TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hacked Jeep USB update criticised

26 pointsby daledaviesover 9 years ago

5 comments

Ninnover 9 years ago
&gt;&quot;Hackers will be able to pull the data off the USB stick and reverse-engineer it. They&#x27;ll get an insight into how these cars receive their software updates and may even find new vulnerabilities they can exploit,&quot; he told the BBC.<p>So? Never thought I would hear a &quot;Security Expert&quot; argue for, and not against security through obscurity. Perhaps this is not the best source for critique.
评论 #10177380 未加载
评论 #10177246 未加载
jnbicheover 9 years ago
Can&#x27;t believe that they didn&#x27;t think to include a way to verify the USB&#x27;s integrity with strong crypto, and clear instructions on how to do this. Yes, non-tech savvy customers would be vulnerable to phishing (since such a letter would simply omit this step), but at least it would be <i>possible</i> for tech-savvy individuals to do so.<p>If they had done this right, they would have sent the USB with a validation step <i>and</i> widely advertised this step, so that all users would be aware of the need to do it, maybe even branding a simple software package to verify the contents as something like &quot;UConnect SafeCheck&quot;.<p>Hopefully, they at least have a secure way to download it online (but given actions up to now, I&#x27;m not optimistic).<p>Edit: Owners can download it via https (albeit with SHA-1), but I&#x27;d be surprised if there&#x27;s a way to validate the integrity of the downloaded file. Also, they&#x27;re advertising that link without the SSL (and indeed, it allows non-SSL connections).
评论 #10177635 未加载
评论 #10177470 未加载
评论 #10177471 未加载
Retr0spectrumover 9 years ago
Does anyone know where I could download an image of the update? I just want to poke around.
评论 #10177627 未加载
评论 #10177874 未加载
altharazover 9 years ago
After the False Promises of Inheritance emails, it seems that we&#x27;ll switch to False Security Updates USB keys letters.<p>If hackers goes into hardware, maybe should we also start working on Scam letters filters?
ck2over 9 years ago
Research the last year your favorite car model was made with mechanical steering and mechanical accelerator and only buy those. You only have to go a decade back at most like I did.<p>You might want to stick with those years considering industries that have little knowledge or care about security are endangering your very life at highway speeds.<p>It&#x27;s going to take them another half decade to care about these things and they will probably just solve it by lobbying politicians to waive liability instead.
评论 #10177853 未加载
评论 #10177576 未加载
评论 #10177432 未加载