Hacker News new | ask | show | jobs
by ffgh 1301 days ago
When something like this happens, is the development team to blame? Or maybe even the QA team? Wouldn't it be customary to test for things like this
3 comments

Manufacturers for even allowing that to exist (why the fuck telemetry app made by company making radio channels would have permissions to unlock the car in the first place) and company for woeful errors in security and data protection.
Because that "radio channels" company already have expensive infrastructure in place to transmit to cars in most of North America, and an established relationships with car manufacturers, and thus are already integrated into their supply chain.

iow, it's not a "radio channels" company.

SiriusXM is a company that does a lot more than just "making radio channels." This is an egregious security issue, but SXM offering the service makes sense. They also offer an aviation weather service.
I've worked on software for SXM receivers.

When you look at the physical layer it's just a 1.5 mbit data stream carrying whatever you want, pointed at most of North America. Over time some of that bandwidth was carved out for data services at the expense of audio quality.

most probably, because of CAN bus, which is the system that most of the cars use to connect their systems.

https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7219335/

how CAN bus works: https://payatu.com/blog/kartheek.lade/automotive-security-pa...

i’m aware that on this case there was something even dumber, an unsecured api endpoint, but as far as i know, if you’ve managed to reach the system you can do anything with any other connected device. there should not be a way to be able to do whatever you want just because you have access to the network.

I recall reading that some cars are now using TCP/IP for connecting some of their systems. A _super_ quick search on this topic yields some results speaking to this [0].

[0] - https://www.techrepublic.com/resource-library/whitepapers/tc...

I'd say it depends on how far out you're willing to zoom.

For example, legislators and regulators allowed this kind of laxity to be commercially advantageous.

Voters allowed legislators and regulators to ignore the issue.

To some extent, parents failed to instill in their children the civic virtue of voting wisely.

Etc.

What good is blame?
"We must take security seriously or we got sued out of existence" is good motivator for management.
Just limit lawsuit damage at the source, force arbitration, or collapse any plurality of suits into a slap-on-the-wrist class action!