The researchers also say they were able to prove the existence of the "Elon mode" (non restricted, fully self driving) and they were able to turn the mode on. All by a voltage glitch attack on the board with cheap equipment #37c3
Full story in German :spiegel.de/netzwelt/gadge…
Security researchers say they were able to access restricted parts of the autopilot board in Tesla vehicles, access the neural networks and reverse engineer most of the program. Even recover deleted footage from a Tesla vehicle.
Here is what they told me:
spiegel.de/netzwelt/gadge…
Drei Berliner Sicherheitsforschern haben mir berichtet, dass sie per Voltage-Glitch Teslas Autopilot-Platine gehackt und den gesperrten Elon-Modus eingeschaltet haben.
Heute stellen Sie beim #37c3 ihre Forschung ausführlich vor, hier eine Übersicht spiegel.de/netzwelt/gadge…
Disk encryption is critical in securing your data when you lose your device or an attacker gets physical access. But we found that if you don't use a BitLocker passphrase on an AMD system (before Windows even comes up), your data is not adequately secured: arxiv.org/abs/2304.14717
blackhat.com/us-23/briefing… Why testing fault injection attacks on integrated circuits matters?
⚡️🚗🔐 At BlackHat 23, a research team from @TUBerlin: Christian (@_cwerling), Niclas, Hans and Oleg will show voltage glitch attack against AMD Secure Processor (ASP) used in Tesla cars!
We built a stealth AirTag clone that is not detected by Apple’s tracking protection. It works by only sending one beacon per generated public key.
positive.security/blog/find-you
New blog post: Windows 10 RCE via an argument injection in the ms-officecmd URI handler.
While our RCE vector (MS Teams) has been fixed, the argument injection still persists.
positive.security/blog/ms-office…
@WangTielei While checking out the Nailgun Attack paper [0], I saw an acknowledgment to you for checking iOS devices. Any insights you would be willing to share? Wondering whether the M1 might be susceptible, too.
[0] compass.sustech.edu.cn/nailgun/
Unpatched, critical vulnerabilities in the PlingStore app and Pling-based Linux marketplace websites and patched, lower-severity vulnerabilities in KDE Discover and the Gnome Shell Extensions website
positive.security/blog/hacking-l…
Different port, same exploit: Our research found how a patched vulnerability in ZyXEL NAS devices was still exploitable due to incomplete patching
srlabs.de/bites/zyxel-ze…
Apple AirTags: Arbitrary data can be uploaded from non-internet-connected devices by sending Find My BLE broadcasts to nearby Apple devices: positive.security/blog/send-my
After months of hard work, we're releasing #LibAFL
✔️Scales across cores and machines
✔️Windows, Android, no_std, ...
✔ Different Modes like binary-only Frida mode (120k execs/sec on a phone anyone?)
✔ Easy to extend with grammar fuzzing, etc.
✔️Rust ;)
9 Followers 539 FollowingAt a certain age, four things must be thrown away: meaningless bars, people who don't love you, despising your relatives, false friends.
836 Followers 2K FollowingSecurity rants&food. Public @naehrdine, working at @HPI_DE (ex @seemoolab). Opinions are someone's. Feel free to request to follow. @[email protected]
3K Followers 850 FollowingReporter for @DerSpiegel on Infosec, Cybercrime, digital national security, digital politics and AI | 2023 ICFJ Burns Fellow @washingtonpost
5K Followers 4K FollowingExpose phishing pages and sometimes malware on domain to either to get reported or exposed out public. Majority of these criminals are part of the underground.
353 Followers 285 Following"You should put a comparable amount of effort into making them better and keeping them under control" (Professor Geoffrey Hinton on AI systems)
3K Followers 850 FollowingReporter for @DerSpiegel on Infosec, Cybercrime, digital national security, digital politics and AI | 2023 ICFJ Burns Fellow @washingtonpost
30K Followers 444 FollowingWe identify with little penguins and sue the German secret service. These are crossposts from Mastodon: https://t.co/ql195UagSf
68 Followers 81 FollowingArchitect: preferably tree-houses, primarily security for @Azimuth-IA. Would rather be in the mountains. My thoughts and statements are my own.
19K Followers 29 FollowingShowing the best (and worst) scran at Mensa and cafeterias all over the world. DMs are open for photos 🍔📸 Contact - [email protected] (scran is positive!)
823 Followers 42 FollowingThe leading ACM and SIGSAC conference dedicated to security and privacy in wireless and mobile networks and their applications.
9K Followers 540 Following#InfoSec University Professor @ #TUGraz. #meltdown, #spectre, #rowhammer, cache attacks, sustainable security. Produced a side channel security sitcom.
43K Followers 363 FollowingI built a C library that lets you compile 12kb static binaries that run natively on Linux, Mac, Windows, FreeBSD, OpenBSD, NetBSD and BIOS using just GCC/Clang.
89K Followers 0 FollowingI report what I see. If it's good, it's good; if it's bad, it's bad. Does not depend on me. Make them release more awesome stuff. Don't shoot the messenger.
145 Followers 68 FollowingAssociate Professor and University Faculty Scholar at NC State. President of mithrilAI. Works on cybersecurity with a hardware focus.
70K Followers 933 FollowingPresident of @DIW_Berlin, Professor at Humboldt University, and columnist Die Zeit. My new book: „Nach uns die Zukunft - Ein neuer Generationenvertrag…“