Farm equipment security at DEF CON 29
kaspersky.com
Farm equipment security at DEF CON 29
1–10 of 34 posts
Re: Farm equipment security at DEF CON 29
#2Re: Farm equipment security at DEF CON 29
#3I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excuse for repair hostility under the guise of "security."
Re: Farm equipment security at DEF CON 29
#4Goes right along with "Bugs allowed hackers to dox John Deere tractor owners" https://news.ycombinator.com/item?id=26903482
The researcher's write-up from April: https://sick.codes/leaky-john-deere-apis-serious-food-supply... (submitted thrice but not discussed.)
Re: Farm equipment security at DEF CON 29
#5More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…
Re: Farm equipment security at DEF CON 29
#6More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…
That's what every other company has been trying to do too, not just farm equipment manufacturers. If you look between the lines you'll find that the "security industry" is largely in favour of corporate-authoritarianism. Thankfully, not everyone is stupid, and I suspect farmers are actually more likely to spot the BS.
Re: Farm equipment security at DEF CON 29
#7Re: Farm equipment security at DEF CON 29
#8More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…
Re: Farm equipment security at DEF CON 29
#9More like "farm equipment manufacturers have insecure backoffice web services" with some tenuous and unsubstantiated highly contrived links to fanciful action movie sub-plots. I agree that automotive and farm equipment have generally mediocre security track records and that, with the addition of remote connectivity, these issues are concerning. But all hyperbole and breathless reporting like this gains us is an excus…
is an excuse for repair hostility under the guise of "security." That's what every other company has been trying to do too, not just farm equipment manufacturers. If you look between the lines you'll find that the "security industry" is largely in favour of corporate-authoritarianism. Thankfully, not everyone is stupid, and I suspect farmers are actually more likely to spot the BS.
If you're looking for some unreasonably secure device, obviously you have to bake an apple pie from scratch in order to ensure no steps in your supply line are tampered with. Current system has plenty of problems with which that's being used as a defense though, and the fact that those systems are so closed is what allows zerodium to exist in the first place.
Re: Farm equipment security at DEF CON 29
#10Link to the actual talk (why didn't op just link to the talk?) maybe, instead of linking to the website of a "security software" company with ties to the FSB? https://www.youtube.com/watch?v=zpouLO-GXLo