TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

My car insurance exposed my location

58 点作者 daureg超过 7 年前

6 条评论

jimnotgym超过 7 年前
comments from the first time this was posted here <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14314205" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14314205</a>
carbocation超过 7 年前
Denouement, in which the author is not rewarded:<p>&gt; <i>The company fixed the leak 3 weeks later by providing new Web services endpoints that use authenticated calls. The company mailed its users saying them to update their App as soon as possible. The old Web services have been shutdown after 1 month and half since my first contact with the CERT Nazionale.</i><p>&gt; <i>I could be wrong, but I suspect the privacy flaw has been around for 3 years because the first Android version of the App uses the same APIs.</i><p>&gt; <i>I got no bounty.</i><p>&gt; <i>The company is a leading provider of telematics solutions.</i><p>I wonder how much that flaw would have fetched from a malicious actor?
评论 #15886392 未加载
wpietri超过 7 年前
Wow. This is gross negligence. Short version: the guy&#x27;s insurance company had him put a GPS-enabled device in his car to measure usage. With no auth and only the car&#x27;s license plate number, you can track the car, find out who owns it, and get a bunch of stats.<p>This is the kind of thing that should result in a fine of millions of dollars. They never even tried to secure this.
sebazzz超过 7 年前
I have not seen him mentioning that the web service is apparently invoked over unsecure http. You can still add authentication, but if the service is running over http yu might as well not have any authentication at all.
评论 #15886719 未加载
评论 #15886588 未加载
razki超过 7 年前
Pretty certain I read this last year.
kevin_thibedeau超过 7 年前
Unless there has been some new innovation in this space, the OBD behavior trackers are just accelerometers. The typical placement down in the driver&#x27;s footwell makes GPS too unreliable to bother with. The GPS correlation comes from being foolish enough to install their app.
评论 #15886441 未加载
评论 #15886413 未加载
评论 #15886443 未加载
评论 #15886549 未加载