Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
 
3rd_gear_Ted's Avatar
 
Join Date: Oct 2007
Location: SoCal
Posts: 4,910
Garage
Cybersecurity Thread

A thread for the latest and greatest Cybersecurity threats.

Here's what is new to me. https://flipperzero.one/

What say you about theses devices and their capabilities?

ZL-1 Camaro's are being stolen with these devices all over SoCal.

__________________
1980 911 - Metzger 3.6L
2016 Cayman S
Old 04-01-2024, 07:26 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
Join Date: Jun 1999
Posts: 7,172
Interesting gadget...never knew such a thing existed. Now I want one....
__________________
1957 Speedster, 1965 356SC, 1965 356SC Outlaw, 1972 911T, 1998 993 C2S, 2018 Targa 4 GTS, 2014 Cayenne S, 2016 Boxster Spyder, 2019 Tacoma
Old 04-01-2024, 07:46 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
Join Date: Sep 2009
Location: North of You
Posts: 9,160
They were banned where I live, which raised the price from $200 to $500. I still see them for sale online every day.

From what I've read, Flipper's are NOT the source of the stolen car epidemic, new cars apparently use rolling codes, so capturing someone's code is useless, unless it's a fairly old car.
__________________
"A machine you build yourself is a vote for a different way of life. There are things you have to earn with your hands."
Old 04-01-2024, 07:53 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
MBAtarga's Avatar
 
Join Date: Jul 2001
Location: Lawrenceville GA 30045
Posts: 7,379
At work we had a briefing on the flipper and its capabilities (I'm in an IT security organization.) Really incredible device which in nefarious hands can cause quite a bit of turmoil.
__________________
Mark

'83 SC Targa - since 5/5/2001
'06 911 S Aerokit - from 5/2/2016 to 11/14/2018
'11 911 S w/PDK - from 7/2/2021 to ???
Old 04-01-2024, 07:56 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,994
You can do this with multiple devices, it’s basically a replay attack, fooling the vehicle to think your keys have unlocked it. Just keep your keys in a metal box, and it’s defeated. More modern vehicles have better rolling codes to defeat this. Another attack is the CAN bus attack, getting access to the bus via the headlight connector, you can unlock the doors and start the car in under two minutes with a device you can easily buy.

Cars are becoming easier to steal the more they rely on computers.

I’m sure someone is actively working on compromising OTA updates from major manufacturers as we speak…
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 04-01-2024, 08:13 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
Join Date: Sep 2015
Location: NY
Posts: 6,943
Quote:
Originally Posted by stealthn View Post
I’m sure someone is actively working on compromising OTA updates from major manufacturers as we speak…
They don’t need to. The mfrs are doing a great job of compromising their own ota updates…
Old 04-01-2024, 10:54 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
Bill Douglas's Avatar
 
Join Date: Jun 2000
Location: bottom left corner of the world
Posts: 22,765
It will be a problem for people locking their buildings with electronic keypads. And a handy tool for interfering with wifi transmissions.
Old 04-01-2024, 11:19 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
Join Date: Sep 2009
Location: North of You
Posts: 9,160
Quote:
Originally Posted by stealthn View Post
I’m sure someone is actively working on compromising OTA updates from major manufacturers as we speak…
Do they even care? People continue to buy cars with flawed security, then they complain when the car gets stolen. The consumer buys another car, and the manufacturer sells another car.

Where's the pressure to fix the problem coming from?

Push-button start is the source of a lot of problems, no one seems to be going back to a physical key.
__________________
"A machine you build yourself is a vote for a different way of life. There are things you have to earn with your hands."
Old 04-02-2024, 06:09 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 85,062
Garage
I see that AT&T was hacked again. Only name address and social security numbers put on the dark web.

And so many companies are pushing me to move to "cloud" based data storage. I am 100% certain I have never been hacked. I will keep my data on my local computers, and the banks and credit union I use are hopefully batter at security than AT&T.
__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 04-02-2024, 06:25 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
Join Date: Mar 2003
Location: SW Cheese Country
Posts: 13,558
Garage
Quote:
Originally Posted by 1990C4S View Post
They were banned where I live, which raised the price from $200 to $500. I still see them for sale online every day.

From what I've read, Flipper's are NOT the source of the stolen car epidemic, new cars apparently use rolling codes, so capturing someone's code is useless, unless it's a fairly old car.
Correct, as they come from the manufacturer they cannot unlock and start a modern car. They are good at cloning RFID and with different modules hack wifi and what not. Great at changing the channel at a sports bar or airport!

They are no different than the little Pi kits or anything else, but they do come in a small case with lots of capability from the factory.

My daughter has one.

You can buy different modules for them and root them for different purposes, but as stated, they are not any differnt than the hobbyist Pi kits.

Professinal kits can do a whole lot more and are far more expensive!
__________________
Brent
The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson.

"Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie.
Old 04-03-2024, 09:40 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
....
 
Arizona_928's Avatar
 
Join Date: Feb 2008
Posts: 18,811
Flipper zero is the least of your worries.

AI and voice models have been scamming Asian corporations this last year
__________________
dolor et pavor

Copyright
Old 04-03-2024, 12:56 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Southern Class & Sass
 
Dixie's Avatar
 
Join Date: Feb 2005
Location: Bradenton, FL
Posts: 4,058
Garage
Quote:
Originally Posted by stealthn View Post
Just keep your keys in a metal box, and it’s defeated.
I simply unplugged my On-Star module. Between car thefts, and GM selling everyone's driving data, it seemed prudent.
__________________
Dixie
Bradenton, FL
2013 Camaro ZL1
Old 04-04-2024, 06:45 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
Registered
 
3rd_gear_Ted's Avatar
 
Join Date: Oct 2007
Location: SoCal
Posts: 4,910
Garage
Recent $30M heist in L.A. from a state of the art secret money storage depot smells like the alarm system was compromised.

Reports are saying the Easter morning, area wide internet outage related to the facility location was a deliberate step in the robbery
__________________
1980 911 - Metzger 3.6L
2016 Cayman S

Last edited by 3rd_gear_Ted; 04-06-2024 at 09:22 AM..
Old 04-04-2024, 07:13 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Registered
 
3rd_gear_Ted's Avatar
 
Join Date: Oct 2007
Location: SoCal
Posts: 4,910
Garage
Microsoft developer did some nefarious stuff.

https://finance.yahoo.com/news/1-why-near-miss-cyberattack-151035964.html
__________________
1980 911 - Metzger 3.6L
2016 Cayman S
Old 04-06-2024, 09:20 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 56,126
Quote:
Originally Posted by 3rd_gear_Ted View Post
Microsoft(wrong) developer did some nefarious stuff.

https://finance.yahoo.com/news/1-why-near-miss-cyberattack-151035964.html
FYI, some random developer named "Tan" did nefarious stuff. A Microsoft developer named Freund discovered the issue.

Excerpts from the article...

Quote:
Freund, who works for Microsoft out of San Francisco, discovered that the latest version of the open source software program XZ Utils had been deliberately sabotaged by one of its developers, a move that could have carved out a secret door to millions of servers across the internet.

Security experts say it’s only because Freund spotted the change before the latest version of XZ had been widely deployed that the world was spared a digital security crisis.

“We really dodged a bullet,” said Satnam Narang, a security researcher with Tenable who has been tracking the fallout from the find. “It is one of those moments where we have to wipe our brow and say, ‘We were really lucky with this one.’”

XZ, a suite of file compression tools packaged into distributions of the Linux operating system, was long maintained by a single author, Lasse Collin.

In recent years, he appeared to be under strain.

In a message posted to a public mailing list in June 2022, Collin said he was dealing with "longterm mental health issues" and hinted that he working privately with a new developer named Jia Tan and that “perhaps he will have a bigger role in the future.”

Update logs available through the open source software site Github show that Tan’s role quickly expanded. By 2023 the logs show Tan was merging his code into XZ, a sign that he had won a trusted role in the project.

Tan could easily have gotten away with it had it not been for Freund, the Microsoft developer, whose curiosity was piqued when he noticed the latest version of XZ intermittently using an unexpected amount of processing power on the system he was testing.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 04-06-2024, 10:49 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
Alenbaarz's Avatar
 
Join Date: Nov 2023
Posts: 4
I’m not a cybersecurity expert by any means, but I’m working on getting my PMI-PMP certification, and it’s wild to think how much project management overlaps with this kind of tech, especially with risk management and safeguarding project data. I’ve seen those Pi kits, and yeah, the modules are cool for hobbyists. My cousin’s really into this stuff and she’s built a bunch of things with them. It’s crazy how accessible the tech is these days. The pmp training I’m doing has really made me think about how important it is to stay on top of security risks, especially as things get more advanced. Anyway, great discussion!

Last edited by Alenbaarz; 10-13-2024 at 11:45 PM..
Old 10-10-2024, 12:38 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,994
Right now Insurance policies for companies are really driving cyber security. It’s great but most clients who’ve been slacking/cheap on this over the years are now forced to spend the money to buy a lot of software and services and change policies/processes otherwise they cannot be insured.

To me it’s a step in the right direction to smarten companies up, but I still feel the supply chain attacks (especially with software updates) are the biggest targets/threats.

__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 10-10-2024, 05:11 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Reply

Thread Tools
Rate This Thread
Rate This Thread:

 


All times are GMT -8. The time now is 11:29 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.