Hacking industrial vehicles from the internet
jcarlosnorte.com
jcarlosnorte.com
Even if the door is wide left open, crossing the threshold
is still trespassing, if you don't belong on the property.
This is why burglars are typically charged with breaking AND entering.Unlawful entry is still a crime one can commit, without breaking open, or otherwise circumventing pro-active security measures.
When it comes to the idea of "hacking" we often find our words fail to describe activities with precision.
The nuanced distinction some tend to draw between "hacking" and "cracking" is mostly relegated to specialized jargon, community slang, and pedantry. Laymen often do not distinguish between the two.
Trespassing is an actual crime, but it does not fit your description, at least in California. Here, you must have an intent to interfere with the owner's property for it to be considered trespassing. If I enter your open door because I want to invite you to a party, or use your restroom, or hang out with your cats and play video games until you come home I have not committed any crime. Well maybe you could get me for stealing water and electricity, but the entry is not a crime.
"Breaking and entering" is also not a crime in California. However, if you actually steal something that is burglary, which is a crime, and does not require forced entry.
The real problem is that the end users are more often than not totally unaware that their stuff is exposed to the world until something bad happens.
[1] http://www.reuters.com/article/us-ukraine-cybersecurity-idUS...
It's like buying a bus with broken brakes, and still use it as public transportation. Nothing wrong with buying the bus.
Ultimately this blog post doesn't describe any rocket science at all: anyone wanting to cause trouble on the internet is well aware of Shodanning for exposed ICS systems that fail to even implement authentication.
Anyway, call me old-fashioned, I don't think this is the way it should be done.
FWIW I'm aware of a SCADA system that is widely deployed that is just about as secure as this system here and I'd be the last person on the planet to publish the details of it because I know for a fact that it is used to control HVAC equipment and other building infrastructure in hospitals and prisons. These things are not toys and being aware of them does not actually allow you to play god. (In that particular case as far as I know the systems are so old that fixing them with an update is not even an option).
Yes, you and a cool bunch of Chinese and Russian government-hired hackers, too.
If releasing irresponsibly a vulnerability puts people in real danger, is it worth it to suppress the release of that vulnerability?
http://www.neweagle.net/ProductDocumentation/Telematics/Tele... mentions "Remote Flashing" so I guess they fix that.
I'm going to go with "no". Companies that admit their failings to their customers are probably pretty rare, particularly "companies that will fail to attempt to secure their computer systems but will actively engage their customers when an issue becomes the focus of unwanted attention" must be close to zero in number.
This is not really a bug, this an unfit design.
That's a novel way to abbreviate Internet Protocol address.
More towards the meaning of strange, rare rather than young, modern. Google automatically corrects "I.P. address" to "IP address", so I can't easily say how much more widespread the second spelling is. But I bet is a lot more.