Post #3963556
2026-07-20 15:40 UTC
Replies (6)
-
@syphist@zoner.work 2026-07-20 16:26
@vogelchr@chaos.social @faheus@chaos.social this is so insane. How do they make so many critical mistakes when setting up something like this?
-
@Viss@mastodon.social 2026-07-20 17:37
@vogelchr@chaos.social @faheus@chaos.social fucking outstanding
-
@cR0w@infosec.exchange 2026-07-20 18:08
@vogelchr@chaos.social @faheus@chaos.social This entire class of devices is ridiculously vulnerable. I tracked a bunch of the vuln reports for a while and my company finally told me to leave them alone. We're not allowing them to touch our networks.
-
@dirkhh@social.afront.org 2026-07-20 17:25
@vogelchr@chaos.social @faheus@chaos.social That is too funny for words. Security. You should try it sometimes,
-
@landelare@mastodon.gamedev.place 2026-07-20 17:51
@vogelchr@chaos.social @faheus@chaos.social My brain's naturally-developed slop filter discarded this one immediately. :(
-
@forthy42@mastodon.net2o.de 2026-07-20 18:08
@vogelchr@chaos.social @faheus@chaos.social I did some charger communication stack stuff with a Chinese startup, i.e. GB/T. Communication is just using CAN bus as usual for cars. Looked all familiar. Of course, CAN bus is no way secure, encrypted or whatever. It's local communication over a large plug that is physically locked to the vehicle, so don't care. The other side has dedicated firmware only for that single purpose. When I figured out what the European industry does, with a powerline modem, a full TPC/IP stack, and well “let's connect some embedded Linux boards to it”, it was obvious what would happen.