Jmaxxz - Your Car is My Car - DEF CON 27 Conference

  Рет қаралды 119,634

DEFCONConference

DEFCONConference

4 жыл бұрын

For many of us, our cars are one of the largest purchases we will ever make. In an always connected world it is natural that we would want to have the convenience of being able to remotely monitor our vehicles: to do everything from remind ourselves exactly where exactly we parked, verify we locked our vehicle, or even remote start it so it will be warmed up (or cooled down) when we get in. There are a variety of vendors offering aftermarket alarm systems that provide these conveniences and offer a peace of mind. But how much can we trust the vendors of these systems are protecting access to our cars in the digital domain? In this talk, Jmaxxz will tell the story of what he found when he looked into one such system.
Jmaxxz
Jmaxxz works as a software engineer, but is a hacker by passion. He is best known for his work on the August Smart Lock (DEF CON 24 “Backdooring the Frontdoor”). In recent years IoT devices have been the focus of his work. He participated in the IoT village zero day track at DEF CON 24 and DEF CON 25. After enduring several polar vortexes, he decided it was probably time to investigate an IoT remote car starter.
twitter: @jmaxxz Website: jmaxxz.com

Пікірлер: 223
@gustavhebner2174
@gustavhebner2174 4 жыл бұрын
Seeing hackers struggle with sound gives me a certain level of satisfaction. Not gonna lie
@maxczapski2239
@maxczapski2239 4 жыл бұрын
It's a Defcon all-time classic!
@jakethejeweler3092
@jakethejeweler3092 4 жыл бұрын
😂😂😂 I was hoping they were going ask the crowd
@dashdashdash_
@dashdashdash_ 4 жыл бұрын
@@jakethejeweler3092 My favorite bit is watching programmers squabble over where to go in the sound manager and what to do.
@KTMsteve
@KTMsteve 4 жыл бұрын
Jmaxx walks up with low energy and expects high energy response from crowd lol
@artby2wenty
@artby2wenty 4 жыл бұрын
Deafcon
@check537
@check537 4 жыл бұрын
I love that the origin story for this work is “honey, I got a gift for you!”
@thewolfin
@thewolfin 4 жыл бұрын
Defcon, I've got a talk for you!
@pav431
@pav431 4 жыл бұрын
When will companies learn that "Security through Obscurity" is a broken concept that's been overcome by the widespread of technology availability?
@MaxBrix
@MaxBrix 4 жыл бұрын
instead of locking my house I painted the door the same color as the walls.
@pav431
@pav431 4 жыл бұрын
@@MaxBrix I thought of a similar analogy, only: Why should I lock the backdoor to my house? People should only go in by the front. Its still a door, and people aiming to break into your house will look around it when finding its weaknesses.
@barongerhardt
@barongerhardt 4 жыл бұрын
@@pav431 Given how easy it is to overcome any standard house door lock, or breaking a window, I wouldn't worry too much about locking them.
@Lucy-dk5cz
@Lucy-dk5cz 4 жыл бұрын
More specifically security purely through obscurity is broken. Obscurity as a whole does have a place in increasing the skillset and resources needed to beat the security.
@namAehT
@namAehT 4 жыл бұрын
I think it's a good supplement to GOOD security. If no one knows how it works, then it takes much more effort to even understand what's going on, but you also need actual security to prevent access. Using an EVVA Magnetic lock will prevent people from breaking in because it's obscure, but it's also a good lock.
@MrKapceru
@MrKapceru 4 жыл бұрын
its defcon27 but still no mic to hear questions from audience
@NicholasLittlejohn
@NicholasLittlejohn 4 жыл бұрын
Pros repeat questions
@L1m3r
@L1m3r 4 жыл бұрын
@@NicholasLittlejohn - real pros (so called "l33ts") don't need to repeat questions from the audience because there are some mics in the audience. ;-)
4 жыл бұрын
It's now a tradition! We should never have microphones.
@kitten-inside
@kitten-inside 4 жыл бұрын
That is tomorrow technology, for any given value of "tomorrow".
@nielsvanderveer
@nielsvanderveer 4 жыл бұрын
It is 2019... HOW ON EARTH IS SQL INJECTION STILL A THING??!!
@thewolfin
@thewolfin 4 жыл бұрын
It's current year and humans are still dumb and lazy. Why are you surprised?
@duskpierce7802
@duskpierce7802 4 жыл бұрын
That's like asking why people don't wash their hands after using the restroom, or ignore vaccination...
@mina86
@mina86 4 жыл бұрын
PHP
@andrewwright.
@andrewwright. 4 жыл бұрын
@@duskpierce7802 I use the sink to wash my hands before I touch my "thing" because its clean.... Its everything else that isn't. Never really got why we wouldn't wash before... But then there are some dirty people about.
@jamess1787
@jamess1787 4 жыл бұрын
@@mina86 PHP5, pretty sure PHP7 automatically sanitizes post and get input. In any case, bad humans.
@Pileot
@Pileot 4 жыл бұрын
So my brand new 2019 Kia came with a cell phone remote start built in. The app requires you don't have a rooted phone (easily bypassed). I've always wondered how easy it would be for someone more skilled than myself to snoop on the messages being sent / received and bypass the "security". I DID notice my app had a "mandatory security update" a few weeks ago... perhaps it was to close some of these holes?
@DariustheUAVguy
@DariustheUAVguy 4 жыл бұрын
Cellphone remote start is my fave easier than can bus hijicaking. And it can be patched to run on a rooted device.
@ocoolwow
@ocoolwow 4 жыл бұрын
I would not hold my breath on the loopholes getting closed, sure it might have fixed some but really there is no way to tell what the update might have done.
@greekguytalks
@greekguytalks 4 жыл бұрын
keep the car on low fuel always so it won't be targeted
@ocoolwow
@ocoolwow 4 жыл бұрын
@@greekguytalks so what you have to get gas everyday or risk running out yourself not to mention the strain on the fuel pump? No thanks that is a terrible tradeoff.
@TNFSDK
@TNFSDK 4 жыл бұрын
m2m suite seems like the kind of service that caters to car monitoring companies, where a track of where the car is and has been might be wanted and requested by the customers. They should however have changed a part of their service or changed the retention time for the GPS logs so that they expired after 1 day or x hours rather than keeping a full comprehensive log.
@lourensjoubert8652
@lourensjoubert8652 4 жыл бұрын
Biggest applause came when they got the sound to work
@aziztcf
@aziztcf 4 жыл бұрын
Did not expect to see SQL injection in 2019. Especially in this context.
@barongerhardt
@barongerhardt 4 жыл бұрын
Last I checked, SQL injection is still the most common security vulnerability.
@duskpierce7802
@duskpierce7802 4 жыл бұрын
Remember, a majority of the internet still runs on unsanitized inputs.
@ErebuBat
@ErebuBat 4 жыл бұрын
Ah yes. I recall a quote about this from little Bobby Tables
@FennecTECH
@FennecTECH 4 жыл бұрын
it would have been REAAALLLLLY hard not to start all the cars.
@resetcoder
@resetcoder 4 жыл бұрын
Oil companies would make you a hero if you did. Others wouldn't.
@thewolfin
@thewolfin 4 жыл бұрын
Alarm is a bit safer, and should raise some alarms at MyCar and get a few engineers fired.
@MaxBrix
@MaxBrix 4 жыл бұрын
When you can hack a computer to do anything you want and you can't unmute it.
@Zanoab
@Zanoab 4 жыл бұрын
It was obviously a hardware problem. \s
@thewolfin
@thewolfin 4 жыл бұрын
Mac user blames Windows
@Null--
@Null-- 4 жыл бұрын
Even brilliant people will get nervous before a huge crowd of people staring at them.
@press_button_for_assistance
@press_button_for_assistance 4 жыл бұрын
6 months later: GF: “Honey, can I have my car back, please?”
@mstuart076267
@mstuart076267 4 жыл бұрын
Ladies. Get you a man with this level of dedication
@thatgeezeruk
@thatgeezeruk 4 жыл бұрын
What a great presentation @ 11:34 should be very comforting for every non-tech "Oh My God" love it :)
@Samouraii
@Samouraii 4 жыл бұрын
Red shirt guy has done well for himself since Blizzcon
@gptandi
@gptandi 4 жыл бұрын
15:40 for when they get the sound to work
@lawrenceredmacher4382
@lawrenceredmacher4382 4 жыл бұрын
why is it every time I watch a video from one of these elite computer hacker conferences, they never have their computer stuff working right XD
@dco5055
@dco5055 4 жыл бұрын
Cause everything is disabled by default. When you go inside you pretty much want to be in airplane mode or you will get hacked. They probably have stuff disabled on the A/V till it's time to play. There is thousand people there wanting to hack that screen or thinking what it would be like
@fpnbrian
@fpnbrian 4 жыл бұрын
because nearly everyone attending defcon shows up with recently wiped / clean install software on old used hardware that they will never use again and most throw away after attending, and thus not much testing of the laptops & software on them. People hacking into fellow attendees computers and devices happens too often for anyone smart to show up with their real personal computer and devices with them.
@shect1
@shect1 4 жыл бұрын
Why is it that companies that boast on social media about their security always have the worst security practices?
@JohnDoe-nq4du
@JohnDoe-nq4du 4 жыл бұрын
Why is it that people who have arms always also have legs? When nearly everyone does A, and nearly everyone does B, yea, you're gonna have a high correlation between A and B.
@allooutrick8266
@allooutrick8266 4 жыл бұрын
I've learned to just be wary of any advertisement. Sometimes a company gets it right but, a lot of times, it's the company humbly standing by and letting their product speak for itself that has it right.
@rubberonasphalt
@rubberonasphalt 2 жыл бұрын
lol, why doesn't Defcon ever have an AV tech, to make things run a bit smoother?
@nirfz
@nirfz 4 жыл бұрын
Interesting that in the US people like to start their cars by remote. In most countries in europe, having your engine running while not in the car just to warm up the car, defrost the windows ect. is illegal, or at least costs you a fine. If you want to have a warm car you install auxilliary heating (or buy the car already outfitted with that) Those systems have remote controls or a sim card slot so you can call it or send a text message to start it. Also this uses way less fuel than the engine ideling, and it heats the engine too, so less cold starts. This means longer engine life. Then again, if your car isn't heating well when started it is either a very old Diesel car, or something is broken and should be fixed. (proper modern Diesel cars for example have additional heating which makes warm air come out of the vets in 1 minute or less after start. And with modern i mean the last 10 years.)
@kusucks991
@kusucks991 4 жыл бұрын
It's illegal in some (most?) places in the US too but I think it hinges on the car being locked/unlocked. I've heard of people getting tickets for leaving their cars running in the driveway unattended, but I was told it was to discourage that behavior so someone doesn't hop in the car and steal it (yes, has happened, I'm sure) resulting in more police resources being used on more car thefts. So a remote start with the doors locked would bypass that problem.
@nirfz
@nirfz 4 жыл бұрын
@@kusucks991 Here in europe it is mostly illegal for enviremental reasons (and a little bit theft prevention). In my country you aren't even allowed to have the engine running while you scrape the ice off the windshield. And if you have your keys in the open car and somebody steals the car no matter if the engine was running or not, you will get fined for "inviting" the thief. (this is my translation of the legal wording).
@kusucks991
@kusucks991 4 жыл бұрын
@@nirfz yeah so it sounds like we're on the same page for the second half but I haven't heard of any concerns regarding the first half in the US, legally speaking Can't have the engine running while you're scraping ice? That's just oppressive. I can't imagine trying to do that; there's external heat vents that blow on the outside of your windshield called defrosters that are partially designed for that...
@tobyvision
@tobyvision 4 жыл бұрын
@@nirfz It's a good intention, but it's such a microscopic contribution to emissions that it infuriates me someone decided to make a law about it. Meanwhile stopping one logging operation on carbon entrapping clay soil would be about a billion times more effective. But yeah, let's nickle and dime guilt trip the average guy.
@tobyvision
@tobyvision 4 жыл бұрын
@@wudntulike2no32 It definitely irks me when I see someone idling a car for a long time for no reason. But in reality, the amount of fuel used and emissions produced is pretty trivial compared to accelerating from four or five stoplights.
@mayvalauvryar1590
@mayvalauvryar1590 4 жыл бұрын
I love your opinion about puzzles.
@nickroberts8011
@nickroberts8011 4 жыл бұрын
Sounds like his wife's car needed a new thermostat, not a remote starter... unless he lives 5 minutes or less from the airport I guess
@gorak9000
@gorak9000 4 жыл бұрын
Yeah!
@bradcloud7670
@bradcloud7670 4 жыл бұрын
Good job being an asshole. He literally said she has a medical condition that reduces blood flow into her hands...
@neroxen_
@neroxen_ 4 жыл бұрын
@@bradcloud7670 I don't think you understood what was said in the comment.
@exoc1
@exoc1 4 жыл бұрын
It sounded like a diesel when it started. I had a Diesel Impreza years ago, they take ages to heat up in the winter. What Subaru did to get the heater working faster was to implement heating wires in the vents, just like a hairdryer. My guess it's that system that have failed, making the car to "never heat up".
@nickroberts8011
@nickroberts8011 4 жыл бұрын
@@exoc1 good catch. I didn't even know Subaru had a diesel engine available but that's a solid theory.
@ryoohk
@ryoohk 4 жыл бұрын
anddddd im not going to install that now.
@PeterKoperdan
@PeterKoperdan 4 жыл бұрын
Young Christopher Hitchens at the start there.
@kusucks991
@kusucks991 4 жыл бұрын
What I didn't understand from this is how all of these attack vectors would be useful to someone standing outside my car or someone who is otherwise trying to compromise me/my car. How would they get the DeviceID of my car's device if they were to use the admin account? Break in, pull the device, and then just use it as a bypass to not having an ignition key but not to bypass having to get through the locked door? (basically to gain the ability they didn't previously have to start the broken-in car without a key) Would one be able to get someone's DeviceID by knowing their email address used for login? So a "friend" who knows your email address could bluff their way in through the API, get your car's DeviceID, unlock it, and start it, perhaps from an open access apartment parking lot?
@NielsNL
@NielsNL 4 жыл бұрын
Have you seen the part about the GPS data? Shouldn't be hard to just scrape all the current positions of ALL the vehicles, and then find nearest vehicle. Nice App-Idea: Locate Nearest vehicle, show route, remote open and start.
@kusucks991
@kusucks991 4 жыл бұрын
@@NielsNL I understand what you mean but from what I saw you had to have the DeviceID for the API call
@XenonG
@XenonG 4 жыл бұрын
Is this your car?... It's my car now.
@fathernojoy2706
@fathernojoy2706 4 жыл бұрын
Classic SNL skit at work here. User "Still no sound"..."yeah its plugged in"....IT Guy: "Oh My God MOVE!!"...still didn't work. LOL.
@ConstantlyDamaged
@ConstantlyDamaged 4 жыл бұрын
Well, that's not good. Though it is great they (eventually) closed the SQLI problems.
@patrickmcginnis7
@patrickmcginnis7 4 жыл бұрын
I would have went straight to the dealership or the remote start company parking lot (assuming most employees prolly got a good deal on one) and set everything off. I have a big hairy hard-on for privacy, and this is a direct example of how your data is being used (and probably sold!) I bought a 2015 Ford Flex and have found so many issues with the onboard computer its ridiculous, even when in warrantee it doesn't cover software updates, they want to charge you $160. Well, if your software is hanging when i exit the vehicle and is leaving power on to certain systems it kills the battery over a period of time that isn't evident (ie. interior lights go off,etc. but the bluetooth box and other power distribution is hot to the touch the next morning when it should be cold). Every year when a new update is released and I don't buy it, inherently stuff starts failing. Maybe I'm paranoid, but they have way to much control over my car. The auto industry is going to hell. There were 3 recalls on my car, everytime i try to set an appt they are mysteriously "out of parts" - but they mfg. new ones everyday. They are crooked AF. They know how far I've traveled and send me snail mail exactly at the recommended oil change mileage regardless of how much time has passed. I have other vehicles. It may be paranoid, but my data and where i go is my business. #ANDREWYANG take your data back!
@MrPhotodoc
@MrPhotodoc 4 жыл бұрын
"Some times things get complicated..cated..cated". Haha.
@lvcsslacker
@lvcsslacker 3 жыл бұрын
sound over HDMI or whatever connection is going into the computer maybe?
@AhmetMurati
@AhmetMurati 4 жыл бұрын
I have been sanitizing the inputs since 2009 they still have SQL Injection and now it is 2019
@nicolali4792
@nicolali4792 4 жыл бұрын
This guy sounds really Canadian he fuzzed over the complete explanation for Renauds syndrome people needing remote car starters in the north. It's so cold for months in a row that you need to (much debate rages here actually) run your engine stationary to warm up your engine before applying load to it also heats up the interior of your car from -15 C or -25 C to like -3 C in 10 minutes idle time more confortable for the human. We would spend 2 minutes putting on outdoor jackets go out start car 10 minutes etc before plan to leave, run back inside only mildly cold take off outdoor stuff, then you're set to leave soon. Now we all use remote starters in the warm and convenience of our living rooms in the time it takes to find it in your bag. This detail of it being so uncomfortably cold inside a canadian car in winter before it has had time to warm up just needed to be mentioned i felt.
@eurithmicsrocks
@eurithmicsrocks 4 жыл бұрын
Just install the remote start somewhere it can only be accessed with a key
@attilakohbor3360
@attilakohbor3360 4 жыл бұрын
That particular video player has to be restarted if it is loosing the sound .
@DannyWilliamH
@DannyWilliamH 4 жыл бұрын
Guy in the very beginning looks like a dork but sounds like Barry White. That's awesome lol
@kde5fan737
@kde5fan737 4 жыл бұрын
Now it's time to look at how many and which cars, without aftermarket accessories, can be remotely disabled or controlled in some way. I'd really like to know if it is possible to kill the ignition in a car or control the steering or gas and I suspect the electric or hybrids will be much more susceptible to this than normal cars. I still think it's a good idea to put a mechanical kill switch in a car, like for the fuel pump, so you can switch this if you are worried about theft and the theif would have to figure out where you hid it. I guess you could also use an electric switch and maybe pair it with an RF or cellular receiver and toggle it remotely and this could be paired with a remote start system as well.
@bradcloud7670
@bradcloud7670 4 жыл бұрын
You can put in a battery switch that can be really hard to locate/too hard to figure out. Crimes are often crimes of opportunity. A guy isnt going to take 2 hours to track down the switch you hid, when he can just find another vehicle without one
@kusucks991
@kusucks991 4 жыл бұрын
@@bradcloud7670 I saw a video from someone using that very thought and proposed just removing the starter fuse when you get out of the car. Simple and not something an "opportunity" thief is gonna screw around trying to troubleshoot. Made sense to me.
@lourensjoubert8652
@lourensjoubert8652 4 жыл бұрын
Loved the fact that a team of hackers couldn’t get the sound to work 😂
@kanescrimes4848
@kanescrimes4848 4 жыл бұрын
I had a dream that a bunch of middle school girls (I dunno why it was all little girls) took remote control over a fleet of Tesla trucks and drove'em all onto a launch site while playing Rick Astley's "Never Gonna Give You Up"...and they were dead serious about whatever they were trying to achieve by doing that. I know they were dead serious because that's how my mind presented it to me. ...that's it...Nothing profound, nothing clever, nothing insightful or witty...just utter nonsense that I'd LOVE to see animated for some reason.
@alockworkorange7296
@alockworkorange7296 3 жыл бұрын
Trick to get ur remote started from further away hold the remote to the bottom of ur chin and ull get an extra 25-50% extra distance
@emrealsancak1334
@emrealsancak1334 4 жыл бұрын
We can hack a car, hell we can hack anything but can't get sound to work :)
@petergerdes1094
@petergerdes1094 10 күн бұрын
How is it that all these devices have worse security than something I'd make in my basement with a raspberry pi?? They do fucking 2 way communication so how hard is it to just do diffie-hellman key exchange and some existing crypto library?
@RobertPendell
@RobertPendell 4 жыл бұрын
11:44 .... Someone had their Android phone on.
@connie_d
@connie_d 4 жыл бұрын
"Yellow/Green (~) IMO" = "Yellow/Green or thereabouts in my opinion"
@interestingspagetti
@interestingspagetti 4 жыл бұрын
I thought this was for hackers???
@befer
@befer 4 жыл бұрын
The funniest part is that form the whole 41 minutes of the video, KZfaq automatically picked the one where the hacker gets the assisance with the sound problem LMAO
@DustinRodriguez1_0
@DustinRodriguez1_0 4 жыл бұрын
There's a fairly simple, and almost inevitable, solution to this sort of thing. As we already have with other areas of engineering, software engineering at least in critical potentially-life-ending-or-saving scenarios, will need to have a real form of credentialing and legislated requirements for companies to hire credentialed engineers, give them the tools and time required to do their job competently and safely, and most importantly, LISTEN to them. Currently, it is literally impossible for a company to face criminal negligence charges if their product involves a computer in some way. No matter how actually negligent their behavior might be, the courts have found (see the Toyota 'unintended acceleration' scandal from a few years ago) that there simply aren't any legal standards that a company can be said to have violated. Right now, even if the companies engineers all say "this product is UNSAFE, and it will KILL people if you release it" but an executive with an MBA and no engineering knowledge whatsoever says 'screw it, we're going to market', that's fine. If they did it in an industry like construction, they would go to prison for criminal negligence. If they do it when there's a computer involved, they flat out can not be punished at all.
@AKsevenFOUR
@AKsevenFOUR 4 жыл бұрын
What a horrible idea. In most countries there are already regulations concerning who can call themselves a professional engineer, and that ensure nothing other than fees are going to be paid to push paper.
@sznt8648
@sznt8648 4 жыл бұрын
I like the idea of companies having to take responsibility for any kind of damages cause by bad software, but that "credentialed engineer" thing sounds horrible.
@DustinRodriguez1_0
@DustinRodriguez1_0 4 жыл бұрын
@@sznt8648 If there was an 'easy' answer where we didn't have to balance pros and cons I imagine we'd have a solution already. Unfortunately we seem doomed to wait until there is a large-scale tragedy and then we will end up with whatever power-hungry politicians serve up to gain approval from their ignorant and emotional base who just want SOMETHING to be done. And then we'll be almost certain to get one of the worst possible outcomes.
@sznt8648
@sznt8648 4 жыл бұрын
@@DustinRodriguez1_0 true
@peteranderson037
@peteranderson037 4 жыл бұрын
@@sznt8648 Every other form of engineering requires some form of credentialing except for software engineering. It was all fun and games 25 years ago when none of this mattered but now these things are crucial parts of vital infrastructure now. We wouldn't tolerate this kind of shoddy workmanship in the design of the brakes or air bags, why would we allow it in the computers that that activate those critical safety systems?
@moth.monster
@moth.monster 4 жыл бұрын
The more I hear about car hacking like this, the more I want to get a truck with an old all-mechanical Cummings diesel engine and say fuck it to all these electrons. Or maybe I'll get a used car where everything is lovely wired communications that can only be hacked from inside the car. That could work too. Maybe I'll get both. A normal car for normal days, truck for when things need to get moved. Or when an EMP happens.
@error.418
@error.418 Жыл бұрын
The carbon monoxide warning seems outdated considering how long catalytic converters have been around...
@Jmaxxz
@Jmaxxz 10 ай бұрын
I still wouldn't recommend starting a car you don't own...
@rudolphriedel541
@rudolphriedel541 4 жыл бұрын
Why start the car when all you want is a pre-heater?
@garagatza
@garagatza 4 жыл бұрын
In very cold areas - but not only - you also want the engine to reach optimal operating temperature, also heating the engine provides with the heat required to heat the car (when you start the air conditioning/climatic control). Indeed a remote car heater would have been probably better for security reasons, but it won't help with the engine being warmed for the road.
@rudolphriedel541
@rudolphriedel541 4 жыл бұрын
@@garagatza Check out this promotional video I just found: kzfaq.info/get/bejne/kKtmd6yVu76sdWg.html Heating the car including the engine is exactly what these things are build for and these have been around for a long time now. So adding a device to remotely start your car for this purpose which has to circumvent the manufacturers security is a pretty stupid idea when all you want is a pre-heated car.
@alockworkorange7296
@alockworkorange7296 3 жыл бұрын
These problems have been know about by mechanics and inatallers for years some systems are alot better some are worse the one he choose is middle of the road. When i checked last fsctory mercedes benz remote are the most secure Viper makes a few differnt systems that are quite good for home install units they use rolling code and has sorftware thst wont allow use to use the key thats bypassing the aystem for more then 15 min and if installed correctly it will lock u out there is ways around but it takes enough time that somebody should notice them fucking with ur car By the way as far as nonody starting a car using SEQUENTIAL injection by wirignthe icm to 12v and shorting the starter off the frame with prybar
@stewartbladensb
@stewartbladensb 4 жыл бұрын
I was more interested in if they got the sound working than what ever he was talking about.
@mikemalo6336
@mikemalo6336 4 жыл бұрын
Am I on LSD or, ......go to 31:00 and pause the video. Look at the screen, take 2 steps back away from the screen and tell me what YOU see. I am looking at a very romantic screne of a boar lying on a bear skin rug-covered floor in front of a roaring fire and an old TV showing static so this image must be from the 80's, i think.
@mikemalo6336
@mikemalo6336 4 жыл бұрын
@Your moms HITACHI Right!??!there is definitely a stout, 4-legged animal with a hunched back, standing on a fluffy white material. The animal is facing to the left and looking at an old school CRT television set. You can see it too, Right on!
@markemarkpsv1
@markemarkpsv1 4 жыл бұрын
Wow, that was embarrassing but also ironic it's called DEFCON. Or, should that be DEAF CON? How many Hakers does in take to get sound? 27 👊😎👍
@JackSalzman
@JackSalzman Жыл бұрын
“Um” counter: 497
@Tinfoilpain
@Tinfoilpain 4 жыл бұрын
But can you Download a car?
@kanescrimes4848
@kanescrimes4848 4 жыл бұрын
Christopher Hitchens had an affair with Rebel Wilson's mom and their son is in this video
@kanescrimes4848
@kanescrimes4848 4 жыл бұрын
How fitting is the name Rebel Hitchens?
@jakenelson1366
@jakenelson1366 4 жыл бұрын
11:44
@JlerchTampa
@JlerchTampa 4 жыл бұрын
36:10 'None of this is the most offensive of all' Wait, it gets worse, How? Oh... wow.. Son of a bitch...
@vampirosonly6282
@vampirosonly6282 3 жыл бұрын
maybe because im a sound guy, but once they started to have sound issues I couldnt watch any further
@ingmarfris8175
@ingmarfris8175 4 жыл бұрын
At first I thought he was gonna get his gf some woolen gloves or something
@therobb5738
@therobb5738 4 жыл бұрын
My car is hackproof and EMP proof. Its carburated. Lol. Never said anyone with a pocket knife or a screwdriver couldn't steal it. If you can get that bitch to fire over before I do, go for it. Ha.
@joeledj
@joeledj 4 жыл бұрын
"My girlfriend" - loses the defcon audience a minute or so into his, um talk.
@eprofessio
@eprofessio 4 жыл бұрын
Dude do not invest that kind of work or cash until you put a ring on that finger.
@Wesrl
@Wesrl 4 жыл бұрын
This then loops around to bounty hunters using the GPS data
@Ssaps
@Ssaps Жыл бұрын
Probably the youtube video that started the mandate for security gateways in vehicles in USA even though it is not even relevant . RIP aftermarket.
@TymexComputing
@TymexComputing 4 жыл бұрын
Hello - i think it is generally illegal or unethical for the environment for sure - when you start your car and leave it on for over a minute without riding - maybe where you live its not in statute though :)
@garagatza
@garagatza 4 жыл бұрын
internal combustion engines run much better at a specific temperature. I would go on,but if you already own a car you should know that.
@gg-gn3re
@gg-gn3re 4 жыл бұрын
You should warm your oil before driving in cold weather. Also you should look stuff up before posting stupid shit. Both of these things you could and should know on your own, the information is there for you.
@LuckySoaringTiger
@LuckySoaringTiger 4 жыл бұрын
Elon musk put on some weight
@tecsmith_info
@tecsmith_info 4 жыл бұрын
LOL! Breaking cars using SQL injection... FFS wow...
@geroffmilan3328
@geroffmilan3328 4 жыл бұрын
I love tech, but... wouldn't s pair of frickin gloves have made more sense? Frankly, screw remote *anything* in a car. At least, until IPS becomes std for the CAN bus. Might be the one place an IPS is actually useful.
@SiliconSentry
@SiliconSentry 4 жыл бұрын
Not sure where you live, but I'm in Wisconsin, last winter we had -50 windchills with a normal temp of -20. Even with REALLY nice gloves, you're gonna get cold. It's just the way it is.
@gameglitcher
@gameglitcher 4 жыл бұрын
I live in the country, and with an older car i just separated the key fob from the key and start the car. Then use the fob to lock it.
@TremereTT
@TremereTT 4 жыл бұрын
Heated stearingwheels and heated motorbike handles exist! Id suggest some of these.
@gg-gn3re
@gg-gn3re 4 жыл бұрын
@@gameglitcher in my older car I just put a relay in there to flip that runs my starter to start the car...
@ThumperDana
@ThumperDana 4 жыл бұрын
Can probably also create a condition that would STOP a running car as well, in traffic, even more dangerous...
@tschaderdstrom2145
@tschaderdstrom2145 4 жыл бұрын
Not once your key is in it.
@Ghost_Rider_786
@Ghost_Rider_786 10 ай бұрын
What a nob ...he did ALLthat so his GF didnt have cold hands ??? Just buy her a PAIR of GLOVES !!!
@andrewwright.
@andrewwright. 4 жыл бұрын
Unplug the can from any vw,BMW, merc and the car will not start. IMO is in the can so...
@reddcube
@reddcube 4 жыл бұрын
Auto start is a dumb feature, but then again I’m perfectly happy sitting in my coat waiting for the car to warm up.
@fondren001
@fondren001 4 жыл бұрын
Can hack a car... Can't make sound play on a video.
@TheChodax
@TheChodax 4 жыл бұрын
Fuck me, talk about solving first world problems.
@blzt3206
@blzt3206 4 жыл бұрын
Don't put reaction gifs in your talk dude please
@HolowatyVlogs
@HolowatyVlogs 4 жыл бұрын
11:00 Conference about security and technology, can’t get a PowerPoint to output Audio. 🤦🏻‍♂️
@teeroy766
@teeroy766 4 жыл бұрын
Ever since I started watching DEFCON recordings, I don't think I have ever seen the presentation audio work correctly. It doesn't help that Murphy's Law always seems to come out during presentations.
@tehLilaQ
@tehLilaQ 4 жыл бұрын
Can someone please tell him it's NOT CALLED "SEQUEL INJECTION". This seriously triggers me
@NicholasLittlejohn
@NicholasLittlejohn 4 жыл бұрын
It's kind of noisy for an electric car.
@RealCadde
@RealCadde 4 жыл бұрын
Teach your girl to do push ups.
@10-AMPM-01
@10-AMPM-01 4 жыл бұрын
Um, is there any, um, reason, um, he can't, um, speak, um, without pausing with an "ummmm" ? Does he think someone else is going to jump in and speak instead?
@Foxbat1155
@Foxbat1155 4 жыл бұрын
Is DEFCON just one huge marketing advertisement plot for the very companies they claim to "hack"?
@paulbenowitz8835
@paulbenowitz8835 4 жыл бұрын
He didn’t hack a car, he hacked HIS car. There is no Nicholas Cage moment here for me. 40 mins I’ll never get back.
@rbh00723
@rbh00723 4 жыл бұрын
Frankly I enjoyed it and it made me wonder if there are any safe remote start systems for my car out there
@paulbenowitz8835
@paulbenowitz8835 4 жыл бұрын
Ryan Hamilton I’ve been installing remote starters on cars for 20 years and I was very interested in this video. I’ve only had one customer broken into AFTER getting an alarm system. And even he admitted he wasn’t sure if the system was turned on. The truth is a little led light flashing on your dash is usually more than enough to warn away thieves. If someone wants YOUR car they’ll steal it with a tow truck. In general most criminals aren’t going to risk an entire night of breaking into cars over one Honda Civic with an after market alarm system.
@renecouture3719
@renecouture3719 4 жыл бұрын
Looks a bit illegal
@spambot7110
@spambot7110 4 жыл бұрын
cool project, don't see any real security implications though. it's not exactly news that if you have access to the can bus and the car's internal wiring, you can bypass its authentication. it's cool though! just, shouldn't this be at like, a maker con and not a hacking convention? or at least not titled "my car is your car" when this doesn't lead to any practical attacks?
@AKsevenFOUR
@AKsevenFOUR 4 жыл бұрын
I think you missed the point. The physical attacks / CAN bus fun was the groundwork. The real issue was any legit install of the phone option, including those done by a major manufacturer was able to be bypassed via the internet with no physical access.
@djneo92nl
@djneo92nl 4 жыл бұрын
Well the can bus hacks are not real security issue's but having an remote app that has a hardcoded Admin password in it, And sql injection so you could in theory make a script to start every car on that platform. or get there locations, unlock and disable te alarm. steal shit from it. or the car it self
@refraggedbean
@refraggedbean 4 жыл бұрын
@@djneo92nl is very much right here, I'd say having the ability to easily unlock any car with this system makes it pretty easy to steal very expensive things, either ones in the car or the car its self
@elstyr
@elstyr 4 жыл бұрын
The older you get, the more you get into thinking: 'Yeah, thanks for that hack, but why couldn't you just keep it to yourself'? What I'm aiming for is that all the nitty-witty-hackers will at some point start a 'normal' living at some point, and by that change focus on what's wrong with e.g. that particular remote they just bought. Its because their focus changed completely once their first born arrived. And then they realise: 'Hmm, well, the 80s weren't so bad', let's try that lifestyle out again: Offline?
@gg-gn3re
@gg-gn3re 4 жыл бұрын
Unlikely, tons of old guys still do it. If you have an active brain with curiosity it doesn't go away. These guys are nice enough to find issues and report them to the source and then open their findings to the public months later. It's a lot better than it falling into the wrong hands because it was kept a secret www.wired.com/story/eternalblue-leaked-nsa-spy-tool-hacked-world/
@elstyr
@elstyr 4 жыл бұрын
@@gg-gn3re I understand your plea, but tell me how does posting these reveals publicly help preventing any hack from 'falling into the wrong hands'? The 'wrong hands' have access to KZfaq too, right? It's just accelerating - dev side / hack side - ever speeding up - ping pong - until devs become obsolete when only machines will be able to coop with the speed of change?
@gg-gn3re
@gg-gn3re 4 жыл бұрын
@@elstyr It's already patched.. and it's to learn from and explore. 20 years ago when I started learning I learned from stuff previous humans did. You've probably learned things from what previous humans did as well.
@Aa12224240
@Aa12224240 4 жыл бұрын
dude i cant watch you are so boring im sleeping
Bill Swearingen - HAKC THE POLICE - DEF CON 27 Conference
41:18
DEFCONConference
Рет қаралды 601 М.
How many pencils can hold me up?
00:40
A4
Рет қаралды 16 МЛН
Hacker Explains One Concept in 5 Levels of Difficulty | WIRED
25:24
Log4J & JNDI Exploit: Why So Bad? - Computerphile
26:31
Computerphile
Рет қаралды 496 М.
DEF CON 31 War Stories - Living Next Door to Russia - Mikko Hypponen
47:46
DEF CON 22 - Dr. Philip Polstra -  Am I Being Spied On?
42:04
DEFCONConference
Рет қаралды 127 М.
Дени против умной колонки😁
0:40
Deni & Mani
Рет қаралды 7 МЛН
IPad Pro fix screen
1:01
Tamar DB (mt)
Рет қаралды 7 МЛН
How Neuralink Works 🧠
0:28
Zack D. Films
Рет қаралды 31 МЛН