Bugs allowed hackers to dox John Deere tractor owners
61–70 of 72 posts
Re: Bugs allowed hackers to dox John Deere tractor owners
#62Now every litigious John Deere owner will also have a Case.
The lack of replies shows me how few 'farm oriented' people browse HN...Top notch pun
Re: Bugs allowed hackers to dox John Deere tractor owners
#63Earlier quoted context omitted.
If a John Deere salesman knocked on that screen door 80 years ago and said, "Mr. Farmer I have something that will make your life easier. The only drawback is when it breaks down, you can't buy parts, can't see repair documatation, and only pricy factory workers whom live far away will be able to repair the machine at set rates. The farmer would have slammed the door, and fed his horses.
To be fair, if you made the pitch that way to farmer today they would as well - those points are all iffy. mostly, though, the nature of labor has completely and utterly changed in 80 years and comparing the two is like apples and oranges.
for tractors generally, maybe, but have read many things specifically about john deere being very DRM/anti repair, and a quick google seems to highlight that there are court battles being fought over exactly this right now.
https://www.bloomberg.com/news/features/2020-03-05/farmers-f...
Re: Bugs allowed hackers to dox John Deere tractor owners
#64Is owning John Deere tractors somehow controversial, since they're talking about how owners were "doxed"? Is there a special place on the web where we can laugh at the hall of shame of John Deere tractor owners? Jokes aside, John Deere are pretty good tractors tho. Very common among farmers here in Norway. ^^
I think the author was using "doxxed" to mean "discovered the ability to expose personal identifying information of", rather than "exposed personal identifying information with the intent to shame by publicizing said PIN". I agree that's not a very accurate usage. They're only slightly controversial here in the Midwestern US. Somewhat like Harley Davidson motorcycles, their users are highly brand loyal due more to hi…
Re: Bugs allowed hackers to dox John Deere tractor owners
#65Having worked on a John Deere integration for an agtech company I can't say I'm surprised. The MyJohnDeere API had a lot of idiosyncrasies that smelled like inexperienced or mismanaged development, especially around authentication/authorization. At the time I was working on it they had some extremely arcane authentication process that required round-trip emails, various link clicking and code entering, and all kinds…
We need a new word for these high tech massive farming operations. I come from the Canadian farming sector. Most of the farmers here are individuals, or medium sized family operations. Even the big farms aren't "high tech". There just a lot of guys and a bunch of leased machines. We have essentially 0 "high tech" farms. I wouldn't say "modern farms are very high tech operations", I'd say "high tech industrial players…
Re: Bugs allowed hackers to dox John Deere tractor owners
#66Earlier quoted context omitted.
If a John Deere salesman knocked on that screen door 80 years ago and said, "Mr. Farmer I have something that will make your life easier. The only drawback is when it breaks down, you can't buy parts, can't see repair documatation, and only pricy factory workers whom live far away will be able to repair the machine at set rates. The farmer would have slammed the door, and fed his horses.
To be fair, if you made the pitch that way to farmer today they would as well - those points are all iffy. mostly, though, the nature of labor has completely and utterly changed in 80 years and comparing the two is like apples and oranges.
Re: Bugs allowed hackers to dox John Deere tractor owners
#67Earlier quoted context omitted.
To be fair, if you made the pitch that way to farmer today they would as well - those points are all iffy. mostly, though, the nature of labor has completely and utterly changed in 80 years and comparing the two is like apples and oranges.
And yet... Deere still gets bought. So clearly someone isn't pointing out something they should be.
Re: Bugs allowed hackers to dox John Deere tractor owners
#68Now every litigious John Deere owner will also have a Case.
The lack of replies shows me how few 'farm oriented' people browse HN...Top notch pun
Care to clue in someone whose cultivation experience terminates at a roto-tiller---
Goddamnit. Nevermind. Just clicked. Well played.
Re: Bugs allowed hackers to dox John Deere tractor owners
#69Earlier quoted context omitted.
And yet... Deere still gets bought. So clearly someone isn't pointing out something they should be.
Or the comparison is flawed, farmers aren't dumb and it makes economic sense to buy the Deere?
The picture of a hard-working solo farmer repairing his only tractor out in the barn is becoming a rare thing. When you say "farmer" today, it is unclear if you mean the multi-billion dollar multi-national, the "manager" for this 400-acre parcel, or the lady next to the field operating the drone or mostly-autonomous equipment. Or perhaps you meant the latest breed--that fellow who greases the conveyor belt in the metal building in the middle of town where they do the vertical farming with the fancy lights and watering systems. No tractors or even dirt involved.
Re: Bugs allowed hackers to dox John Deere tractor owners
#70> Sick Codes said he could iterate and brute force all VIN numbers in the database, as they were "sequential," according to him Seems like they didn't think that people would enter someone else's VIN. A few years back I discovered that I could get activation code for a map update in my car simply by entering my VIN and the product number of the DVDs with the map update. They gave me a list to choose from when I enter…
This is pretty common, oftentimes cars with parts restricted to VIN (special editions, etc.) or online manual or software download portals will ask for a VIN. Sometimes this is to verify parts fitment and sometimes it is to attempt to rate-limit parts purchase (i.e. - to keep a dealer from buying 100 sets of "special edition" wheels and reselling them, they need to supply a unique VIN for each). The difference is tha…
There was a lawsuit in Norway a while back were the question essentially was: are you breaking the law if you change the URL? (no, it wasn't). More specifically, a guy logged into Norways DMV and looked up information about his own car and by changing the license plate in the URL he got information about other cars, including their owner. I guess the triggering factor was that he scraped this information into a big database.
In Norway you can freely look up car information based on license plate, but it cost extra (?) to get the name of the owner. So the information wasn't secret in any way.
But that brings us back to the question: where does the line go when scraping the web for information?