DEF CON 30 - Sick Codes - Hacking the Farm = Breaking Badly into Agricultural Devices

  Рет қаралды 95,293

DEFCONConference

DEFCONConference

Жыл бұрын

Hacking the farm. In this session, I'll demonstrate tractor-sized hardware hacking techniques, firmware extraction, duplication, emulation, and cloning. We'll be diving into how the inner workings of agricultural cyber security; how such low-tech devices are now high-tech devices. The "connected farm" is now a reality; a slurry of EOL devices, trade secrets, data transfer, and overall shenanigans in an industry that accounts for roughly one-fifth of the US economic activity. We'll be discussing hacking into tractors, combines, cotton harvesters, sugar cane and more.

Пікірлер: 157
@renakunisaki
@renakunisaki Жыл бұрын
Imagine paying $3500 to be allowed to use a feature of the $8000+ machine you bought.
@ShainAndrews
@ShainAndrews Жыл бұрын
Imagine you knowing anything about agriculture...
@TheCynicalJedi
@TheCynicalJedi Жыл бұрын
@@ShainAndrews What does knowledge of agriculture have to do with a company selling you a product with all the bells and whistles included except you can't use the bells and whistles without paying substantially more money beyond attempting to defend and justify it? - Are the people complaining about BMW's subscription based heated seats irrelevant because they don't understand automotives? Any fan of video games knows exactly what this path looks like and where it ultimately leads. Corporations slowly push forward adding features over time to the base product (lifetime unlocks) garnering all of the priase imaginable, then when they inevitably hit the wall and struggle for new features, they begin pay-gating features previously included in base products slowly enough that nobody complains until they realize they're paying the same or more for a product that has comparably less features unless spending even more money. In video games it's customization/aesthetic/visual things like character clothing, arguably not that important, being taken from the base game and monetized in other ways - But is in essence the same thing happening here, except with tractors and farm equipment it's markedly more useful/important features
@ShainAndrews
@ShainAndrews Жыл бұрын
@@TheCynicalJedi Who are you to jump into somebody else's conversation. Sure like you trying to compare the real world with games. You're not going to make it very far. Really like you trying to make it about software, or feature keys... of which my comment was not about at all.
@TheCynicalJedi
@TheCynicalJedi Жыл бұрын
@@ShainAndrews Lmao. It's an open comment section, not a DM and OP hadn't even replied to you, for what is in hindsight obvious reason. I wasn't comparing the real world to video games, I was comparing two comparable situations ocurring in two different real world industries. "Of which my comment was not about at all." Your comment was about absolutely nothing, other than attempting to belittle someone else based on their knowledge, or lack of, in regards to agriculture, something irrelevant to the point they made. For the record, I didn't specify software or feature keys at all, I said "features" - Those can in fact be physical things too, like heated seats in a car, that in some cases you're forced into paying extra for whether you want it or not, and those that do still need to pay more to use it.
@BraveClam
@BraveClam Жыл бұрын
@@ShainAndrews LMAO, you forgot to tip your fedora...
@einball
@einball Жыл бұрын
For being such hardasses with regards to 'owning the thing' I'm surprised they lack any kind of security at all.
@georgetaylor6146
@georgetaylor6146 Жыл бұрын
@Doug Anderson I think it is more complacency than arrogance to be honest. Unlike Automotive, the standards for agricultural machines are much less stringent. A caveat to less standards and more 'guidelines' is that security measures end up becoming optional rather than mandatory with Automotive. Obviously almost everyone has a car, very little have agricultural machinery - the OEM effectively has less of an incentive to invest in security measures.
@sparklesparklesparkle6318
@sparklesparklesparkle6318 Жыл бұрын
@@douganderson7002 Most people are very well aware with the problems of John Deere and their software. Actually wait nevermind people are dumb I forget only 30% of the US population even knows what the name of our Vice President is and only 60% of Americans can find the United States on a map.
@brendenbaxter3269
@brendenbaxter3269 Жыл бұрын
Farmers have been 'hacking' their own tractors for maybe over a decade now. Farmers have been doing it out of necessity longer than anyone else. We see facilities getting hit, not lone tractors taking to the hills. There is atleast one really good documentary about younger farmers dealing with these restraints put on the equipment. They definitely do care and it seems to really hinder their efforts.
@thinkamajig
@thinkamajig Жыл бұрын
not alot of networked devices on the farm...
Жыл бұрын
@@thinkamajig Wrong.
@ericngay
@ericngay Жыл бұрын
I worry that you are just helping JD just make it even harder to mod their machines. However I’m impressed by your skills and persistence. I like that you open with the problem and then go deep. Great talk! Wish farmers were able to use this to their benefit but honestly I think JD has more resources and will probably just shut it down harder. The average farmer can’t compete with the $/time/hrs/resources that the corporate giant will apply to this type of information just to improve the locks on their $20k subscription model. Small/family owned farms are f’d… and that’s why they use old tech with the forever unlock vs the new subscription model that will bury them in fees. I wish this had ended with a rubber ducky solution for farmers instead of answering JD’s devs questions on how to make their gear more impenetrable…
@SickCodes
@SickCodes Жыл бұрын
Love the feedback, and I totally get where you’re coming from. What you asked for is coming soon 😁 For the talk, I specifically chose to publish this way of doing it as it shows a way that the OEM will never be able to prevent this from happening: the OEM cannot stop me from doing this to my device, in good faith. I know it may seem like I’m making it easy to fix, but it certainly isn’t haha. One example is that for them to prevent this from happening would require full disk encryption and they can’t simply start encrypting devices as the compute overhead and possibility of bricking devices remotely is too high. Basically, the demo is enough to show those who need to know how easy it is to jailbreak.
@renakunisaki
@renakunisaki Жыл бұрын
It's always a double edged sword. You're telling them how to lock it down better and telling malicious actors how to exploit them, but you're also telling people how to be able to actually use the very expensive machine they paid for without being extorted.
@DigiTheInformer
@DigiTheInformer Жыл бұрын
As mentioned the units in the field will out last our laptops. Farmers don't upgrade fast enough for JD to patch effectively. A hack today lasts for decades. Food should be Open Source.
@HeartsandMachineGuns
@HeartsandMachineGuns Жыл бұрын
Such a fantastic talk and a fantastic con this year all around. Was the best year for me.
@Time4Technology
@Time4Technology 10 ай бұрын
Read this as "fantastic corn" at first.
@melltelae3557
@melltelae3557 8 ай бұрын
that was such a fantastic comment. i want to commend you for the best internet comment all around.
@k33li0
@k33li0 Жыл бұрын
Thank you sickcodes for putting in this work!! looking forward to your solutions for farmers to easily jailbreak it. Would love to see the simple pcb thing you have going offered for sale
@montanaharkin
@montanaharkin Жыл бұрын
Interesting that all of the software for each license is already on the device as well...
@MyDancingirl
@MyDancingirl Жыл бұрын
Great information, thanks for sharing
@az.tek.00
@az.tek.00 Жыл бұрын
Beautiful work. Thx for your efforts. 💥💯🏴‍☠️❤😎
@EllieJ-gl6rg
@EllieJ-gl6rg 9 ай бұрын
Thanks sickcodes for everything ❤
@MichaelOfRohan
@MichaelOfRohan Жыл бұрын
This is my 3rd second defcon talk i think!! Super crazy skils
@josharmour
@josharmour Жыл бұрын
You should have a go at the Sena/Harley Davidson anti customer firmware shenanigans that is used by the helmet headsets produced by Sena for Harley Davidson. Lots of happy bikers if you help there.
@Ozai36regno
@Ozai36regno Жыл бұрын
Just curious why there is very few actual recorded talks from this year's DefCon on the channel..
@tonyzone8999
@tonyzone8999 Жыл бұрын
I believe some talks was shut down by the feds
@gemmapeter7173
@gemmapeter7173 Жыл бұрын
If you've got a brand new combine harvester he'll give you the key.
@DigiTheInformer
@DigiTheInformer Жыл бұрын
Cause you got 20 acres and i've got 43.
@eformance
@eformance Жыл бұрын
Dunno if the presenter will read this, but did you try to exploit the software install via USB stick? Given the RPM base distro, it would be logical they distribute software as RPMs.
@SickCodes
@SickCodes Жыл бұрын
They do except that the firmware has to pass their repo and all the yum configs have signature thing on. I am however working on another method using isobus virtual terminals which are like popups over canbus
@mskiptr
@mskiptr Жыл бұрын
Now I guess we need a postmarketOS for tractors
@davidanalyst671
@davidanalyst671 Жыл бұрын
YES!!!
@CornishCarper
@CornishCarper Жыл бұрын
Sick your presentation was SICKKKK BOI! #RightToRepair
@bobmcbob4399
@bobmcbob4399 Жыл бұрын
So sick as in no one watching can reproduce his hacks as he does not go into the details of his successful hacks, just waffles past them.
@loicpiernas3102
@loicpiernas3102 Жыл бұрын
A bit hard to follow but very interesting
@MarketingMovies1337
@MarketingMovies1337 Жыл бұрын
Success dude! All about that Success
@Dave-kq7gv
@Dave-kq7gv Жыл бұрын
I dislike the modifier "{as a [...]}", but {as an [Iowan nerd who was at DC30]} I'm sad I missed this talk. Doom was the cherry on top! Cheers 🌽🌽
@toastyPredicament
@toastyPredicament Жыл бұрын
Does the DEF CON convention area have back rooms?
@TillmannHuebner
@TillmannHuebner Жыл бұрын
loved that arch joke :D
@sovereignprime4683
@sovereignprime4683 Жыл бұрын
this would be a bitch to do but changing the computer is the way to go. I bet you could run a tractor on a raspberry pie.
@Bruke53
@Bruke53 Жыл бұрын
The issue being the group of people who happen to be technically skilled enough to write the code for that overlaps very minimally with the group of people who are farming at the scale to benefit from said code.
@dustinmorrison6315
@dustinmorrison6315 Жыл бұрын
Incredible.
@AlanThompsonTheFirst
@AlanThompsonTheFirst Жыл бұрын
i need to know whether "in the field" is pun intended ?!!
@SickCodes
@SickCodes Жыл бұрын
There’s so many corny puns in Agriculture, so I can’t confirm this 😂
@AlanThompsonTheFirst
@AlanThompsonTheFirst Жыл бұрын
@@SickCodes I've got no beef with that
@renakunisaki
@renakunisaki Жыл бұрын
@@SickCodes now you're just farming for laughs
@von...
@von... Жыл бұрын
@@renakunisaki nah, I respect his dedication to reaping the discourse being sown here
@Lino1259
@Lino1259 Жыл бұрын
My dude has worse ADHD issues than me, and thats RARE.
@kspfan001
@kspfan001 Жыл бұрын
people here complaining about this guy's presentation and I have no idea what they are talking about. but, would make a lot of sense if it's just adhd cus I also have terrible adhd. I guess ppl with adhd can both understand each other a lot better than someone without.
@denissorn
@denissorn Жыл бұрын
wasn't OVH mainly in business of renting dedicated servers. At prices significantly below their competition. If you are afraid something will happen to your dedicated server than have some redundancy, or change 'modus operandi' lol and pay the same price for 5x worse virtual ones, where you also wouldn't get free backups. So, I guess, SaaS, serverless etc are the only right choices.
@sovereignprime4683
@sovereignprime4683 Жыл бұрын
Tell me more about wind River UNIX
@Hebdomad7
@Hebdomad7 Жыл бұрын
26:20 - don't worry mate, it's already rooted by john deer mate. We are here to fix it!
@yepee1
@yepee1 Жыл бұрын
Do one on subverting drm on farm equipment. It keeps are farmers from doing their jobs.
@goatpepperherbaltea7895
@goatpepperherbaltea7895 Жыл бұрын
“IVE GOT A LOT RIDING ON THIS!!”
@zxcvb_bvcxz
@zxcvb_bvcxz Жыл бұрын
What happened to the bitrate here?
@fllthdcrb
@fllthdcrb Жыл бұрын
It has the appearance of being from a livestream. Bitrate management is severely constrained on those, seeing as the encoder can barely plan ahead at all.
@user-sf4vn4lf9h
@user-sf4vn4lf9h 4 ай бұрын
Unfortunate the vid resolution isn't (a lot) better...
@HEREisTRACYY
@HEREisTRACYY 5 ай бұрын
If i sold a car and some one sells it for cheaper or more..are they cheatin or are there smart to to know that u have a flaw..
@michaeltaylor8835
@michaeltaylor8835 Жыл бұрын
What about right to repair
@davidanalyst671
@davidanalyst671 Жыл бұрын
this man just gave you the right to repair
@jevans101
@jevans101 Жыл бұрын
fully sick!
@newspecies2149
@newspecies2149 Жыл бұрын
audience seemed a bit dead, great talk!
@jimmysoncookland5446
@jimmysoncookland5446 Жыл бұрын
Chad codes
@t.alexanderlystad291
@t.alexanderlystad291 Жыл бұрын
I thought Louis C.K. was cancelled
@faradaysage15
@faradaysage15 Жыл бұрын
Octave is only one of 8 names he has
@pandeomonia
@pandeomonia Жыл бұрын
Thanks for the presentation but I was pretty worried when I got to the 12 minute mark and still nothing interesting had happened other than some sales brochures on makes and models (just why). Dunno if Sick Code reads comments, but maybe vet your presentation with some friends first, I think this really suffered from a lack of focus, and what focus was there was on fluff/un-useful material.
@davidanalyst671
@davidanalyst671 Жыл бұрын
this wasn't a video showing THAT he cracked the computer, hes telling you the tools he used to break the tractor. He wants you to use the tools to break your tractor as well
@SickCodes
@SickCodes 11 ай бұрын
Thanks for the feedback mate, there was definitely quite a bit of fluff in here. In follow up talks since this, I have removed most of the useless/boring parts. This was my first talk post-pandemic so was pretty nervous on stage 😂
@tonyzone8999
@tonyzone8999 Жыл бұрын
Is this talk about helping farmers or is it helping the corporate giant
@graog123
@graog123 6 ай бұрын
Late feedback: First 5 minutes of this video are really chaotic.
@mrbinky7
@mrbinky7 Жыл бұрын
you make my brain hurt, think you
@anundagreen
@anundagreen Жыл бұрын
one more until the nice number
@auzzierocks
@auzzierocks Жыл бұрын
Australia represent
@user-bh8uy8ur4j
@user-bh8uy8ur4j 8 ай бұрын
Man, it's funny how they price everything 20,000 2,000 585 (600)
@__cm__
@__cm__ Жыл бұрын
jeez you can play DOOM on it!
@michaeltaylor8835
@michaeltaylor8835 Жыл бұрын
Everythong is a target. Irs crazy
@renakunisaki
@renakunisaki Жыл бұрын
Every thong 😳
@JohnSmith-fq3rg
@JohnSmith-fq3rg Жыл бұрын
@@renakunisaki 😩
@illygah
@illygah Жыл бұрын
continental makes automotive components
@SELG88
@SELG88 Жыл бұрын
this video feels kinda weird. You just showed them their software's vulnerabilities and they will take the necessary precautions.
@sarahmanalapan8443
@sarahmanalapan8443 Жыл бұрын
Imagine having 100k of crops that would of net you 60k but its gonna take 20K to unlock the software on your tractor and harvest. Thats the definition of being screwed you just have open the wallet and tighten your belt. Also imagine him not having a good presentation style and watching thr ehole thing without understandinghow he actuall got root!
@michaeltaylor8835
@michaeltaylor8835 Жыл бұрын
Remember when machines didnt need computers. Im sure you can unhook.a machine from AI
@renakunisaki
@renakunisaki Жыл бұрын
Does it even have AI? I thought it just had GPS.
@ShainAndrews
@ShainAndrews Жыл бұрын
Neither one of you know anything. Just buzz word salad tossed at the wall....
@von...
@von... Жыл бұрын
@@ShainAndrews intuitive SaaS systems completely in harmony w/ versatility of on-demand deployment how about that one? I hope you liked my salad because it was hard to put together without my brain hurting lol
@von...
@von... Жыл бұрын
@@ShainAndrews also sir, with all due respect, can you confirm or deny the allegations that you are in-fact a dog driving a car - who can also write KZfaq comments?
@firinne
@firinne Жыл бұрын
7:22
@YouChube3
@YouChube3 Жыл бұрын
This explanation is far beyond my intuition. What are key takeaways? What is now possible with a tractor? What is a likely open source scenario stemming from the new capabilities presented? How will food production benefit?
@renakunisaki
@renakunisaki Жыл бұрын
I think the biggest takeaway is that it's now possible to repair your tractor, and actually be allowed to use the features it has, without paying obscene subscription fees and just trusting that their systems keep doing the right thing. Another notable finding is that the anti-theft protection is trivial to bypass.
@omardelmar
@omardelmar Жыл бұрын
They should be hacking factory farms.
@ShainAndrews
@ShainAndrews Жыл бұрын
This guy really needs someone adept at the physical side. This is industrial equipment. Yeah the shit is going to have thread locker applied everywhere. Your tools meet the bare minimum for PC repair. You remove chips with a utility blade? I'm moving on before I start punching kittens.
@DutchManticore
@DutchManticore 8 ай бұрын
Intesting topic but its hard to listen to this. Lots of unstructured tangents, and it feels like youre surprised at the content of every slide making you pause or going "ohh!" Lots of random flipping back and forth between slides, lots of pauzes and long drinking pauzes. Some constructive criticism
@lineways5477
@lineways5477 Жыл бұрын
In the soviet russia tractors hack you
@keycontroller
@keycontroller Жыл бұрын
🤣jd is doomed
@TakNULLr
@TakNULLr Жыл бұрын
puh this talk is hard to follow because of his jumping all over the place :(
@richardedmondson9434
@richardedmondson9434 Жыл бұрын
This may be the most disorganized, rambling presentation I've ever seen from DEFCON. Maybe 5 minutes of on-topic content spread across 48 minutes.
@ThomasGabrielsen
@ThomasGabrielsen Жыл бұрын
I hate to criticize people who give presentations, but this was really messed up. If he had structured the content it would have been really interesting, but I really struggled to follow and kept thinking that everything will be wrapped up at the end of the presentation, but then he ended up playing DOOM. Running DOOM on the console on a tractor is fun, but not very interesting when it's hard to understand how he manage to do it. I doubt that people who are not computer literate will benefit from this information at all. It was far too messy and unstructured for that. What's the point of having lots of slides that he just flips right past.
@renakunisaki
@renakunisaki Жыл бұрын
Yeah this guy would have benefited greatly if he'd prepared a script and read from it. It seemed like he had some technical issues as well so that's why he skipped some slides.
@kspfan001
@kspfan001 Жыл бұрын
I didn't have trouble following it.
@edak1
@edak1 Жыл бұрын
@@kspfan001 can you tell us how he enabled root without desoldering?
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
Watching this shit having to threat model initiation of contact using integer variables and two character variable "VD"
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
kzfaq.info/get/bejne/eMqWo7leyK_PpXU.html
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
kzfaq.info/get/bejne/o715icepvtOXeIE.html "Repeat after me "I'm retarded not retardent"
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
Only when it helps them
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
Watching handicaps on 20ft
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
So here's another 500 lb interaction every iteration of action "not touching you"
@JohnSmith-fq3rg
@JohnSmith-fq3rg Жыл бұрын
Nothing is wrong with unmaintained software/hardware; if it worked in the 90's, the software will still be functional now. It's a tractor, it doesn't fucking need to be online and exposed to attacks.
@Energine1
@Energine1 Жыл бұрын
You clearly havent been around a serious farming operation in a while. You may as well state that "Its a teenager, they don't NEED the internet!"
@Energine1
@Energine1 Жыл бұрын
For exapmle: They fly drones with multispectral optics that capture invisible changes for TARGETED applications of chemicals, fertilizer, irrigation, infestation intervention etc... These are then used to augment regularly sampled satellite data of the farm and compiled into a solution package which is crosschecked for weather forecasts and implemented for the day.
@JohnSmith-fq3rg
@JohnSmith-fq3rg Жыл бұрын
@@Energine1 Niggas got by with their eyes and an almanac for millions of years, they don't need that shit, lol
@robs3644
@robs3644 Жыл бұрын
Is this Anonymous?
@quillclock
@quillclock Жыл бұрын
nah this guy is "Sick Codes"
@robs3644
@robs3644 Жыл бұрын
@@quillclock could he be in anonymous?
@quillclock
@quillclock Жыл бұрын
@@robs3644 I mean yeah. anyone could be.
@robs3644
@robs3644 Жыл бұрын
Do you reckon he sleeps with his dad?
@yzrippin
@yzrippin Жыл бұрын
No his name is Patrick
@youarethecreator1
@youarethecreator1 Жыл бұрын
Please get over the mask delusion, geez us.
@HRRRRRDRRRRR
@HRRRRRDRRRRR Жыл бұрын
Right back at you. Get over it.
@youarethecreator1
@youarethecreator1 Жыл бұрын
@@HRRRRRDRRRRR Get over what? Watching half the human race go full retard? How about turn off the propaganda news networks and stop complying with your own slavery? I’m sure those are big words and concepts for you to synthesize so take your time.
@rebane2001
@rebane2001 Жыл бұрын
I travelled to the US recently and people mostly don't wear masks anymore, but at conventions and other gatherings it's usually heavily recommended because you have a lot of people spending time together in the same crowded place, so disease can very easily spread - makes sense to take extra precautions there.
@creaturerecords
@creaturerecords Жыл бұрын
youre the only ones freaking out dude. where did the "my body my choice" go?
@youarethecreator1
@youarethecreator1 Жыл бұрын
@@rebane2001 So you don’t get it either. I’ll spell it out for you. People have been spreading all sorts of nasty things for hundreds maybe even thousands of years and the human race is still here alive and kicking. What makes you think (oh yeah, the propaganda media networks) that masks do anything at all? Hundreds and thousands of years is scientific proof vs. 2 years of media BS. I’m sorry, I just can’t believe anyone with half a brain can even think that’s logical. It makes no sense at all. I respectfully disagree and I hope this fades away so that our kids concept of a normal life isn’t permanently adulterated.
@agrofaq
@agrofaq Жыл бұрын
hack trimble cfx750
DEF CON 30 - Roger Dingledine - How Russia is trying to block Tor
47:27
DEFCONConference
Рет қаралды 62 М.
100😭🎉 #thankyou
00:28
はじめしゃちょー(hajime)
Рет қаралды 18 МЛН
Когда на улице Маябрь 😈 #марьяна #шортс
00:17
狼来了的故事你们听过吗?#天使 #小丑 #超人不会飞
00:42
超人不会飞
Рет қаралды 50 МЛН
1❤️
00:20
すしらーめん《りく》
Рет қаралды 32 МЛН
Jmaxxz - Your Car is My Car -  DEF CON 27 Conference
41:03
DEFCONConference
Рет қаралды 119 М.
How Hackers Could Wirelessly Bug Your Office
7:33
Motherboard
Рет қаралды 932 М.
DEF CON 26 - Si, Agent X - Wagging the Tail:Covert Passive Surveillance
47:14
Why it Was Almost Impossible to Put a Computer in Space
17:20
Linus Tech Tips
Рет қаралды 988 М.
POCO F6 PRO - ЛУЧШИЙ POCO НА ДАННЫЙ МОМЕНТ!
18:51
👎Главный МИНУС планшета Apple🍏
0:29
Demin's Lounge
Рет қаралды 482 М.
С Какой Высоты Разобьётся NOKIA3310 ?!😳
0:43