depending on impact.
- bashwizard 4y agoMost of us get private invites by the companies themselves or there are already open public bug bounty programs on HackerOne, Bugcrowd, Intigriti etc for anyone to try to hack them within confined scopes. There are a lot of money to be made if you're good, so there's the incentive as well.
- somewhat_drunk 4y agoHow much money can a good hacker make per year doing this sort of testing?
- RektBoy 4y agoHow much bounty money did you receive from these multi-billion companies?
- iancarroll 4y ago$0, as far as I know. For example, Ford has HackerOne programs but only pays bounties for an extremely small set of their applications. Other companies had no program at all, like Ferrari, and we had to message them on LinkedIn. (I worked on some parts of this research.)
- jancsika 4y agoIs there a way to leverage any of this for a jailbreak? It would be fun to buy a Prius Prime and play Quake on it with steering and horn as controls.
- still_grokking 4y agohttps://www.youtube.com/watch?v=NRMpNA86e8Q https://www.youtube.com/watch?v=NRMpNA86e8Q
- andylynch 4y agoWhen reading that article I wondered whether anyone felt tempted to pipe up on that Mattermost server and introduce themselves.
- WarOnPrivacy 4y agoThe next time someone asks me to name my heroes, I'm sending them a link to this article.
- ck2 4y agoProbably impossible on an EV but otherwise unscrew the antenna connections on your car and use the key for the lock. My year 2000 car with stick-shift and window cranks seems more valuable now, it even has mechanical accelerator/throttle, lol hack that.
- MaanuAir 4y agoLooks like another recurring movie where evil/young wizards (car manufacturers) would summon some attractive daemons for their own needs (profit/power) thanks to some new magic spells (IoT tech) without mastering it, leading to unintended consequences (vulnerabilities and bad exploits) that others wiser wizards (security researchers/industry) know for ages. Not good, but seems to be the IT curse repeating again and again.
- pjmlp 4y agoThis is a great example why one should not rely on frontend validation and assume all requests are coming from the browser. Yep, I see this all the time in junior's code.
- still_grokking 4y agoWe need some kind of "license to code" finally. People doing such things should never got the job in the first place.
- concordDance 4y agoNo Tesla on the list? I guess they've probably started remote stuff earlier and thus all the hacks and disclosures happened ages ago.
- stefanoco 4y agoAlthough all vulnerabilities affect cloud services and/or mobile apps (SaaS and similar areas) looks like this eventually leads to closely interact with the single vehicles. Which raises questions about the recent Cybersecurity UNECE Regulations R155 and R156 that any new vehicles manufacturer must take into account while submitting a new model for approval in Europe and other areas. Those regulations explicitly cover the vehicle itself and not connected cloud services. Should an urgent revision extend coverage?
- squeegeeninja 4y agoThe consensus among manufacturers (and auditors) is that R 155 does cover the security of vehicle backend services with its wording and intent. There are of course still active discussions about what exactly constitutes a backend service, e.g. whether a production planning system that provides data to a direct vehicle backend service should also be considered relevant under R155. But in general, this is something that manufacturers in Europe are aware of and are working towards.
- still_grokking 4y agoWe've just seen the great results of this efforts.
- tambre 4y agoFrom R155 4.3.1 "threats regarding back-end servers related to vehicles in the field" covers it? Of course the whole standard is still pretty focused on the on-vehicle side of things, but it certainly touches on it. Surprised to see these even mentioned on HN. I've read R155 as part of my job and am responsible for implementing it.
- kdjkdjk 4y agonah, automotive hackers hang around here too ;)
- scohesc 4y agoThis is exactly the reason why I'm trying my best to keep my non-smart vehicle running as well as possible for as long as possible. I have no idea what exactly will be exposed to the manufacturer's backend, what can be manipulated and hacked on the front-end, and the possible safety repercussions involved with this. Who's to say some government/corporate espionage results in a manufacturer getting their back-end hacked and having every online vehicle immediately get their brakes applied? Definitely some Black Mirror-esque stuff... Not to mention the convenient ability to surveil any vehicle and their locations with a busted and easily crackable API - why does it take external hackers with a (thankfully good) sense of morals and ethics to bring these things to companies' attention? It'll probably take something hitting national/international news before lawmakers or companies take this security seriously.
- Gordonjcp 4y agoI have a couple of late-90s Range Rovers. They're pretty secure from hacking, having nothing more sophisticated than an FM stereo on board.
- julianz 4y agoAnd also, given that with Range Rover reliability they'll perpetually be in the shop, you'll always know where they are!
- Gordonjcp 4y agoI've never actually had one fail in service. My older one (which is actually a few months newer than my "newer" one which I got a couple of years ago) did over 100,000 miles with only fairly minor repairs, and is currently on 270,000 miles. I'd drive either of them to any spot in the world. I'd carry tools and spares, but I'd still drive them there.
- hef19898 4y agoStill Classics or already P38s?
- ballenf 4y agoThe scary thing with any of these disclosures is the thought that state intelligence would be stupid to not spend a lot more resources than these ethical hackers did to discover the same.
- deleted 4y ago[deleted]
- AlexandrB 4y agoWould love to see a regulatory requirement for a physical off switch for vehicle network connectivity. Probably won't happen though.
- berjin 4y agoThe problem is that the power thirsty law makers aren't much different than hackers since they also want access to everything.
- zzz345345 4y agoThat or guides that walk you through the process of destroying wireless capabilities.
- luxuryballs 4y agoironically they just passed a law in the US that will require all new vehicles to have a remote kill switch added by the manufacturer https://dailycaller.com/2021/11/29/barr-bidens-infrastructure-bill-contains-backdoor-kill-switch-for-cars/ https://dailycaller.com/2021/11/29/barr-bidens-infrastructur...
- Mountain_Skies 4y agoReally wonder how long it will take before you can't renew your vehicle registration unless your older vehicle has been "upgraded" to include such a kill switch?
- jimt1234 4y agoI can't wait until some junior dev pushes a change to the system and shuts down all 2026+ vehicles, sorta like a nationwide "carmageddon" (https://en.wikipedia.org/wiki/Interstate_405_(California)#%22Carmageddon%22 https://en.wikipedia.org/wiki/Interstate_405_(California)#%2...).
- autoexec 4y agoEven if the devs don't accidentally flip the switch themselves, they'll screw up the implementation so some enterprising hacker will be able to do it.
- mike_hearn 4y agoA few recurring patterns here: - Broken API authentication mechanisms, SSO that doesn't work properly. The frequency with which they could simply register accounts and then make themselves some sort of admin by sending ordinary HTTP requests, without ever once needing to confirm with anyone in person, is quite astounding. - Everything being totally exposed on the internet: frontends, backends, all of it. Apparently IP firewalls are history. - Stringly typed APIs and protocols in which adding escaped control characters in various places allows bypass of critical comparison logic. - And a bit of SQL injection. Apparently only worth looking for on old web apps - progress? It feels like the ad-hoc way user accounts were added to the web platform have led to a universe of different implementations and varying exploits. Still, it'd be good to know what their failure rate was. How many companies did they attack without finding any (serious) problem?
- TeMPOraL 4y ago> And a bit of SQL injection. Apparently only worth looking for on old web apps - progress? Yes, but very minimal and disappointing. Sure, people got serious about this and today, SQL injection is hard to near-impossible to introduce using modern frameworks and practices. But we got there by learning the wrong lesson. We've treated SQL injection as its own vulnerability class. We've taught a generation of developers to Not Write SQL Statements By Hand, to Use Prepared Statements or Use ORMs. Libraries and frameworks were changed accordingly. Sanitizing, which evolved to "Web Application Firewalls", was introduced to detect and block SQL injection attempts. We've solved this as a specific case, instead of learning the general principle: never work with structured operations on structured data in their string representation form. "Stringly typed APIs" you mention are just another form of this, they're the same class of problems as SQL injection. So are XSS attacks. So are ${any other query language} injection attacks. So is your site breaking apart because of a stupid mistake or malformed user input that broke your templating engine. All of them are caused by gluing unstructured strings together and then deserializing the result. Operations like "interpolate this value in this place of structure/query" aren't string-level operations, they're structure representation level operations (e.g. DOM node replacements). If you do them in their natural representation, injection vulnerabilities cease to exist.