{"id":17798,"date":"2020-02-22T10:45:28","date_gmt":"2020-02-22T18:45:28","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/02\/22\/news-11531\/"},"modified":"2020-02-22T10:45:28","modified_gmt":"2020-02-22T18:45:28","slug":"news-11531","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2020\/02\/22\/news-11531\/","title":{"rendered":"A Tiny Piece of Tape Tricked Teslas Into Speeding Up 50 MPH"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e50481ca4dea100087f96e7\/master\/pass\/Security_teslax_628733180.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Sat, 22 Feb 2020 14:00:00 +0000<\/strong><\/p>\n<p class=\"byline bylines__byline byline--author\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\"><span class=\"byline__name byline--with-bg\"><a class=\"byline__name-link\" href=\"\/contributor\/brian-barrett\">Brian Barret<span class=\"link__last-letter-spacing\">t<\/span><\/a><\/span> <\/span><\/p>\n<p class=\"content-header__row content-header__dek\">An MGM Resorts breach, natural gas ransomware, and more of the week&#39;s top security news.<\/p>\n<p>This week was filled with wide-scale calamity. <a href=\"https:\/\/www.wired.com\/story\/firmware-hacks-vulnerable-pc-components-peripherals\/\">Hundreds of millions of PCs<\/a> have components whose firmware is vulnerable to hacking\u2014which is to say, pretty much all of them. It&#x27;s a problem that&#x27;s been known about for years, but doesn&#x27;t seem to get any better.<\/p>\n<p>Likewise, Bluetooth implementation mistakes in seven SoC\u2014system on chips\u2014have exposed <a href=\"https:\/\/www.wired.com\/story\/bluetooth-flaws-ble-internet-of-things-pacemakers\/\">at least 480 internet of things devices to a range of attacks<\/a>. IoT manufacturers will often outsource components, so a mistake in one SoC can impact a wide range of connected doodads. The most troubling part, though, is that medical devices like pacemakers and blood glucose monitors are among the affected tech.<\/p>\n<p>YouTube Gaming, meanwhile, wants to take Twitch&#x27;s crown as the king of videogame streaming. But its <a href=\"https:\/\/www.wired.com\/story\/youtube-gaming-scams-cheats-livestreams\/\">most-viewed channels are almost all scams and cheats<\/a>, a moderation challenge that it&#x27;ll have to take more seriously if it wants the legitimacy <a href=\"https:\/\/www.wired.com\/story\/activision-esports-leagues-youtube-exclusive\/\">it&#x27;s spending big money to attain<\/a>. In another corner of Alphabet&#x27;s world, hundreds of Chrome extensions were caught siphoning data from people who installed them, part of a sprawling adware scheme.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/us-blames-russia-gru-sweeping-cyberattacks-georgia\/\">WIRED reported exclusively this week<\/a> that US officials have pinned a wave of cyberattacks against the country of Georgia on Russia&#x27;s notorious Sandworm hackers. The hack itself was brazen\u2014defacing 15,000 websites and disrupting two TV networks\u2014but the attribution serves mostly as a warning to Russia that it shouldn&#x27;t attempt the same sort of malarky stateside.<\/p>\n<p>With the firing of director of national intelligence Joseph Maguire this week, Donald Trump has <a href=\"https:\/\/www.wired.com\/story\/trump-hollowed-out-us-national-security-vacancies-acting\/\">continued his gutting of senior national intelligence positions<\/a>. Probably not a great strategy in the long run, especially since <a href=\"https:\/\/www.wired.com\/story\/bernie-sanders-russia-chaos-2020-election\/\">Russia is actively supporting both Trump and Bernie Sanders this year<\/a>, just like they did in 2016. (In fairness, they only want Trump to actually win.)<\/p>\n<p>And that&#x27;s not all! Every Saturday we round up the security and privacy stories that we didn\u2019t break or report on in depth but think you should know about nonetheless. Click on the headlines to read them, and stay safe out there.<\/p>\n<p>Researchers at McAfee have demonstrated a new spin on an old trick. By subtly tampering with a speed limit sign\u2014in this case, literally adding a two-inch strip of black tape\u2014they were able to trick the Mobileye EyeQ3 camera on a 2016 Tesla Model X and Model S into feeding bad information to the vehicles&#x27; autonomous driving features, sending both cars into a rapid acceleration. It&#x27;s a low-tech version of the <a href=\"https:\/\/www.wired.com\/story\/ai-has-a-hallucination-problem-thats-proving-tough-to-fix\/\">well-known problem of adversarial examples<\/a>, image alterations that cause machine learning systems to misinterpret data. (Intel, which owns Mobileye, disputes that it&#x27;s an adversarial attack, since the tape could have fooled a human eye as well.) The good news is that the problem doesn&#x27;t affect 2020 Teslas, which no longer use Mobileye technology, and newer versions of the Mobileye camera seem impervious as well. That doesn&#x27;t help older models, though, which remain susceptible to the shenanigans below:<\/p>\n<p><iframe loading=\"lazy\" height=\"420\" sandbox=\"allow-scripts allow-popups allow-same-origin\" class=\"iframe-embed__content\" title=\"Embedded Frame\" src=\"https:\/\/www.youtube.com\/embed\/4uGV_fRj0UA\" width=\"100%\" frameborder=\"0\" style=\"\"><\/iframe><\/p>\n<p>Ransomware has long targeted victims that have the most to lose. That&#x27;s typically meant <a href=\"https:\/\/www.wired.com\/2016\/03\/ransomware-why-hospitals-are-the-perfect-targets\/\">hospitals<\/a> and <a href=\"https:\/\/www.wired.com\/story\/atlanta-spent-26m-recover-from-ransomware-scare\/\">governments<\/a>. But lately hackers have targeted another sensitive field: <a href=\"https:\/\/www.wired.com\/story\/ekans-ransomware-industrial-control-systems\/\">critical infrastructure<\/a>. The latest example comes from the US Cybersecurity and Infrastructure Security Agency, which reported this week that a natural gas compression facility went down for two days as they grappled with a ransomware infection. There&#x27;s not really any <em>good<\/em> news here, but it certainly could have been worse; the hackers appear not to have targeted industrial control system components specifically. They got lucky with a phishing email, and were only able to impact the Windows-based portions of the victim&#x27;s network.<\/p>\n<p>If you stayed at an MGM Resorts hotel sometime before 2017, the bad news is that someone hacked one of their servers and stole data relating to over 10 million guests. The worse news is that said data has since been discovered in an online hacking forum, as first reported <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.zdnet.com\/article\/exclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking-forum\/&quot;}\" href=\"https:\/\/www.zdnet.com\/article\/exclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking-forum\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">by ZDNet<\/a>. The haul includes names, addresses, phone numbers, emails, and dates of birth, and celebrities, politicians, and journalists are among those affected. (Sorry, Jack Dorsey!) It could have been worse\u2014no financial information appears to be involved\u2014but as with any breach, look out for phishing attempts or identity theft.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/adware-most-common-malware\/\">Adware is like gnats<\/a>: everywhere, annoying, impossible to get rid of but relatively harmless. But you still have to try, which Google did this week by expelling nearly 600 apps both from the Play Store and its ad networks. That includes 45 apps from a single developer, China-based Cheetah Mobile. Google cited &quot;disruptive ads&quot; as the reason for the removal, framing it as part of a broader crackdown on fraudulent behavior.<\/p>\n<p>In other data compromise news, the Defense Information Systems Agency\u2014which provides secure communications support to the US president and military\u2014informed potential victims this week that their Social Security numbers may have been part of a breach that occurred between May and July 2019. They&#x27;ll spring for free credit monitoring if you were affected, but honestly you&#x27;ve already got that through Marriott or Equifax or take your pick, right?<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/tesla-speed-up-adversarial-example-mgm-breach-ransomware\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e50481ca4dea100087f96e7\/master\/pass\/Security_teslax_628733180.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Sat, 22 Feb 2020 14:00:00 +0000<\/strong><\/p>\n<p>An MGM Resorts breach, natural gas ransomware, and more of the week&#8217;s top security news.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-17798","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17798"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17798\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}