Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

2 million Progressive Snapshot customers may be at risk for car hacking
Autoblog ^ | 1/21/2015 | Pete Bigelow

Posted on 01/21/2015 4:41:43 PM PST by nascarnation

It was a mere two months ago that Israeli cyber-security researchers hacked into a device that plugs into the diagnostic port of a car and determined they could remotely control the vehicle from anywhere in the world. At the time, the simulated attack seemed like the automotive version of a canary in a coal mine. If researchers could breach this one device, perhaps other aftermarket products that plug into diagnostic ports were also vulnerable?

In short order, another cyber-security firm now reports finding serious flaws in a device used by more than 2 million motorists.

Researchers at Florida-based Digital Bond Labs say they have uncovered major problems in a device that Progressive Insurance uses to measure the driving habits of participating customers. By reverse-engineering the dongle, they gained access to a network that allows control of critical vehicle functions, like steering, braking and throttle inputs.

"What we found with this device was that it was designed with no security features," Dale Peterson, founder and CEO of Digital Bond Labs, tells Autoblog. "It wasn't even based on basic security coding practices. ... It's a house that has no doors, no windows and no fences, with valuables inside."

Peterson emphasized this was not a case of researchers exploiting a weakness in the dongle's security; it was simply that no security existed.


TOPICS: Business/Economy; Computers/Internet; Conspiracy; Science
KEYWORDS: hacking; insurance; progressive; progressiveinsurance; soros
Navigation: use the links below to view more comments.
first 1-2021-4041-59 next last
Flo knows...but apparently a lot of others can get in on the info too....
1 posted on 01/21/2015 4:41:43 PM PST by nascarnation
[ Post Reply | Private Reply | View Replies]

To: Chode

ping


2 posted on 01/21/2015 4:48:48 PM PST by nascarnation (Impeach, convict, deport)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation
"researchers exploiting a weakness in the dongle's security"

No more yankey-my-wanky. The Dongle needs food.

3 posted on 01/21/2015 4:49:16 PM PST by fieldmarshaldj (Resist We Much)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation
Oh oh say it ain't so, Flo...

Why does that woman get on my nerves...?
4 posted on 01/21/2015 4:53:26 PM PST by BigEdLB (Now there ARE 1,000,000 regrets - but it may be too late.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation

5 posted on 01/21/2015 4:55:35 PM PST by varyouga
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation

I started seeing those ads maybe a year ago with that floosie, Flo.

I couldn’t believe they were thinking anyone would want a device on their vehicle which allowed their insurance company to spy on them.


6 posted on 01/21/2015 4:55:59 PM PST by yarddog (Romans 8:38-39, For I am persuaded.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation
" they gained access to a network that allows control of critical vehicle functions, like steering, braking and throttle inputs. "

Impossible.


7 posted on 01/21/2015 4:57:38 PM PST by UCANSEE2 (Lost my tagline on Flight MH370. Sorry for the inconvenience.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: yarddog

Apparently 2 Million volunteered for a small discount

Most people will willingly go into death camps if they are told a good enough story


8 posted on 01/21/2015 4:59:01 PM PST by varyouga
[ Post Reply | Private Reply | To 6 | View Replies]

To: varyouga

Another “progressive” idea with unintended consequences.


9 posted on 01/21/2015 5:04:33 PM PST by Sasparilla (Si Vis Pacem, Para Bellum)
[ Post Reply | Private Reply | To 8 | View Replies]

To: nascarnation

Car Hacking..according to Flo she says “Nailed It”


10 posted on 01/21/2015 5:06:29 PM PST by Sarah Barracuda
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation

Even before this story broke, there’s no way I will give my insurance company access to this information, no matter how funny Flo is.


11 posted on 01/21/2015 5:06:42 PM PST by colorado tanker
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation

The issue in NOT with the “Dongle”, Progressive’s or otherwise. The problem is that the OBD II port was developed without security features. The need was to download data. Think of it as an automotive USB port.

I run the Android App, “Torque”, to pull data from my car’s ECU onto my phone.

http://torque-bhp.com/ “Measure the performance of your vehicle”


12 posted on 01/21/2015 5:17:03 PM PST by BwanaNdege
[ Post Reply | Private Reply | To 1 | View Replies]

To: BwanaNdege

I have one also (DashCommand) but when the interface box is not plugged in, no big deal.


13 posted on 01/21/2015 5:18:23 PM PST by nascarnation (Impeach, convict, deport)
[ Post Reply | Private Reply | To 12 | View Replies]

To: BwanaNdege

However, I guess that the Progressive dongle does provide 2-way communication with the ODBII port, negating the need for the hacker to physically connect to the car.


14 posted on 01/21/2015 5:20:15 PM PST by BwanaNdege
[ Post Reply | Private Reply | To 12 | View Replies]

To: nascarnation

For openers, no conservative in their right mind would do business with an insurance company owned by a left wing Obama supporter.

Also, when I contemplated changing auto insurance carriers a couple of years ago, I found several other well known insurance carriers quoting rates that were a good bit lower than the Progressive quote, and I have an excellent driving record.

Lastly, I would not care how much of a discount they offered, I would never have one of these “big brother” devices installed in my auto.


15 posted on 01/21/2015 5:21:59 PM PST by CdMGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation

Sue those lefties put of existence!


16 posted on 01/21/2015 5:24:51 PM PST by FreeAtlanta (Liberty or Big Government - you can't have both.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BwanaNdege

Where do you connect your phone? Is the connection a standard USB connection?


17 posted on 01/21/2015 5:30:09 PM PST by gunsequalfreedom (Conservative is not a label of convenience. It is a guide to your actions.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: UCANSEE2
like steering,

How? Braking, throttle, anything else electronic, yes. Maybe using the antilock brake system, or traction control to slow one wheel or the other can affect direction of travel, but outright turning it? Not likely.

18 posted on 01/21/2015 5:41:42 PM PST by IYAS9YAS (Has anyone seen my tagline? It was here yesterday. I seem to have misplaced it.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: IYAS9YAS

A lot of vehicles have electronic boosted power steering these days which interfaces with the computer. That’s how they do the unassisted parallel parking feature.

http://en.wikipedia.org/wiki/Intelligent_Parking_Assist_System


19 posted on 01/21/2015 5:44:15 PM PST by nascarnation (Impeach, convict, deport)
[ Post Reply | Private Reply | To 18 | View Replies]

To: gunsequalfreedom

You plug a module (15 bucks on Amazon) into the vehicle OBD diag connector. It communicates with the phone via wifi.

Search for ELM327 module.


20 posted on 01/21/2015 5:47:27 PM PST by nascarnation (Impeach, convict, deport)
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-59 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson