Live data from Hacker News

Hacking Subaru: Tracking and controlling cars via the admin panel

samcurry.net

271–280 of 334 posts

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#271
post #4

Hah, them being able to bypass the 2FA by commenting-out the line: $('#securityQuestionModal').modal('show'); is... mind-boggingly stupid of whoever got the job to write that Starlink web-app. OTOH, the hacker hijacked a Starlink employee's account to get in, isn't that over the line in terms of "ethical hacking"/legality standpoint?

It's like they had no idea of how 2FA is supposed to work apart from what it looks like as a user

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#272
post #41

Earlier quoted context omitted.

I love my Subaru as far as reliability, all wheel drive performance in snow and ice, and such. But OMG it's consumer tech was dated when I bough it, and it's just full of inexplicable issues and caveats and such. Even just the limitations and the UX issues are so obvious that it sends a message that if they tried to fix them they would introduce just as many new issues. I'm at the point where despite the car being go…

yep... there was a tv ad for subaru vehicles a couple of years ago (not that long!), and during the ad, they showed the infotainment system, where the user pans the map on the navigation touchscreen, and the map moves at maybe 1fps! in an ad! I kinda wish they standardized the car interface for tablets (like android auto, but more features), where you could just buy a tablet and insert it in (like din slots for radio…

Look into "iDatalink" aftermarket radios

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#273
post #262
post #4

Hah, them being able to bypass the 2FA by commenting-out the line: $('#securityQuestionModal').modal('show'); is... mind-boggingly stupid of whoever got the job to write that Starlink web-app. OTOH, the hacker hijacked a Starlink employee's account to get in, isn't that over the line in terms of "ethical hacking"/legality standpoint?

I used my chrome inspector to edit a read only field in Jira. Surprisingly I was able to edit it and submit the change. It complete fucked up whatever protect we were about to use and we had to start over. The JIRA admins were scratching their heads.

Thats by design, you can’t trust the client, everything has to be checked server side.

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#275

Last year, I submitted a "right to know" request to Subaru, and they sent the following back. I've reformatted it for legibility. Basically asserts they'll do and sell whatever they want (except another car to me). > Subaru may collect the following personal information about a consumer: > Categories of personal information: > Identifiers: Consumer records, Commercial information, Internet or Other Electronic Network…

This is pretty well known and true for almost all car manufacturers. A few years ago there was a small upset about this [1]. My Opel (a Stellantis brand) happily shows me a message that it is now sharing my location data and that I can change that by pressing the message now -- while I drive. It never shows the message when the car is not moving. I lavishly spread a blanket of Hanlon's Razor over this.

[1] https://foundation.mozilla.org/en/privacynotincluded/article...

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#276
post #47

Earlier quoted context omitted.

Back when I used to do AppSec, these types of issues were extremely common. Software developers and their managers would argue endlessly about them not being real vulnerabilities, which meant I had to put together a proof of exploitability. And since these were interdepartmental fights, office politics get involved. Just one of the dozen or so reasons why I stopped doing AppSec and went back to development.

That seems like a culture issue rather than an appsec issue?

I left security work for a similar reason. In most companies, Security isn't there to collaboratively build more reliable and dependable products that protect customer privacy, bringing in a useful perspective of how things can go wrong, similar to QA's role. Instead, Security is there to be the internal police, who treat engineers (and other employees) like criminals, and get recognition and rewards for stopping the company from shipping. The way the vast majority of companies treat Security is deeply dysfunctional and soul-killing to anyone who wants to bring a glass-half-full mentality to work. And in an industry where it has become practically an expectation for people to jump ship after ~4 years, that's too much of a career risk to take. (side note: QA has exactly the same problem.)

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#277
post #59

Earlier quoted context omitted.

Just as an aside - a friend had their car nicked in NYC this winter. He was able to tell the cops the car location from some Toyota find my car type thing. The cops said they saw nothing on the street so unless he could come and make the horn beep infront of a garage - and then get a warrant - there was nothing more to do. He now has a new vehicle.

a friend had their car nicked in NYC this winter. He was able to tell the cops the car location from some Toyota find my car type thing. The cops said they saw nothing on the street so unless he could come and make the horn beep infront of a garage - and then get a warrant - there was nothing more to do. Here's the way it's done with Volvos (from the manual): If the vehicle has been stolen or otherwise used without p…

5. Police thank you/volvo and tell you you'll probably never get your car back (because that requires effort on their part).

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#278
post #41

Earlier quoted context omitted.

I love my Subaru as far as reliability, all wheel drive performance in snow and ice, and such. But OMG it's consumer tech was dated when I bough it, and it's just full of inexplicable issues and caveats and such. Even just the limitations and the UX issues are so obvious that it sends a message that if they tried to fix them they would introduce just as many new issues. I'm at the point where despite the car being go…

Subaru infotainment is also very controlling. Want to use the keypad while you’re taking a phone call on the go? No, it won’t let you if the car is moving. You’ll need to use your phone’s UI. Other CarPlay cars don’t do this.

My BMW does the same. I can't use the CarPlay keyboard while moving.

It is especially annoying since the car does not (can not) distinguish between me or the missus pressing the touch screen.

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#279

FYI for Subaru owners, you can opt out and have your data deleted anywhere in the US (not just California): https://www.subaru.com/support/consumer-privacy.html It'll take ~6 months or so, but they will send you a confirmation email.

It would be cool if the researcher could have tested this before reporting

Re: Hacking Subaru: Tracking and controlling cars via the admin panel

#280

Earlier quoted context omitted.

We once hired an Indian programmer who absolutely didn't get along with his boss, who was also Indian. Turns out the boss was a Dalit and the programmer was a Brahmin. And this is how I learned about the Indian Caste system.

I am of Indian descent. Apparently from the penultimate caste. Anyway, I had someone from another team inform me of the inferior caste of one of our clients, and why I shouldn’t take shit from them. That said, going back to New Delhi, at least in the circles I travelled in, it’s incredibly taboo to ask about caste. (Comparable to Americans using the n word.)

I've learned it is normally pretty easy to tell what caste someone is from.

But watching a Brahmin who really believes they are vastly better than Dalits act like as arrogant as the Goa'uld from Stargate SG1 was really something.

Post reply on HN