Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Thursday January 22 2015, @02:31AM   Printer-friendly
from the Progressive-for-the-hackers dept.

An electronic dongle used to connect to the onboard diagnostic systems of more than two million cars and trucks contains few defenses against hacking, an omission that makes them vulnerable to wireless attacks that take control of a vehicle, according to published reports.

US-based Progressive Insurance said it has used the SnapShot device in more than two million vehicles since 2008. The dongle tracks users' driving to help determine if they qualify for lower rates. According to security researcher Corey Thuen, it performs no validation or signing of firmware updates, has no secure boot mechanism, no cellular communications authentication, and uses no secure communications protocols. SnapShot connects to the OBDII port of Thuen's 2013 Toyota Tundra pickup truck, according to Forbes ( http://www.forbes.com/sites/thomasbrewster/2015/01/15/researcher-says-progressive-insurance-dongle-totally-insecure/ ). From there, it runs on the CANbus networks that control braking, park assist and steering, and other sensitive functions.

http://arstechnica.com/security/2015/01/wireless-device-in-two-million-cars-wide-open-to-hacking/

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 1) by tftp on Thursday January 22 2015, @07:12AM

    by tftp (806) on Thursday January 22 2015, @07:12AM (#136891) Homepage

    until some misanthrope sends someone else's car barreling into a ditch with their phone, I guess. ...well, okay, that damn near happens all the time already, I guess.

    Yes, but with the driver's own phone.