164 karma · joined June 10, 2021
I know the vehicle data recorder, and I've heard that LTE radios have to report occupancy, though I can't find a requirement that cars need an LTE radio.
There's rumors cars will be mandated to support remote deactivation, but the story is unclear: https://www.usatoday.com/story/news/factcheck/2023/01/19/fac...
relevant: https://consumerwatchdog.org/sites/default/files/2019-07/KIL...
https://www.npr.org/2019/11/01/775554343/the-world-is-consta...
https://www.wsj.com/articles/porsche-rolls-out-board-approve...
And they all do, even their EV. I voted with my wallet.
What we have here is a way for an attacker using shady means (email-delivered 0day, parking lot thumbdrive, browser drive-by compromise) to take over a computer and then drop a signed package that will allow for remote control over time that looks completely legitimate. To a network IDS, that access will look like an authorized cloud tunnel, completely normal. To a file scanner, it will look like an vendor-signed binary, the gold standard. To the complete defense-in-depth stack, the entire c2 chain is cloaked in legitimacy. If you get a single detection at all for the initial compromise (not possible with 0day), the entire rest of the kill chain looks like legitimate access and vanishes.
It's a nightmare for defense in depth and hunt teams.
https://www.fox13news.com/news/evidence-showing-drivers-spee...