Friday, August 2, 2013

No, I am not taking my computer to DEFCON

Duh.  There be dragons.  I'm also turning the WiFi off on my phone.  Proper prior planning prevents perverse performance, and all that.

Long time readers will recall me ranting about how all the SCADA computers that control the power grid, oil drilling, chemical plants, etc are swiss cheese from a security perspective.  Well, I went to a nifty demo yesterday where they showed a hack (against a system they brought to the show, not against anyone live) where they (a) made a valve open to 100% to fill a tank, (b) made the SCADA operator's console show that the water level in the tank was decreasing, and (c) uploaded executable code of their choice to the SCADA system.  Mad lulz when they showed that the executable code was solitaire, and the operator's console was a touch screen.  Good times, good times.

Yeah, we're totally screwed.

DEFCON starts today.  I'm only going to today's sessions - I've been traveling long enough, thank you very much, and today's VoIP hacking session is of considerable interest to the company.  But there are not one, not two, but three sessions on hacking automobile computer systems.  My recommendation is to get yourself a GTO.  Or a Harley.  Hack those, biatchz!

And I'll miss out on the Pwnie Awards for best hacks.  I'll post on that when I get home.

I'll have scheduled posts for later today, but I'll be sort of dropping off the grid today as I prowl the mean corridors of the show.  You will not see me posted on the Wall Of Sheep.

Peace out.  Hack the Planet.  Free Kevin.

10 comments:

Matt W said...

Don't forget to turn off your bluetooth ;)

Matt W said...

Oh, and I think I'm going with you when I have to purchase my next vehicle. I'd rather buy an old Bronco or Blazer for cheap and pay to have it fixed up nice instead of purchasing a new PC with wheels.

I don't know why cars that can step on the brakes for you scare the bajeezus out of me... but they do.

Unknown said...

Yep, I've been looking at older compact and midsize cars, as in 60s to about mid-70s. First off, I've got this inexplicable thing for inline sixes; secondly, if I'm gonna drive a computer I want it to be one that I built. That pretty much rules out current (and future!) motor vehicles.

Seriously, the same ~$15k will get you a moderately crappy new car will get you something pretty sweet and almost infinitely home-hackable on the used market. It's turned into a no-brainer for me.

Old NFO said...

Yep, truly want my old GOAT back, along with a 50s/60s pickup...

Spike said...

Do you recall what the name of that demo on SCADA was? I would LOVE to find the vid/slides to show to my friends that run the DPW central energy plant/water distro system/waste water system...

Mark/GreyLocke said...

So you're saying my 65 Ford Galaxie would be good to hang on to? ;)

Unknown said...

GreyLocke: Old Fords FTW; that marque has always been good to me, whereas my parents' favored Chevies would smoke-check random locations if I just looked at them from the wrong angle. My first car was a '64 Galaxie, and I so wish I still had it.

Unknown said...

Spike:

I'm not Borepatch, nor am I at Black Hst/DEFCON, but I think the presentation might have been Out of Control: Demonstrating SCADA device exploitation.

There are slides and a PDF at that link, but no video at the moment.

Differ said...

New car is averaging 31 mpg which is about 3x what I expect from the unhackable 1970 Camaro.....running soon and will try to bring to first suitable blogmeet.

Borepatch said...

Unknown, yes that's the exact one.

Differ, I'd just say that splitting your driving between a Camaro (12 MPG) and a motorcycle (50+ MPG) might get you pretty close to a 31 MPG average. Just sayin'.

And I'd *love* to see your ride (with its new engine).