Live data from Hacker News

Farm equipment security at DEF CON 29

kaspersky.com

1–10 of 34 posts

Re: Farm equipment security at DEF CON 29

#3
More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots.

I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excuse for repair hostility under the guise of "security."

Re: Farm equipment security at DEF CON 29

#4
post #2

Goes right along with "Bugs allowed hackers to dox John Deere tractor owners" https://news.ycombinator.com/item?id=26903482

'Goes right along with' as in it's the same work, this submission is just blog author's write up of a presentation of it (or whatever) at Def Con 29.

The researcher's write-up from April: https://sick.codes/leaky-john-deere-apis-serious-food-supply... (submitted thrice but not discussed.)

Re: Farm equipment security at DEF CON 29

#5
post #3

More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…

I believe by gut feeling, that the "heavy farm equipment with tracking and repossession built-in" example directly inflames ancient tensions between farmers and remote management. The psychological trigger of the topic adds power and excitement to both sides of that, and security shenanigans multiply, with publicity.

Re: Farm equipment security at DEF CON 29

#6
post #3

More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…

is an excuse for repair hostility under the guise of "security."

That's what every other company has been trying to do too, not just farm equipment manufacturers. If you look between the lines you'll find that the "security industry" is largely in favour of corporate-authoritarianism. Thankfully, not everyone is stupid, and I suspect farmers are actually more likely to spot the BS.

Re: Farm equipment security at DEF CON 29

#8
post #3

More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…

Not just repair hostility: especially JD sought to wall in their garden a decade or so ago. They went all-in on Canbus/SAE J1939 and used the proprietary word spec to keep out other manufacturers of ag automation. I worked at Trimble Navigation during that time, remember it well. Most manufacturers were still using direct hydraulic controls then. Not JD. Evidently things have just got worse since.

Re: Farm equipment security at DEF CON 29

#9
post #3

More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…

is an excuse for repair hostility under the guise of "security." That's what every other company has been trying to do too, not just farm equipment manufacturers. If you look between the lines you'll find that the "security industry" is largely in favour of corporate-authoritarianism. Thankfully, not everyone is stupid, and I suspect farmers are actually more likely to spot the BS.

> If you look between the lines you'll find that the "security industry" is largely in favour of corporate-authoritarianism.

If you're looking for some unreasonably secure device, obviously you have to bake an apple pie from scratch in order to ensure no steps in your supply line are tampered with. Current system has plenty of problems with which that's being used as a defense though, and the fact that those systems are so closed is what allows zerodium to exist in the first place.

Re: Farm equipment security at DEF CON 29

#10

Link to the actual talk (why didn't op just link to the talk?) maybe, instead of linking to the website of a "security software" company with ties to the FSB? https://www.youtube.com/watch?v=zpouLO-GXLo

Because a written summary is nice for people who want to read and might not be in a place where they can watch a video / listen to a talk?
Post reply on HN