Live data from Hacker News

Void captures over a million Android TV boxes

news.drweb.com

11–20 of 113 posts

Re: Void captures over a million Android TV boxes

#11
post #2

What's going to be even more fun is when the cars gets hacked, given that their are 100+ (200+) car makers, specially with ev cars (WSJ claimed 140+ makers in China) Bloomberg claimed 500+. I'm not dissing Chinese makers. I'm only sure that like everything there's an exponential curve of how serious companies take security. I'm guessing, of the car makers out there, Tesla and Rivan are near the top since they are new…

Even if the companies took security seriously (which they don't since it rarely affects their bottom line, even in the event of a breach), it's one of the hardest topics in IT, and there are very few people actually competent in it.

With the explosion of the number of those boxes, we added more surface of attack, but the number of good security people didn't increase.

Re: Void captures over a million Android TV boxes

#13
post #2

What's going to be even more fun is when the cars gets hacked, given that their are 100+ (200+) car makers, specially with ev cars (WSJ claimed 140+ makers in China) Bloomberg claimed 500+. I'm not dissing Chinese makers. I'm only sure that like everything there's an exponential curve of how serious companies take security. I'm guessing, of the car makers out there, Tesla and Rivan are near the top since they are new…

Every company, car or otherwise, has security grossly inadequate for the current and especially the near future threat landscape. Everybody knows everything is easily hacked and companies people tout as exemplars like Apple and Microsoft just keep piling on the abject failures to prove the common wisdom true like it is going out of style. Decades of claimed success followed shortly after by failure after failure should really pound in the lesson: "Fool me once, shame on you. Fool me ten thousand times, shame on me."

You need systems secure against teams commercially motivated attackers with 10 M$+ budgets and tens of full-time professionals working for years. Nobody in commercial IT would even dare to claim they could stop such attacks even though they are regular occurrences these days. If they do not even dare to say they can do it, why on Earth would anybody believe those vendors have, what, accidentally made things better than they think?

Ranking companies by security is like ranking the relative resistance of individual sheets of toilet paper to bullets. Sure, maybe the single ply toilet paper is not as good as the two ply, but neither of them provide objectively useful degrees of protection. And that is just talking about the bare minimum to protect against current threats.

If you can hack every Honda at rush hour to turn off the brakes, slam the accelerator, and drive slightly into oncoming traffic how many people do you think would die in the next minute before anything can be done or people informed to stop driving their cars? 1K? 10K? 100K? 1M? Does Honda survive killing more people than died in most wars? If a criminal organization demonstrates they can and will do it, how much would Honda pay in extortion to avoid being put out of existence and their executives jailed? How much security is adequate to avoid the deaths of thousands to millions? Certainly orders of magnitude more than the 10 M$ attacks that steam roll the "best commercial IT security" available today. Any reasonable number is vastly in excess of what these companies can secure today.

20 years ago, the hackers were 18 year olds demanding 300 dollars from grandmas. 10 years ago, the hackers were 28 year olds founding businesses demanding 10 thousand dollars from small businesses. Now they are 38 year olds managing teams demanding millions from billion dollar companies. Soon we will see them demanding billions if the trends continue for 5-10 more years. The software security doomsayers were right, just early. Even Mark Zuckerberg took a decade with huge piles of VC funds to get to a multi-billion dollar valuation; you have to forgive the hacking teenagers who had to bootstrap their criminal enterprises for taking so long.

Re: Void captures over a million Android TV boxes

#14
post #4
post #2

What's going to be even more fun is when the cars gets hacked, given that their are 100+ (200+) car makers, specially with ev cars (WSJ claimed 140+ makers in China) Bloomberg claimed 500+. I'm not dissing Chinese makers. I'm only sure that like everything there's an exponential curve of how serious companies take security. I'm guessing, of the car makers out there, Tesla and Rivan are near the top since they are new…

The sorry state of IOT security combined with V2V/V2X really worries me.

The S in IoT is for Security; the P is for Privacy.

Re: Void captures over a million Android TV boxes

#15

Earlier quoted context omitted.

That's not the impression I've gotten from Tesla's software. From the flash wear issue to the numerous vehicle opening issues, to the entire mess of their UDS implementation, there's quite a lot to complain about compared to a hypothetical "best practices" manufacturer, as opposed to the dumpster fire software of other OEMs.

It's easy to complain since they're the only manufacturer who opens up your car as an API

None of the issues I mentioned where discovered via API. The flash wear issue was discovered by bricked cars. Security researchers are pretty good at publishing about remote unlock mechanisms for all manufacturers, though Tesla's bounty program has helped. The UDS implementation issues are non user facing and were discovered by reverse engineering. Ford, as an interesting point of comparison, published a competent (if incomplete) open source UDS server.

Re: Void captures over a million Android TV boxes

#16

Earlier quoted context omitted.

Tesla is amazingly good at software development practices. It’s the new Fords that are bricking themselves via updates, not Teslas.

That's not the impression I've gotten from Tesla's software. From the flash wear issue to the numerous vehicle opening issues, to the entire mess of their UDS implementation, there's quite a lot to complain about compared to a hypothetical "best practices" manufacturer, as opposed to the dumpster fire software of other OEMs.

I don't know anything about their practices, but once bumped into this Reddit post by someone claiming to be ex-Tesla and describing exceptionally bad practices. There's no way to verify the claims, they could as well be total misinformation. But I found the link to that Reddit post:

https://old.reddit.com/r/EnoughMuskSpam/comments/99sbwa/form...

Re: Void captures over a million Android TV boxes

#17
post #3
post #2

What's going to be even more fun is when the cars gets hacked, given that their are 100+ (200+) car makers, specially with ev cars (WSJ claimed 140+ makers in China) Bloomberg claimed 500+. I'm not dissing Chinese makers. I'm only sure that like everything there's an exponential curve of how serious companies take security. I'm guessing, of the car makers out there, Tesla and Rivan are near the top since they are new…

> I'm guessing, of the car makers out there, Tesla and Rivan are near the top since they are new and have people with security experience? From what little has been leaked, I really doubt Tesla should be enar the top.

Which car makers offer prizes at pwn2own?

Re: Void captures over a million Android TV boxes

#18

Earlier quoted context omitted.

Tesla is amazingly good at software development practices. It’s the new Fords that are bricking themselves via updates, not Teslas.

That's not the impression I've gotten from Tesla's software. From the flash wear issue to the numerous vehicle opening issues, to the entire mess of their UDS implementation, there's quite a lot to complain about compared to a hypothetical "best practices" manufacturer, as opposed to the dumpster fire software of other OEMs.

Was it Chris Lattner or Francois Chollet that joined Tesla, set up their CI pipeline, and politely left?
Post reply on HN