Hello There, Guest! (LoginRegister)

Post Reply 
REPORT: Progressive Insurance Driving Tracker Lacks Basic Security, Allows Attacker "
Author Message
EagleRockCafe Offline
Hall of Famer
*

Posts: 13,221
Joined: Nov 2003
Reputation: 430
I Root For: Eagles
Location:
Post: #1
REPORT: Progressive Insurance Driving Tracker Lacks Basic Security, Allows Attacker "
[Image: 2ch15k9.jpg]

I think I would pass on using this tracking device....

Quote: Corey Thuen, a senior researcher with Digital Bond Labs, reverse engineered Progressive Insurance’s SnapShot device — used in 2 million US vehicles — and tested it on his 2013 Toyota Tundra truck. After picking apart the hardware and testing its wireless communications while plugged into the vehicle’s ODP-II diagnostic port on the car’s local network, Thuen found the Progressive dongle doesn’t authenticate to the cellular network or encrypt its traffic. The firmware isn’t signed or validated, and there’s no secure boot function. Also, the device uses the notoriously unsecure FTP protocol.

The device runs on CANbus, the very same network where key vehicle functions — including braking, park assist steering, and ECU — are housed. It sends messages over the CAN to request information from the vehicle’s computer systems, such as revolutions per minute, to calculate the driver’s ultimate insurance policy rate.

“Anything on the bus can talk to anything [else] on the bus,” he says “You could do a cellular man-in-the-middle attack” on the device’s communications to Progressive, because there’s no authentication or encryption. But a MITM would require spoofing a cell tower to capture the traffic, which Thuen did not test.

It would be easy for data to be leaked wirelessly. “What happens if Progressive’s servers are compromised?” he says. “An attacker who controls that dongle has full control of the vehicle.”

http://directorblue.blogspot.com/2015/01...iving.html
01-22-2015 02:02 PM
Find all posts by this user Quote this message in a reply
Advertisement


Post Reply 




User(s) browsing this thread: 1 Guest(s)


Copyright © 2002-2024 Collegiate Sports Nation Bulletin Board System (CSNbbs), All Rights Reserved.
CSNbbs is an independent fan site and is in no way affiliated to the NCAA or any of the schools and conferences it represents.
This site monetizes links. FTC Disclosure.
We allow third-party companies to serve ads and/or collect certain anonymous information when you visit our web site. These companies may use non-personally identifiable information (e.g., click stream information, browser type, time and date, subject of advertisements clicked or scrolled over) during your visits to this and other Web sites in order to provide advertisements about goods and services likely to be of greater interest to you. These companies typically use a cookie or third party web beacon to collect this information. To learn more about this behavioral advertising practice or to opt-out of this type of advertising, you can visit http://www.networkadvertising.org.
Powered By MyBB, © 2002-2024 MyBB Group.