Motor Vehicles Increasingly Vulnerable to Remote Exploits
ic3.gov
ic3.gov
Right. This may be the beginning of the end of remote software updates for "security fixes". The backdoor implicit in remote software updates may be a bigger risk than the existing hole. If anybody ever gets (or already has) Microsoft's or Apple's signing key, there's going to be big trouble.
If a system has an options for untrusted I/O (radios, network, unmonitored physical access), I would take the later over the former every time.
Granted not all companies are created equal in how they handle security, but that doesn't change in either scenario. The same team developing a fix are also typically working on the original implementation, so it's unlikely that the system code/design quality would be drastically different.
Then it wouldn't be an issue how 'insecure' the OS is, since a thief would have to be physically near the vehicle to do anything.
But hey, thanks to the obsession with 'smart' devices and the internet of things and all that stuff, everything seems to have an internet connection chucked in for no real reason.
Look up "Xbox turn off trolling" on Youtube.
Or imagine a voice-controlled self-driving car, and a radio commercial loudly saying "Siri, drive me to New York".
https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)#...
They're coming to car/refrigerator/toaster near you.
Not that this is "old news", but I thought Rule #1 was that when something is more complicated (or here, "smarter") there's more opportunity for things to go wrong, or for things to get abused.
I feel like we knew this was going to happen, but kind of shrugged it off as irrational.
Right after cell phones with blue tooth were made public, we added "blue snarfing" into our vocabulary.
I mean, I don't put a sticky-note over my webcam; I'm just not surprised at all that hackers are keeping up with tech.