Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Phillies lose late lead, rally to finish 3-game sweep of Tigers

    June 9, 2023

    US Judge Dismisses Lawsuit Against DeFi Startup, PoolTogether

    June 9, 2023

    It’s not just Apollo: other Reddit apps are shutting down, too

    June 9, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    EasyDailyCrypto – Today Crypto | Bitcoin | Global World News
    Button
    • Home
    • Features
      • Contact
    • Crypto
    • Politics

      Trump Has Apparently Committed So Many Crimes That He’s Not Sure What He’s Indicted For

      June 9, 2023

      Joe Rogan Eviscerates Target For Going Woke – ‘Stop Shoving This Down Our Throats!’

      June 9, 2023

      One Of Jim Jordan’s Fake Whistleblowers Has Been Referred To Merrick Garland For Lying To Congress

      June 9, 2023

      SCOTUS Shocks With ‘Huge’ Ruling Protecting Black Voters in Alabama

      June 9, 2023

      SCOTUS’ Stay Might Have ‘Wrongly’ Given Republicans the House

      June 9, 2023
    • Technology
      1. Crypto
      2. Politics
      3. Business
      4. Lifestyle
      5. View All

      US Judge Dismisses Lawsuit Against DeFi Startup, PoolTogether

      June 9, 2023

      Bitcoin, Ethereum Volumes At 1-Month Highs, Volatility Soon?

      June 9, 2023

      Cathie Wood Says ‘Uncertainty and Volatility’ Solidifies Belief That Bitcoin Will Reach $1 Million

      June 9, 2023

      Regulators Put the Squeeze on Crypto Trading, Volumes Plummet

      June 9, 2023

      Trump Has Apparently Committed So Many Crimes That He’s Not Sure What He’s Indicted For

      June 9, 2023

      Joe Rogan Eviscerates Target For Going Woke – ‘Stop Shoving This Down Our Throats!’

      June 9, 2023

      One Of Jim Jordan’s Fake Whistleblowers Has Been Referred To Merrick Garland For Lying To Congress

      June 9, 2023

      SCOTUS Shocks With ‘Huge’ Ruling Protecting Black Voters in Alabama

      June 9, 2023

      Donald Trump says he has been indicted on federal charges in documents probe

      June 9, 2023

      EU ministers clinch deal on migration reform

      June 9, 2023

      Live news: Moody’s lowers outlook on Coinbase to ‘negative’

      June 9, 2023

      Joe Biden says US will have funding for Ukraine for ‘as long as it takes’

      June 9, 2023

      Easy Ways to Add Retinol to Your Routine

      June 8, 2023

      The 4 Best Clean Lubes

      June 6, 2023

      Jeanine Lobell’s Glowy, Chic Makeup (and Skin) Tutorial

      June 6, 2023

      It’s a Summer of Sea Minerals for Skin, Flickering Candles, and a New French Brush

      June 6, 2023

      It’s not just Apollo: other Reddit apps are shutting down, too

      June 9, 2023

      Devolver Digital’s showcase featured just four games, but they look like good ones

      June 9, 2023

      Logitech is killing off the Blue mic brand, will sell Yeti and Astro under Logitech G

      June 9, 2023

      Summer Game Fest featured no women onstage

      June 9, 2023
    EasyDailyCrypto – Today Crypto | Bitcoin | Global World News
    Beranda » Sirius XM flaw could’ve let hackers remotely unlock and start cars
    Technology

    Sirius XM flaw could’ve let hackers remotely unlock and start cars

    EASYDAILYCRYPTO NEWSBy EASYDAILYCRYPTO NEWSDecember 3, 2022No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A vulnerability affecting Sirius XM’s connected vehicle services could’ve let hackers remotely start, unlock, locate, flash the lights, and honk the horn on cars. Sam Curry, a security engineer at Yuga Labs, worked with a group of security researchers to discover the flaw and outlined their findings in a thread on Twitter (via Gizmodo).

    In addition to providing a satellite radio subscription, Sirius XM also powers the telematics and infotainment systems used by a number of auto manufacturers, including Acura, BMW, Honda, Hyundai, Infiniti, Jaguar, Land Rover, Lexus, Nissan, Subaru, and Toyota. These systems collect a whole lot of information about your car that’s easy to overlook — and could pose potential privacy implications. Last year, a report from Vice called attention to a spy firm that planned to sell the telematics-based location information of over 15 billion cars to the US government.

    While telematics systems obtain data about your car’s GPS location, speed, turn-by-turn navigation, and maintenance requirements, certain infotainment setups might track call logs, voice commands, text messages, and more. All of this data allows vehicles to provide “smart” features, like automatic crash detection, remote engine start, stolen vehicle alerts, navigation, and the ability to remotely lock or unlock your car. Sirius XM offers all these features and more, and says over 12 million vehicles on the road use its connected vehicle systems.

    However, as Curry demonstrates, bad actors can take advantage of this system if the proper safeguards aren’t in place. In a statement to Gizmodo, Curry says Sirius XM “built infrastructure around the sending/receiving of this data and allowed customers to authenticate to it using some form of mobile app,” like MyHonda or Nissan Connected. Users can log into their accounts on these apps, which are linked to their vehicle’s VIN number, to execute commands and obtain information about their cars.

    It’s this system that could give bad actors access to someone’s car, Curry explains, as Sirius XM uses the VIN number linked with a person’s account to relay information and commands between the app and its servers. By creating an HTTP request to fetch a user’s profile with the VIN, Curry says he was able to obtain the vehicle owner’s name, phone number, address, and car details. He then tried executing commands using the VIN and discovered that he could remotely control the vehicle, allowing him to lock or unlock it, start the car, and perform other functions.

    Curry says he alerted Sirius XM of the flaw and that the company quickly patched it. In a statement to Gizmodo, the company said the vulnerability “was resolved within 24 hours after the report was submitted,” noting that “at no point was any subscriber or other data compromised nor was any unauthorized account modified using this method.” Sirius XM didn’t immediately respond to The Verge’s request for comment.

    Separately, Curry uncovered another flaw within the MyHyundai and MyGenesis apps that could also potentially let hackers remotely hijack a vehicle, but says he worked with the automaker to fix the issue. White hat hackers have found similar exploits in the past. In 2015, a security researcher uncovered an OnStar hack that could’ve let bad actors locate a vehicle remotely, unlock its doors, or start the car. Around the same time, a report from Wired showed how a Jeep Cherokee could be remotely hacked and controlled with someone at the wheel.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    EASYDAILYCRYPTO NEWS
    • Website

    Daily update exclusive News about the latest Crypto, Bitcoin, Ethereum, Blockchain, NFTs, Altcoin, Trendings News with the latest Global World News today

    Related Posts

    It’s not just Apollo: other Reddit apps are shutting down, too

    June 9, 2023

    Devolver Digital’s showcase featured just four games, but they look like good ones

    June 9, 2023

    Logitech is killing off the Blue mic brand, will sell Yeti and Astro under Logitech G

    June 9, 2023

    Leave A Reply Cancel Reply

    Advertisement
    Our Picks

    Kim Kardashian’s Cryptocurrency Lawsuit Progresses

    June 7, 2023

    Red Sox rally late to beat Guardians, end skid

    June 7, 2023

    How Blogging Can Boost Sales and Revenue

    June 6, 2023

    Logi Dock review: conference calls have never been so cute

    May 29, 2023
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Sports

    Phillies lose late lead, rally to finish 3-game sweep of Tigers

    By EASYDAILYCRYPTO NEWSJune 9, 202300 Views

    Jun 8, 2023; Philadelphia, Pennsylvania, USA; Philadelphia Phillies starting pitcher Zack Wheeler (45) throws a…

    US Judge Dismisses Lawsuit Against DeFi Startup, PoolTogether

    June 9, 2023

    It’s not just Apollo: other Reddit apps are shutting down, too

    June 9, 2023

    Donald Trump says he has been indicted on federal charges in documents probe

    June 9, 2023

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Update Breaking Crypto News about the latest Crypto daily, Ethereum, Blockchain, NFTs, Altcoin, Trends and Happenings including the latest World News. Exclusive crypto coin news in Easy Daily Crypto.

    Email Us: [email protected]
    Contact: +62-822-7359-8787

    Our Picks

    Phillies lose late lead, rally to finish 3-game sweep of Tigers

    June 9, 2023

    US Judge Dismisses Lawsuit Against DeFi Startup, PoolTogether

    June 9, 2023

    It’s not just Apollo: other Reddit apps are shutting down, too

    June 9, 2023
    Crypto

    US Judge Dismisses Lawsuit Against DeFi Startup, PoolTogether

    June 9, 2023

    Bitcoin, Ethereum Volumes At 1-Month Highs, Volatility Soon?

    June 9, 2023

    Cathie Wood Says ‘Uncertainty and Volatility’ Solidifies Belief That Bitcoin Will Reach $1 Million

    June 9, 2023
    Facebook Twitter Instagram Pinterest
    • Politics
    • Business
    • Crypto
    • Technology
    © 2023 All Right Reserved. Designed by EasyDailyCrypto.com.

    Type above and press Enter to search. Press Esc to cancel.