Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

2 million Progressive Snapshot customers may be at risk for car hacking
Autoblog ^ | 1/21/2015 | Pete Bigelow

Posted on 01/21/2015 4:41:43 PM PST by nascarnation

It was a mere two months ago that Israeli cyber-security researchers hacked into a device that plugs into the diagnostic port of a car and determined they could remotely control the vehicle from anywhere in the world. At the time, the simulated attack seemed like the automotive version of a canary in a coal mine. If researchers could breach this one device, perhaps other aftermarket products that plug into diagnostic ports were also vulnerable?

In short order, another cyber-security firm now reports finding serious flaws in a device used by more than 2 million motorists.

Researchers at Florida-based Digital Bond Labs say they have uncovered major problems in a device that Progressive Insurance uses to measure the driving habits of participating customers. By reverse-engineering the dongle, they gained access to a network that allows control of critical vehicle functions, like steering, braking and throttle inputs.

"What we found with this device was that it was designed with no security features," Dale Peterson, founder and CEO of Digital Bond Labs, tells Autoblog. "It wasn't even based on basic security coding practices. ... It's a house that has no doors, no windows and no fences, with valuables inside."

Peterson emphasized this was not a case of researchers exploiting a weakness in the dongle's security; it was simply that no security existed.


TOPICS: Business/Economy; Computers/Internet; Conspiracy; Science
KEYWORDS: hacking; insurance; progressive; progressiveinsurance; soros
Navigation: use the links below to view more comments.
first previous 1-2021-4041-59 last
To: nascarnation
damn... looks like this was not an accident is all that more possible
41 posted on 01/21/2015 7:52:22 PM PST by Chode (Stand UP and Be Counted, or line up and be numbered - *DTOM* -w- NO Pity for the LAZY - 86-44)
[ Post Reply | Private Reply | To 2 | View Replies]

To: gunsequalfreedom
Where do you connect your phone? Is the connection a standard USB connection?

The phone connects to the OBDII dongle using Bluetooth. The "Torque" program converts my car's ECU data to graphic displays such as Current Speed, Average MPG, Instantaneous MPG, Acceleration, Temperatures, etc.

42 posted on 01/21/2015 8:05:17 PM PST by BwanaNdege
[ Post Reply | Private Reply | To 17 | View Replies]

To: nascarnation; COUNTrecount; Nowhere Man; FightThePower!; C. Edmund Wright; jacob allen; ...
Nut-job Conspiracy Theory Ping!

To get onto The Nut-job Conspiracy Theory Ping List you must threaten to report me to the Mods if I don't add you to the list...


43 posted on 01/21/2015 8:23:58 PM PST by null and void (The aggregate effect of competitive capitalism is indistinguishable from magic)
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void

so glad I don’t use that company


44 posted on 01/21/2015 8:39:37 PM PST by Nifster
[ Post Reply | Private Reply | To 43 | View Replies]

To: nascarnation
"Peterson emphasized this was not a case of researchers exploiting a weakness in the dongle's security; it was simply that no security existed."

How dumb can they be?

45 posted on 01/21/2015 8:55:16 PM PST by MV=PY (The Magic Question: Who's paying for it?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: IYAS9YAS
I learned how to parallel park in a 1978 Buick Landyacht...

Ditto, but with my Daddy's 1965 Plymouth Fury II nine-passenger station wagon with a rear-facing back seat, great for parking backwards at the drive-in. :-)

46 posted on 01/21/2015 9:35:29 PM PST by pigsmith
[ Post Reply | Private Reply | To 21 | View Replies]

To: nascarnation; maggief; LucyT; null and void; Republicanprofessor; KC_Lion

I’m thinking of that guy whose car accelerated and the engine was found outside of the car...

guy was investigating a story unfavorable to certain people.

all y’all, ping to the thread, about technology possibly being able to do in the guy that I mentioned.


47 posted on 01/21/2015 9:43:39 PM PST by WildHighlander57 ((WildHighlander57, returning after lurking since 2001)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BwanaNdege; nascarnation

Thank you!


48 posted on 01/21/2015 11:30:38 PM PST by gunsequalfreedom (Conservative is not a label of convenience. It is a guide to your actions.)
[ Post Reply | Private Reply | To 42 | View Replies]

To: nascarnation
It's a house that has no doors, no windows and no fences, with valuables inside."

Flo's got no clothes!

49 posted on 01/21/2015 11:55:04 PM PST by uglybiker (nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-nuh-BATMAN!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation

Just say “no” to George Soros insurance!


50 posted on 01/21/2015 11:59:12 PM PST by Drago
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascarnation
Martin Gross, program executive officer, Command and Control Capabilities, DISA
51 posted on 01/22/2015 4:19:08 AM PST by bmwcyle (People who do not study history are destine to believe really ignorant statements.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: IYAS9YAS

I was skilled at parallel parking, but I don’t think I’ve had a need to parallel park for 20-30 years. I guess it would be easy, but who knows.


52 posted on 01/22/2015 4:35:32 AM PST by gitmo (If your theology doesn't become your biography, what good is it?)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Disambiguator

I wonder if I’m at risk with my 21 year old SUV.


53 posted on 01/22/2015 4:41:22 AM PST by gitmo (If your theology doesn't become your biography, what good is it?)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Ditto
Seriously, if those companies thought they had a really good product, something better than the competition, they would not resort those gimmick ad campaigns. They would not need to.

I used to hear great things about USAA insurance from those who had it. I don't really remember hearing about them anywhere but by word-of-mouth before a few years ago (now they're advertising pretty heavily).

I looked into it quite a while back, but at that time, for some reason, I didn't qualify for it (I think I'd been out of the service too long, or some such), but they've since opened themselves up to a much greater range of people these days.

When I looked again, they were more expensive than my current insurance, so I didn't go with them, but I've still heard so much good about them, I may have to check into it again, as my insurance company can't even seem to get my bills/payments right.

54 posted on 01/22/2015 6:19:45 AM PST by IYAS9YAS (Has anyone seen my tagline? It was here yesterday. I seem to have misplaced it.)
[ Post Reply | Private Reply | To 36 | View Replies]

To: gitmo

I think you’re ok. This drive by wire business is relatively recent.


55 posted on 01/22/2015 6:24:03 AM PST by Disambiguator
[ Post Reply | Private Reply | To 53 | View Replies]

To: gitmo
I wonder if I’m at risk with my 21 year old SUV.

Probably. If you have the OBDII interface, you're at risk for some sort of hack. Now, the amount of things controlled by your computer is likely to be fewer than today's cars, but you still probably have a computer (my 1989 Mustang had one, and the 1994 Chevy Silverado 1-ton dually did, as well).

So they could affect engine speed/operation/shifting (if automatic). Unless you had ABS, or shift-by-wire 4-wheel-drive, that would likely be unaffected, but I know that GM's 4x4s in the early/mid 1990s had shift levers for their transfer cases in trucks/SUVs, but it's my understanding that they were fully fly-by wire and the shift lever was just there to make you think they were mechanically linked. My old boss had one go out, and he was surprised to learn that (as was I).

56 posted on 01/22/2015 6:27:36 AM PST by IYAS9YAS (Has anyone seen my tagline? It was here yesterday. I seem to have misplaced it.)
[ Post Reply | Private Reply | To 53 | View Replies]

To: WildHighlander57

http://www.freerepublic.com/focus/news/3089959/posts

Who Killed Michael Hastings?


57 posted on 01/22/2015 6:32:38 AM PST by maggief
[ Post Reply | Private Reply | To 47 | View Replies]

To: Ditto

Actually I think the lizzard is an Aussie, not a Brit, LOL


58 posted on 01/22/2015 12:28:27 PM PST by BigEdLB (Now there ARE 1,000,000 regrets - but it may be too late.)
[ Post Reply | Private Reply | To 36 | View Replies]

To: BigEdLB
Actually I think the lizzard is an Aussie, not a Brit, LOL

Probably has venom if he's an Aussie. They got some nasty critters down there. ;~))

59 posted on 01/22/2015 6:55:04 PM PST by Ditto
[ Post Reply | Private Reply | To 58 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-59 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson