Showing posts with label Hacker News. Show all posts
Showing posts with label Hacker News. Show all posts
How to Hack a Car: Phreaked Out (Episode 2)
Click here to watch Episode 3 now! http://bit.ly/1mfBwef
In this episode of "Phreaked Out," we met some of the top security researchers at the center of the car hacking world. The goal isn't to make people crash: They highlight security holes in order to highlight flaws in car technology, intended to pressure auto manufacturers to be a few steps ahead of their friendly foes.
Information security researcher Mathew Solnik gave us a first-hand demonstration on how to wirelessly send commands to the car and remotely tell it what to do. With a little over a grand and about a month of work, Solnik found time outside of his full-time job to reverse-engineer a car's computer system to make it ready for a takeover.
From his laptop, he was able to manipulate the car's engine, brakes and security systems by wirelessly tapping into the Controller Area Network, or CAN bus, network. Without getting too deep into the details—both for legal reasons and due to my own training-wheel knowledge of such things—he was able to do so by implementing some off-the-shelf chips, a third party telematic control unit, a GSM-powered wireless transmitter/receiver setup, and a significant amount of know-how he's accrued over the years.
The reason for such additional hardware was to make our older, mid-sized sedan function like a newer—and arguably more vulnerable—stock vehicle, which these days often come with data connections. (We would have loved to tinker with the latest, most connected car on the market, but since we were on a shoestring budget and it's incredibly hard to find a friend who's willing to lend their car for a hacking experiment, our pickings were slim.)
With that said, a car whose network system is connected to a cloud server and accessible by Bluetooth, cell networks, or wi-fi is potentially vulnerable to intrusion.
Unlocking L.A.'s Traffic Grid: Phreaked Out (Episode 1): http://bit.ly/1r03DpC
How to Hack a Car: Phreaked Out (Episode 2): http://bit.ly/1ps2BB7
All The Ways To Hack Your Phone: Phreaked Out (Episode 3): http://bit.ly/1mfBwef
Subscribe to MOTHERBOARD: http://bit.ly/Subscribe-to-MOTHERBOARD
Follow MOTHERBOARD
Facebook: http://www.facebook.com/motherboardtv
Twitter: http://twitter.com/motherboard
In this episode of "Phreaked Out," we met some of the top security researchers at the center of the car hacking world. The goal isn't to make people crash: They highlight security holes in order to highlight flaws in car technology, intended to pressure auto manufacturers to be a few steps ahead of their friendly foes.
Information security researcher Mathew Solnik gave us a first-hand demonstration on how to wirelessly send commands to the car and remotely tell it what to do. With a little over a grand and about a month of work, Solnik found time outside of his full-time job to reverse-engineer a car's computer system to make it ready for a takeover.
From his laptop, he was able to manipulate the car's engine, brakes and security systems by wirelessly tapping into the Controller Area Network, or CAN bus, network. Without getting too deep into the details—both for legal reasons and due to my own training-wheel knowledge of such things—he was able to do so by implementing some off-the-shelf chips, a third party telematic control unit, a GSM-powered wireless transmitter/receiver setup, and a significant amount of know-how he's accrued over the years.
The reason for such additional hardware was to make our older, mid-sized sedan function like a newer—and arguably more vulnerable—stock vehicle, which these days often come with data connections. (We would have loved to tinker with the latest, most connected car on the market, but since we were on a shoestring budget and it's incredibly hard to find a friend who's willing to lend their car for a hacking experiment, our pickings were slim.)
With that said, a car whose network system is connected to a cloud server and accessible by Bluetooth, cell networks, or wi-fi is potentially vulnerable to intrusion.
Unlocking L.A.'s Traffic Grid: Phreaked Out (Episode 1): http://bit.ly/1r03DpC
How to Hack a Car: Phreaked Out (Episode 2): http://bit.ly/1ps2BB7
All The Ways To Hack Your Phone: Phreaked Out (Episode 3): http://bit.ly/1mfBwef
Subscribe to MOTHERBOARD: http://bit.ly/Subscribe-to-MOTHERBOARD
Follow MOTHERBOARD
Facebook: http://www.facebook.com/motherboardtv
Twitter: http://twitter.com/motherboard
Category
License
- Standard YouTube License
Labels:
Hacker News
U.S. Banks May Have Been Hacked By Russia
FBI Examining Whether Russia Is Tied to JPMorgan Hacking
The FBI is investigating a wave of coordinated cyberattacks that have hit JPMorgan Chase and other U.S. firms in the past month.
The FBI is investigating a wave of coordinated cyberattacks that have hit JPMorgan Chase and other U.S. firms in the past month.
Computer hackers have targeted JPMorgan Chase & Co. and at least four other banks in a coordinated attack on U.S. financial institutions in the past month, Bloomberg is reporting.
Justin Sullivan / Getty Images
Two unidentified sources — one a U.S. official and another a person briefed by U.S. law enforcement — discussed the incident with Bloomberg, with one saying that the theft of customer data could be used to drain accounts.
A third person said that employee data had been breached, and that the scale of the theft — which involved many gigabytes of data — meant there was potential for serious fraud.
Bloomberg’s report says the FBI is in the process of investigating whether Russian hackers were involved in attacks on JPMorgan and at least one other bank.
FBI Said to Examine Whether Russia Tied to JPMorgan Hacking http://t.co/JOOKy5zVPv via @BloombergNews
The attack may have been in retaliation for sanctions placed on the country for its involvement in the ongoing conflict in eastern Ukraine.
In a statement, JPMorgan spokesperson Trish Wexler said: “Banks of our size unfortunately experience cyberattacks nearly every day. We have multiple layers of defense to counteract any threats and constantly monitor fraud levels.”
According to the Guardian, Wexler did not confirm the reports.
“We are working with the United States Secret Service to determine the scope of recently reported cyber attacks against several American financial institutions,” FBI spokesman Joshua Campbell said in a statement.
JPMorgan is America’s largest bank in terms of assets.
The Wall Street Journal said the hacking incidents marked a “significant breach of corporate computer security.”
UPDATE
This piece has been updated with the statement from Joshua Campbell.
Labels:
Hacker News,
News
Anonymous' New Walkie Talkies Use Radio Waves to Access the Internet
Image: Lulz Labs/Vimeo
The hacktivist group Anonymous is working on a new communication tool to circumvent censorship and set information free, and it’s going low-tech this time. The project is called Airchat, and it will use radio waves instead of wifi, broadband, or phone lines to communicate data and messages between computers. It’s basically pirate radio for ones and zeros.
The idea for Airchat was hatched because of the “lessons learned in the Egyptian, Libyan and Syrian revolutions, but also from the experience of Occupy Wall Street and Plaza del Sol,” explains the project description on Github, posted under “Lulz Labs,” which was spotted by International Business Times. With social upheaval in Ukraine and Venezuela and other places around the world, a safe anonymous way for dissidents to organize movements and share information is as relevant as ever.
The radio communication works much like a walkie-talkie or CB radio, with the transmitter acting as a sender and receiver—only you’re sending computer commands instead of audio.
This kind of radio data transfer has been done before. The concept has existed since ALOHAnet was introduced in 1971, a University of Hawaii project that sent data over radio. In 2010, a startup called OneBeep created software that transferred data over radio waves by converting it into an audio signal and then back to the original information packets for the computer to translate.
The team also experimented with laser light-based transmissions, a more complicated method of transmitting data through the pulse of a laser beam, but decided to put a pin in that for now.
Beyond political dissidence, the group writes that Airchat could be used for disaster relief, by support groups or medical teams, or by sailors to communicate weather conditions out at sea. Basically, it could be used any time you need information and traditional communication methods are down.
The end goal is to make this all available for free—“free as in 'free beer' and free as in 'Jeremy Hammond must be freed,” the group writes—without the control of megacorporations or heavy-handed governments.
"Even after all these years of technological advance, we still need to meet in common public places to continue expressing ourselves in a free way," they write.
We’ve seen apps like Zello play a major role for rebel groups in Venezuela and Ukraine, becoming the go-to walkie talkie app that gave protesters the ability to communicate in private voice messages on the go. The problem with Zello, as was witnessed in Venezuela, is that it can only run using wifi or a data plan. With Airchat, which will use both encrypted and non-encrypted radio waves, that shouldn’t be an issue.
In its current incarnation, the project uses Fldigi software to communicate data—it’s the software commonly used to broadcast amateur radio stations from a computer. The machine’s sound card controls most of the communication of information to and from the transmitter using audio-frequency signals. It typically works on Linux, OSX, and Windows.
The radio transmitter is operated by keyboard commands, and Airchat can be programmed to let you send messages, access Twitter streams, download, news, or find community related articles, the group writes. For extra security, the program will is capable of using anonymous Tor servers and proxy support.
So far, they’ve had trouble transferring images via Google's WebP format, due to lack of browser support, but they’re still working out the kinks.
As it currently exists, as you can see in the Vimeo video posted this week, the program is still quite technical for everyday folk. At this point Airchat is still a proof of concept, and the group is releasing early information about it to try to rally community support and funding.
But it’s already been used by Anonymous to play chess with people 180 miles away, share images and communicate “encrypted low bandwidth digital voice chats.” They have also accomplished 3D printing at distances over 80 miles and have been able to send medical orders at distances over 100 miles.
It works, but it doesn’t operate at high-speeds, and the clarity of the connection depends on the strength of your radio signal. As the group writes, it “sacrificed bandwidth for freedom.”
TOPICS: free the network, hacking, Anonymous, censorship, radio, airchat, power
Labels:
Communications,
Hacker News
Energy Firms' Cybersecurity Is So Bad They Can't Get Insurance
Malevolent hackers looking to cause havoc couldn’t find a much better target than the energy grid. In our electrified world, power is pretty vital in delivering even the most essential services, and is the backbone of other indispensable sectors to boot. But when it comes to cyberattacks, confidence in energy companies’ abilities to protect their critical systems appears to be lacking.
In a report today, the BBC revealed that UK energy firms are being denied insurance against cyberattacks because their defences are too weak. They spoke to underwriters at Kiln Syndicate, which offers cover via Lloyd's of London.
When companies apply for cover, the insurance firm assesses what measures they have in place to safeguard against attacks—and they said that in the majority of cases, they’ve turned down applicants for not doing enough. As underwriter Laila Khudari told the BBC, “We would not want insurance to be a substitute for security.”
While that’s likely partly to cover the insurers’ backs—they don’t want to be faced with huge payouts if huge damages were actually to occur—it’s also in the public interest. Insurance companies can help systems recover financially after a breach, but it’s not in their remit to prevent attacks happening in the first place. And I know which I’d prefer.
Part of the reason this news is coming out now is probably because more energy companies are actually realising the full danger of cyberattacks and so are seeking insurance in this area for the first time. In some ways, it’s a good thing that they’ve finally recognised the threat. Then again, it’s perhaps more worrying that they didn’t think to insure against such attacks before. Or build adequate defences against them.
While the threat of cyberattacks on the power industry across the world isn’t new, it’s certainly grown over the past few years, and with the increasing pressure the companies involved are no doubt keen to safeguard against “what if?” scenarios.
In a 2013 report, US congressman Edward Markey warned that “the electric grid is the target of numerous and daily cyber-attacks.” President Obama said in a statement this month on the subject of critical infrastructure that “cyber threats pose one the gravest national security dangers that the United States faces.”
In the UK, security expert Chris McIntosh said last year that Britain’s energy infrastructure was at risk of shutdown from cyber attacks, especially after an invitation for Chinese companies to run UK nuclear reactors. “We need to have new regulations that dictate that energy companies introduce security systems that protect operational networks from attack,” he said.
Just this month, we reported on the complex Careto malware, a very sophisticated virus that has apparently been propagating since 2007 and that targets major power brokers—including companies in the energy sector. Cyberattacks on energy firms are a very real threat, and it looks like they might have woken up to that.
Khudari also suggested to the BBC that changes to the energy companies' systems might have made them more vulnerable. “I think what's behind [the increase in applications for insurance] is the increase in threats and the fact that a lot of these systems were never previously connected to the outside world,” she said. While companies might have previously sought insurance for digital crimes like stolen customer information, they’re now seeking huge policies for if their actual computers and power networks are damaged.
Let’s just hope the firms are rushing to improve cyber defences with as much haste as they’re running to insurers.
TOPICS: cyberattacks, power grid, energy, power, hacking, cyber defencescybersecurity,, security
Labels:
Hacker News
Why California Is Organized Cybercrime's Favorite Target
"Cyber gangs" most likely conjure up images of black hat hackers trafficking guns and drugs on the deep web, laundering money through cryptocurrencies, or fraudsters stealing your credit card numbers to sell on the black market. This is all true. But there's another realm of cybercrime beyond contraband that has law enforcement wriging its hands: Organize cyber gangs targeting lucrative commercial industries, like the energy sector, oil, finance, and especially, a new report suggests, Silicon Valley and Hollywood.
This afternoon, California Attorney General Kamala Harris presented a detailed report on the growing cybercrime problem in the state, and the stats are pretty grim. California is the top US target for foreign-based cyber gangs, pretty much acrosss the board. It led the country in the number of computer systems hacked or infected by malware, the number of victims of internet crimes, and the amount of money lost to identity fraud. The report called the state a "new frontier" for organized cybercrime.
So who are these digital criminals? It runs the gamut from your stereotypical computer whiz with a low moral bar, to politically charged hacktivist groups or state-sponsored cyber militias exploiting the fact that huge swaths of global commerce have moved online and this digital infrastructure be breached.
The number of breaches jumped 280 percent in the US and 27 percent in California.
The report, Gangs Beyond Borders: California and the Fight Against Transnational Organized Crime found that computer network breaches in the Golden State are on the rise, "and many originate from organizations based in China, Russia, Romania, and Nigeria, among other countries." The study covered a broad range of transnational organized crime, one part of which included high-tech crimes like online piracy, hacking, and fraud.
What makes California an attractive target is, in a nutshell, money. Criminals will go where the cash is flowing, and California's in the midst of a 21st Century Gold Rush. The state's GDP is about $2 trillion, which makes it the eighth-largest economy in the world, bigger than the whole of Canada and nearly twice the size of New York or Texas. And it's not just the VC-rich tech industry catching cybercriminals' eyes; the monied celebrities populating star-studded Los Angeles also leaves the state vulnerable to identity and intellectual property theft, and Hollywood is a hotbed for online piracy.
Naturally, the attorney general is using the unnerving findings from the research she led to ask for more state money for the Department of Justice, which she heads up. So it's worth taking the statistics, as always, with a grain of salt. But it's no secret that cybercrime is a serious and growing threat to the US, on both the military and economic front—and one the country is still remarkably unprepared to deal with.
California, for its part, seems to be making an effort. In 2011 the state Justice Department launched a new "eCrime" unit to "investigate and presecute technology crime," specifically to prevent identity theft and fraud and protect Californians' right to privacy.
Now Harris wants to expand the unit to crack down harder.
“State and local law enforcement officers are on the front lines of this fight every day," she said in today's news release. "Our response must include sustained funding for their work and strong coordination at all levels of government.”
TOPICS: Cyberwar, cyberattacks, California, hacking, power
Labels:
Hacker News
Hacking a Car Shouldn't Be as Easy as Hacking a Computer
As you've no doubt picked up on by now, the future car is, for better or worse, a computer with wheels. You log in to your car with a password to control the digitized features. The car comes with built-in internet and downloadable apps. Toyota's new electric concept is named the "iRoad." As Motherboard's Derek Mead reported from CES this year, the trend is crystal clear: "Every car is going to get smarter and more connected, and no car will be worth its salt unless it's got an app."
There's a lot of cool shit you can do with a smart car. The problem with having an automobile that works just like a computer is it can be hacked just like a computer—in other words, far too easily.
At the Black Hat Asia security conference in Singapore over the weekend, security consultant Nitesh Dhanjani demonstrated just how easily it is to break into and control a vehicle, specifically a Tesla Model S.
Dhanjani focused his research on the all-electric car because it's leading the trend of computerized vehicles. The Model S comes with 3G data and wireless internet, its API is open to third-party developers who are starting to build apps for the car, and the car is remote-controllable via the Tesla iPhone app (screenshot below).
That app is accessed with a six-digit password that Tesla owners set up when they first buy the car. Dhanjani's report spells out how insecure this is, especially since the system doesn't lock you out after numerous incorrect attempts.
It'd take a hell of a long time to try to brute-force the password, but without a lockout, it's not impossible. If that didn't work, a phishing scheme could potentially be successful, Dhanjani explained. Or perhaps a bit of social engineering aimed at Tesla customer service employees or the owner could work. In any case, Dhanjani's point is that if a car has a password, that password can be swiped.
Once in, the attacker would be able to see the car's location, unlock it, and start messing around with the various connected features—relatively innocuous stuff like like draining the battery, honking the horn, or opening and closing the sunroof. But the virtual intruder could also steal valuable data about the owner and track their whereabouts.
“It’s a big issue where a $100,000 car should be relying on a six-character static password,” Dhanjani wrote.
They wouldn't be able to start the car and take off with it, or pull off the terrifying scenario of hacking the car while it's moving; for that to happen, the owner's electronic fob key would need to be present.
Tesla didn't comment on the specific report but said in a statement to Reuters, "We protect our products and systems against vulnerabilities with our dedicated team of top-notch information security professionals, and we continue to work with the community of security researchers and actively encourage them to communicate with us through our responsible reporting process."
It's not just Tesla. A spate of internet-enabled automobiles from General Motors are coming off the line this summer, which will make the connected car more mainstream. Right now some 23 million cars on the road globally are connected to the internet in some capacity, according to research firm IHS Automotive, and that’s expected to jump to 152 million by 2020, Time reported.
Researchers have exposed serious security flaws in a variety of vehicles in the past, and as cars get more connected and more automated, the opportunities for an attack grow, and so does the concern—last December, a Massachusetts senator asked automakers to explain how they'll protect against car hacks.
It's no secret that the burgeoning Internet of Things is a potential security nightmare. But as much as no one wants their computer, phone, or smart home broken into, a car takes the risk to the next level. This is the point Dhanjani was trying to make.
"Owners of Tesla as well as other cars are increasingly relying on information security to protect the physical safety of their loved ones and their belongings," he wrote. "Given the serious nature of this topic, we know we can’t attempt to secure our vehicles the way we have attempted to secure our workstations at home in the past by relying on static passwords and trusted networks. The implications to physical security and privacy in this context have raised stakes to the next level."
TOPICS: transportation, hacking, cars, smart cars, internet of things, security,cybersecurity, machines
Labels:
Hacker News
Subscribe to:
Posts (Atom)
Comments / Your Posts
Related Channels
Faith Networks
- Faith Networks Main Page
- The Discipleship Series
- FN-TV
- Christian Views
- Christian Faith Blog
- Faith Networks Missions
- BWP-MediaOne Productions
- Causes & Community
- Advocates For Abstinence
- Disaster Relief & World Missions
- Faith Based Ministries
- Historical & Theology
- Theories, Truths & Endtimes Study
- Healthy Living - Good Intentions
- Causes.com
- Public Info
- Blog
- Media
BWP ENT
- The Arts
- Fashion & Performing Arts
- Poetry & Quotes
- Music Weekly
- Project_7
- Healthy Living - Good Intentions
- Green News
- Causes & Community
- Disaster Relief & World Missions
- Military Digest
- Entertainment Weekly | Media Corner
- Travel & Adventure
- Tech Blog
- Amazing Transportation
- Biz Blogger
- BWP-MediaOne Productions
- Internet Source Media
- Network Promotions
- Timeline of Events | World History
Live Feed
Popular Posts
-
3D printing has seemingly jumped from science fiction into reality. With a little design knowledge or access to a CAD designer, anyone can n...
-
PC case mods come in all shapes and sizes, but they typically return to metal casings as their choice of material. However in this instan...
-
Having seen a number of case mod competitions over the years as well as all of the ones I have posted that I have just stumbled across, I a...
-
Some of the Custom Gaming PC and Case Mods created by Mnpctech "Shiny" Firefly Tribute PC for Corsair by Mnpctech ...
-
Here is the video link on YouTube as well.... YouTube - Acrylic casing UV mod... Last edited by s@meEr; 23-08-09 at 11:12 PM .
-
When you had bought your PC gaming first, you may have liked its looks. But after having seen it in the same design for more than a year i...
-
These guys are literally geniuses. I’ve seen so many case mods but these are the ones I find most creative. Case modding is an art and it...
-
Are you looking for my other, previous, insane multi-monitor home office setups? Version 6.0 , Version 5.0 , Before 5.0 , The FAQ , and ...
-
You have spent a lot of time on the popular video game Battlefield 3 ? Maybe you also like to take some time to create an awesome Battle...








