TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Nissan code leaked after bitbucket repo set-up with defaults admin/admin

145 pointsby nucatusover 4 years ago

13 comments

driverdanover 4 years ago
From the screenshot the torrent name is nissan-na-gitdump-EXCONFIDENTIAL.<p>Searching for that lead me to these. I haven&#x27;t confirmed if they&#x27;re legit:<p><a href="https:&#x2F;&#x2F;git.rip&#x2F;exconfidential&#x2F;nna" rel="nofollow">https:&#x2F;&#x2F;git.rip&#x2F;exconfidential&#x2F;nna</a><p>Torrent: magnet:?xt=urn:btih:36cc1d89f8d5155bb08d05d0ed67a0e861f7b536&amp;dn=nissan-na-gitdump-EXCONFIDENTIAL<p>Torrent tracker: <a href="https:&#x2F;&#x2F;newtrackon.com&#x2F;api&#x2F;stable?include_ipv6_only_trackers=0" rel="nofollow">https:&#x2F;&#x2F;newtrackon.com&#x2F;api&#x2F;stable?include_ipv6_only_trackers...</a>
评论 #25676841 未加载
评论 #25674477 未加载
mikestewover 4 years ago
What &quot;defaults&quot;? There&#x27;s no BitBucket default to make the admin account &quot;admin&#x2F;admin&quot;, someone did this intentionally.
评论 #25676608 未加载
flr03over 4 years ago
Should I be waiting for the usual press communiqué &quot;We were the target of a very complex Cyberattack&quot; from Nissan?
评论 #25673355 未加载
orevover 4 years ago
It’s absolutely inexcusable that in 2021 we still have apps that come with default credentials like admin&#x2F;admin. You can yell at users all you want, but history has shown that is not good enough. The blame here at least partially falls on bitbucket for making it so easy to set things up in an insecure way.<p>To all developers reading this: it is YOUR responsibility to do everything you can to prevent your users from shooting themselves in the foot like this.
评论 #25673423 未加载
评论 #25672391 未加载
评论 #25673488 未加载
评论 #25672518 未加载
outworlderover 4 years ago
Maybe people will be able to understand why their &quot;Connect&quot; apps are so horrible?<p>On my Leaf I can theoretically send a route to the car. And theoretically check things like state of charge. These might work. Or might not. Random API RNG seems to dictate that.
评论 #25675645 未加载
评论 #25677349 未加载
encomover 4 years ago
Readable link: <a href="https:&#x2F;&#x2F;archive.ph&#x2F;Q9bKf" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;Q9bKf</a>
that_guy_iainover 4 years ago
Since Nissan and Renault are now one company, we could be seeing Renault code getting leaked soon too since they&#x27;re 100% sharing code internally even if both Nissan and Renault both have projects to do the exact same thing with completely different suppliers.
dzhiurgisover 4 years ago
Possibly can be best thing for them as they don’t bother to make EV that lasts (failing to heat&#x2F;cool batteries, but great cars otherwise). Someone might hack something good now lol.
darth_avocadoover 4 years ago
Lol I&#x27;m more amazed that they have 1 repo, for pretty much everything, than I am that they forgot to change the default passwords. It&#x27;s a nightmare.
评论 #25675341 未加载
denoover 4 years ago
So how ‘open’-source is that car now? This actually might make Nissan more attractive to some people.
评论 #25673202 未加载
评论 #25676062 未加载
评论 #25674465 未加载
stuntover 4 years ago
Default passwords and not enforcing strong passwords are bad idea by design. I thought we learned that 10 years ago.
iridium_coreover 4 years ago
Their production source code has the salt for the encryption algorithm hard coded as the (presumably H1B worker&#x27;s) name &quot;Amalesh&quot;
mattlondonover 4 years ago
Unrelated meta-side-rant: this leak exhibits one of the two types of naming conventions for internal tools that I really dislike:<p>- Unrelated historical&#x2F;comic book&#x2F;movie references, e.g. &quot;Project Morpheus&quot; or &quot;X-37&quot; or &quot;Calligua&quot;, &quot;Wolverine Project&quot; etc etc. Meaningless.<p>- Things like this Nissan leak where everything is an acronym that is meaningless on its own. TTBA. SSKLR. URA. PIIY. What the hell?<p>Both are awful. Please please please if you are responsible for naming something at your work, please choose something descriptive.<p>E.g. instead of picking something &quot;clever&quot; or &quot;cool&quot; like &quot;Boudicca Project&quot; or &quot;Skylark&quot; or some useless acronym like &quot;CTITT&quot; please call your mundane CRM system something meaningful like &quot;Customer Management Tools&quot; or something understandable without knowing the backstory (e.g. &quot;we called it Team Sofa because it replaced and old CouchDB instance, and everyone used to hangout on our sofa in our office when we did meetings - duh&quot;) and easily searchable.<p>Future users and engineers trying to figure things out will thank you.
评论 #25673212 未加载
评论 #25672475 未加载
评论 #25673023 未加载
评论 #25672559 未加载
评论 #25674746 未加载
评论 #25675271 未加载
评论 #25673485 未加载
评论 #25677431 未加载
评论 #25672596 未加载