Insurance Company Dongles Dont Offer Much Assurance Against - TopicsExpress



          

Insurance Company Dongles Dont Offer Much Assurance Against Hacking According to a story at Forbes, Digital Bond Labs hacker Corey Thuen has some news that should make you think twice about saving a few bucks on insurance by adding a company-supplied car-tracking OBD2 dongle: It’s long been theorised that [Progressive Insurances Snapshot and other] such usage-based insurance dongles, which are permeating the market apace, would be a viable attack vector. Thuen says he’s now proven those hypotheses; previous attacks via dongles either didn’t name the OBD2 devices or focused on another kind of technology, namely Zubie, which tracks the performance of vehicles for maintenance and safety purposes. ... He started by extracting the firmware from the dongle, reverse engineering it and determining how to exploit it. It emerged the Snapshot technology, manufactured by Xirgo Technologies, was completely lacking in the security department, Thuen said. “The firmware running on the dongle is minimal and insecure. It does no validation or signing of firmware updates, no secure boot, no cellular authentication, no secure communications or encryption, no data execution prevention or attack mitigation technologies basically it uses no security technologies whatsoever.” Read more of this story at Slashdot. ift.tt/1xIgry7
Posted on: Sun, 18 Jan 2015 23:58:22 +0000

Trending Topics



:30px;"> Ive been challenged by Douwe Reimerink to provide a list of ten

Recently Viewed Topics




© 2015