Elektrine lite

← Feed

@ryanboswell@sfba.social

Post #3980142

2026-07-21 03:57 UTC

I likely comes as no surprise that at least some EV charging infrastructure has been rolled out with laughably bad security. The fact that someone could probably cause significant damage to the local power grid or plant malware for future vehicles connected with very little real effort is wild, especially since many chargers are in only minimally protected public spaces. It’s like being able to stick in a specially formatted debit card and suddenly have full access to a bank’s entire internal system. https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers

Replies (5)

  • @hanscees@ieji.de 2026-07-21 08:20

    @ryanboswell@sfba.social and how difficult would it be to plant ☘️ an malware thingy that attacks cars in this way? #infosec #iot

    Open ##4012299

  • @ryanboswell@sfba.social > "hidden attack surface" > not hidden

    Open ##4038718

  • @jmcrookston@mastodon.social 2026-07-21 12:26

    @ryanboswell@sfba.social So I opened the article expecting some kind of malware attack needed but nope the charger is just completely open to root access. Okay. "An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage."

    Open ##4038721

  • @ryanboswell@sfba.social the UK's PSTI bans default credentials in consumer IOT devices, but exempts EV chargers that are covered by Electric Vehicles (Smart Charge Points) Regulations 2021: https://www.schneier.com/blog/archives/2024/05/the-uk-bans-default-passwords.html The EV Smart Charger regulation does also require unique passwords per charger if present, however. https://www.legislation.gov.uk/uksi/2021/1467/schedule/1/made Thus these chargers would be illegal in the UK.

    Open ##4210545

  • @Jirikiha@raphus.social 2026-07-21 16:55

    @ryanboswell@sfba.social "It’s like being able to stick in a specially formatted debit card and suddenly have full access to a bank’s entire internal system." Now, just to be clear, have we ruled out the possibility that debit cards could be programmed to gain access to the banks's or the ATM's system?

    Open ##4210549