TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Gone in six seconds? Exploiting car alarms

95 点作者 alphabetter大约 6 年前

4 条评论

nearengine大约 6 年前
I had a Viper alarm with these features installed in my car back in 2012 and immediately noticed that while their iOS app used SSL to talk to the API, it never actually validated the certificate, and was trivial to set up a man-in-the-middle proxy to grab a user's auth token and make requests as them. According to their reply their devs weren't able to replicate it, which told me all I needed to know about their ability to write secure software. It's good to hear they responded quickly in this instance, but I'm not sure I'd ever trust their devices again.
评论 #19345627 未加载
spydum大约 6 年前
So, vulnerable web apps exploited to attack internet connected cars? you&#x27;d think they&#x27;d learn from Nissan like two years ago?<p><a href="https:&#x2F;&#x2F;jalopnik.com&#x2F;how-the-nissan-leaf-can-be-hacked-via-web-browser-from-1761044716" rel="nofollow">https:&#x2F;&#x2F;jalopnik.com&#x2F;how-the-nissan-leaf-can-be-hacked-via-w...</a>
评论 #19344313 未加载
chx大约 6 年前
This where -- literally -- the rubber hits the road and we need extreme regulatory oversight over cybersecurity in cars. I don&#x27;t like fearmongering but can you imagine what would happen if a terrorist group got hold of an exploit like this??
评论 #19345579 未加载
评论 #19344791 未加载
评论 #19344688 未加载
评论 #19344670 未加载
评论 #19344908 未加载
jarym大约 6 年前
So many ‘security’ companies making coding mistakes that there’s simply no excuse for.<p>How are these companies remaining in business? Call yourself unhackable and then don’t bother to even authenticate API requests... mind bogggles.