Showing posts with label Security Patches. Show all posts
Showing posts with label Security Patches. Show all posts

Friday, 7 August 2015

Tesla Model S Patches Vulnerabilities Via Update


Cars manufacturer Tesla is well protected against hacking, according to two researchers who eventually painstakingly did manage to hack a Tesla Model S. Marc Rogers of CloudFlare and Kevin Mahaffey of Lookout Mobile found a total of six vulnerabilities in the Tesla, as they leave today via a blog posting know. The two researchers will present their findings this week at the Def Con conference presenting in Las Vegas.

For the study, about two years confiscated, they had to get the car literally falling apart. Through the vulnerabilities they had full control of the infotainment system of the vehicle. They then installed malware was remotely controlled and which they could carry out all actions that could also be implemented through the touchschreen or smartphone app of the Tesla. Thus it was possible to switch from the car while it was driving, so the examiner opposite Forbes know.

In addition to the required physical access to the researchers discovered that it was possible to attack the remote infotainment system. The system used a vulnerable browser, with a four year old WebKit vulnerability, reports Wired . This allows an attacker would the car remotely attacks as a Tesla user from the car a malicious website would visit. In this case it would also be possible to start the engine remotely or turn off.

However, the researchers discovered that Tesla had introduced a security measure. In case the engine is switched off when the car is driving, the brake is activated and stop the car if the speed falls below 8 km per hour. The researchers reported the problems to Tesla, which has delivered an update. Unlike Chrysler, which because of security issues had to recall 1.4 million cars so that they could be updated using a USB stick, Tesla updates brings "over-the-air" and require customers to bring their vehicle back to the dealer. However, they must accept the update, because there is no automatic installation location.

Saturday, 25 July 2015

Google: Consumers Wary Of Security Updates


Average Internet users are wary of security updates, and consider even mistaken as a security risk, according to research ( pdf ) from Google. The Internet giant decided the security behaviour of 231 294 security experts and Internet users who are not experts to compare.

For example, among other things, to the top five security measures take any consideration of both groups. It shows that average Internet users underestimate the importance of security updates seriously. 35% of the experts called to install security updates as a security measure, while only 2% of users doing this. As a result, the installation of the patches is a security measure, with the largest difference between users and experts.


Further research into this behaviour shows that 39% of the experts shows automatically install updates, while among users is 29%. In addition, 25% of the experts said that updates are installed immediately. When the user, this is done by only 9%.According to the researchers did not make installing updates as timely as possible with bad past experiences or that users do not realise its effectiveness.

Passwords

The study also shows that password management is important for both users and experts, but there different approaches are used. The experts often use password managers. The difference between experts and users is a factor of three. 24% of users said for some accounts using a password manager, while it is 73% of the experts. Furthermore, users will find anti-virus software very important, while experts prefer other measures.

"Our results show that experts and non-experts take various measures to protect themselves on the Internet. The action of the experts be experts considered good advice, while the actions of the non-experts get mixed reactions from experts," said the researchers. They argue that there is room for improvement when it comes to identifying the main security and to then make this clear to users.