Live data from Hacker News

Bugs allowed hackers to dox John Deere tractor owners

vice.com

61–70 of 72 posts

Re: Bugs allowed hackers to dox John Deere tractor owners

#62
post #52

Now every litigious John Deere owner will also have a Case.

The lack of replies shows me how few 'farm oriented' people browse HN...Top notch pun

I just saw it and truly appreciate it as a former farm kid who also got to "enjoy" 8 months working at John Deere here in Iowa, it gave me a hearty chuckle.

Re: Bugs allowed hackers to dox John Deere tractor owners

#63

Earlier quoted context omitted.

If a John Deere salesman knocked on that screen door 80 years ago and said, "Mr. Farmer I have something that will make your life easier. The only drawback is when it breaks down, you can't buy parts, can't see repair documatation, and only pricy factory workers whom live far away will be able to repair the machine at set rates. The farmer would have slammed the door, and fed his horses.

To be fair, if you made the pitch that way to farmer today they would as well - those points are all iffy. mostly, though, the nature of labor has completely and utterly changed in 80 years and comparing the two is like apples and oranges.

> those points are all iffy.

for tractors generally, maybe, but have read many things specifically about john deere being very DRM/anti repair, and a quick google seems to highlight that there are court battles being fought over exactly this right now.

https://www.bloomberg.com/news/features/2020-03-05/farmers-f...

Re: Bugs allowed hackers to dox John Deere tractor owners

#64
post #27

Is owning John Deere tractors somehow controversial, since they're talking about how owners were "doxed"? Is there a special place on the web where we can laugh at the hall of shame of John Deere tractor owners? Jokes aside, John Deere are pretty good tractors tho. Very common among farmers here in Norway. ^^

I think the author was using "doxxed" to mean "discovered the ability to expose personal identifying information of", rather than "exposed personal identifying information with the intent to shame by publicizing said PIN". I agree that's not a very accurate usage. They're only slightly controversial here in the Midwestern US. Somewhat like Harley Davidson motorcycles, their users are highly brand loyal due more to hi…

I sometimes think john deere and harley and to a lesser extent ford/chevy are basically americana cults with merchandizing and machinery sales attached

Re: Bugs allowed hackers to dox John Deere tractor owners

#65
post #2

Having worked on a John Deere integration for an agtech company I can't say I'm surprised. The MyJohnDeere API had a lot of idiosyncrasies that smelled like inexperienced or mismanaged development, especially around authentication/authorization. At the time I was working on it they had some extremely arcane authentication process that required round-trip emails, various link clicking and code entering, and all kinds…

We need a new word for these high tech massive farming operations. I come from the Canadian farming sector. Most of the farmers here are individuals, or medium sized family operations. Even the big farms aren't "high tech". There just a lot of guys and a bunch of leased machines. We have essentially 0 "high tech" farms. I wouldn't say "modern farms are very high tech operations", I'd say "high tech industrial players…

For perspective, my parents both grew up on farms and I spent my summers on them. You are right but "farming" used to be a family with 3 acres and an ox and a plow. These small farms you lament are just as much a whole new world to the ox and plow as a 16/20 row combine that can process 150 acres a day is to your childhood. Efficiency comes from specialization which creates incentives for economies of scale. Software will continue to eat the world.

Re: Bugs allowed hackers to dox John Deere tractor owners

#66

Earlier quoted context omitted.

If a John Deere salesman knocked on that screen door 80 years ago and said, "Mr. Farmer I have something that will make your life easier. The only drawback is when it breaks down, you can't buy parts, can't see repair documatation, and only pricy factory workers whom live far away will be able to repair the machine at set rates. The farmer would have slammed the door, and fed his horses.

To be fair, if you made the pitch that way to farmer today they would as well - those points are all iffy. mostly, though, the nature of labor has completely and utterly changed in 80 years and comparing the two is like apples and oranges.

And yet... Deere still gets bought. So clearly someone isn't pointing out something they should be.

Re: Bugs allowed hackers to dox John Deere tractor owners

#67
post #66

Earlier quoted context omitted.

To be fair, if you made the pitch that way to farmer today they would as well - those points are all iffy. mostly, though, the nature of labor has completely and utterly changed in 80 years and comparing the two is like apples and oranges.

And yet... Deere still gets bought. So clearly someone isn't pointing out something they should be.

Or the comparison is flawed, farmers aren't dumb and it makes economic sense to buy the Deere?

Re: Bugs allowed hackers to dox John Deere tractor owners

#68
post #52

Now every litigious John Deere owner will also have a Case.

The lack of replies shows me how few 'farm oriented' people browse HN...Top notch pun

...I only caught the legal connection, and assumed the Case was a capitalization error...

Care to clue in someone whose cultivation experience terminates at a roto-tiller---

Goddamnit. Nevermind. Just clicked. Well played.

Re: Bugs allowed hackers to dox John Deere tractor owners

#69
post #66

Earlier quoted context omitted.

And yet... Deere still gets bought. So clearly someone isn't pointing out something they should be.

Or the comparison is flawed, farmers aren't dumb and it makes economic sense to buy the Deere?

"Farmer" is an interesting word these days. Think giant corp running 1 million acres across 200 sites. And think of "tractor" as a fleet of combines that cost $500K each and are shared across all 200 sites.

The picture of a hard-working solo farmer repairing his only tractor out in the barn is becoming a rare thing. When you say "farmer" today, it is unclear if you mean the multi-billion dollar multi-national, the "manager" for this 400-acre parcel, or the lady next to the field operating the drone or mostly-autonomous equipment. Or perhaps you meant the latest breed--that fellow who greases the conveyor belt in the metal building in the middle of town where they do the vertical farming with the fancy lights and watering systems. No tractors or even dirt involved.

Re: Bugs allowed hackers to dox John Deere tractor owners

#70
post #56
post #48

> Sick Codes said he could iterate and brute force all VIN numbers in the database, as they were "sequential," according to him Seems like they didn't think that people would enter someone else's VIN. A few years back I discovered that I could get activation code for a map update in my car simply by entering my VIN and the product number of the DVDs with the map update. They gave me a list to choose from when I enter…

This is pretty common, oftentimes cars with parts restricted to VIN (special editions, etc.) or online manual or software download portals will ask for a VIN. Sometimes this is to verify parts fitment and sometimes it is to attempt to rate-limit parts purchase (i.e. - to keep a dealer from buying 100 sets of "special edition" wheels and reselling them, they need to supply a unique VIN for each). The difference is tha…

In my case I was able to get activation codes for product I hadn't purchased, but yeah, once personal information is involved, its a whole different game.

There was a lawsuit in Norway a while back were the question essentially was: are you breaking the law if you change the URL? (no, it wasn't). More specifically, a guy logged into Norways DMV and looked up information about his own car and by changing the license plate in the URL he got information about other cars, including their owner. I guess the triggering factor was that he scraped this information into a big database.

In Norway you can freely look up car information based on license plate, but it cost extra (?) to get the name of the owner. So the information wasn't secret in any way.

But that brings us back to the question: where does the line go when scraping the web for information?

Post reply on HN