Gone in 120 seconds: Tesla Model 3 child's play for hackers
- Reference: 1679916731
- News link: https://www.theregister.co.uk/2023/03/27/in_brief_security/
- Source link:
The prize was awarded at the annual Pwn2Own competition in Vancouver and it wasn't Synacktiv's only win. The team walked away from the competition with over half a million dollars in prize money after a series of cracks found not only in Tesla's armor but in that of established players too.
Ubuntu took a hammering, with three different teams finding critical flaws in the open source operating system. Windows 11 was also shown to have serious flaws and VMWare Workstation was also successfully cracked. Expect updates soon.
[1]
In all, over a million dollars was dished out to competitors, and software companies will now get fixes that could save much more than that if these issues got into the wrong hands. It's a win-win for the industry - proper hackers get a payday and the flaws aren't sold on to others.
[2]
[3]
"Contestants disclosed 27 unique zero days and won a combined $1,035,000 (and a car)!" [4]said Dustin Childs, Head of Threat Awareness, Zero Day Initiative at Trend Micro.
"Congratulations to the Masters of Pwn, Synacktiv ( [5]@Synacktiv ), for their huge success and hard work! They earned 53 points, $530,000, and a Tesla Model 3."
Twitter's source code leaked online
The troubled Twitter has [6]taken action after chunks of its source code were leaked online, despite its current owner promising to make the code open source at the end of this month.
Twitter will open source all code used to recommend tweets on March 31st — Elon Musk (@elonmusk) [7]March 17, 2023
The code was posted on GitHub and was taken down after being spotted, but appears to have been live for some months. Twitter is also asking GitHub to identify who posted the code and anyone who downloaded it, according to a filing in the US District Court for the Northern District of California.
[8]
This isn't going to help Twitter's value, which Musk admitted on Friday was around $20 billion, less than half what he had paid for the social network. However, he said the company could be worth $250 billion one day - although given Musk's loose deadlines that could take some time.
Login.gov accused of biometric balderdash
In the US, the Office of Inspector General (OIG) of General Services Administration (GSA), issued a [9]redacted report [PDF] earlier this month that found the government agency had misled its customers and other government agencies by telling them that Login.gov complied with NIST standards.
Per SP 800-63-3, Identity Assurance Level 2 (IAL2), "strong" identity verification calls for physical comparison to a photograph, or biometric comparison to the strongest available evidence (e.g. face image or selfie, iris, fingerprint). If done remotely, when physical comparison is not an option, IAL2 requires biometric comparison.
According to the OIG report, "18 of Login.gov's 22 interagency agreements executed from September 18, 2018 to July 7, 2021 stated that they included IAL2 services that met and/or were consistent with the IAL2 requirements." But Login.gov never actually supported the requirements.
[10]GitHub publishes RSA SSH host keys by mistake, issues update
[11]Police pounce on 'pompompurin' – alleged mastermind of BreachForums
[12]Europe, America fear Twitter job cuts mean it can't protect users
[13]Where are the women in cyber security? On the dark side, study suggests
The report says IAL2 non-compliance was a matter of discussion as early as 2019.
That discussion ended, according to the OIG report, when Vladlen "Dave" Zvenyach, former director of GSA's Technology Transformation Services (TTS), the group overseeing the development of the authentication service, determined that facial recognition via submitted selfies was discriminatory.
The agency's position states that facial recognition will not be implemented until it "can be implemented equitably and without causing disproportionate harm to vulnerable populations."
[14]
That plan, the OIG report says, "omitted any mention of the duration and nature of Login.gov's noncompliance with NIST's IAL2 requirements." It concluded "GSA knowingly billed customer agencies over $10 million for services, including alleged IAL2 services that did not meet IAL2 standards." ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCG9oQEBPz0mx8bMt0emZgAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCG9oQEBPz0mx8bMt0emZgAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCG9oQEBPz0mx8bMt0emZgAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.zerodayinitiative.com/blog/2023/3/24/pwn2own-vancouver-2023-day
[5] https://twitter.com/synacktiv
[6] https://www.nytimes.com/2023/03/26/technology/twitter-source-code-leak.html
[7] https://twitter.com/elonmusk/status/1636835209587949570?ref_src=twsrc%5Etfw
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCG9oQEBPz0mx8bMt0emZgAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.gsaig.gov/sites/default/files/ipa-reports/GSA%20Misled%20Customers%20on%20Login.gov%27s%20Compliance%20with%20Digital%20Identity%20Standards%20%28JE23-003%29_Redacted.pdf
[10] https://www.theregister.com/2023/03/24/github_changes_its_ssh_host/
[11] https://www.theregister.com/2023/03/20/in_brief_security/
[12] https://www.theregister.com/2023/03/08/eu_us_regulators_concerned_twitter/
[13] https://www.theregister.com/2023/03/06/in_brief_security/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCG9oQEBPz0mx8bMt0emZgAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Re: Expect updates soon
Any software or OS vendor (and I count Microsoft, Apple and Google in that) worth their salt should have coders and other techies there. Hopefully, we'll get patches for a lot of stuff relatively soon.
Re: Expect updates soon
With MS, would we even notice the extra patches? It's nearly Patch Tuesday again!
With Google, it seems to be down to device manufactures, so not holding my breath (although my Samsung A12 just got another update last week!)
With Apple, I have no clue. I've not properly used an Apple computer since I played with an Apple ][ many years ago :-)
@T. F. M. Reader - Re: Expect updates soon
Nobody cares, security is always an afterthought. Otherwise we would see more OpenBSD-like systems around. And this is not a bad thing, there's a lot of money to be made.
Re: @T. F. M. Reader - Expect updates soon
It's been said many times before but Open BSD is likely only secure because it's so obscure. Nobody tries to find flaws because there's no mileage in finding them. In order for it to be worthwhile spending time breaking into a system there needs to be a large installed base.
Re: @T. F. M. Reader - Expect updates soon
Oh dear. How little you understand.
OpenBSD is specifically used in some places of high value. Some commercial firewalls are based on OpenBSD, i.e. at the first line of network defence. If you think there is no mileage in finding holes in firewalls, go back to security school.
Why Musk is upset that Twitter's source has leaked? Didn't he promise to open source the algorithms? *
* Yes, pedants. I know there's a difference between algorithms and code. But does Musk? And the effect is the same: Twitter's algorithms are now open sourced.
Take your pick......
Quote: ' It concluded "GSA knowingly billed customer agencies over $10 million for services, including alleged IAL2 services that did not meet IAL2 standards." '
Ha.......a mistake........or incompetence......or deliberate lying? Surely not lying!! No!! No!! ........
They found serious security flaws in Tesla cars and won....
A brand new Tesla car. Never mind, you might not have it all that long, as a succession of other people "win" it who've done the same.
Expect updates soon
Ubuntu took a hammering... Windows 11 was also shown to have serious flaws and VMWare Workstation was also successfully cracked.
OK, interesting and important. It would also be interesting whether there were any OSes/systems/platforms/whatever that were not cracked despite the attempts. Or were there none?