27
27
Aug 1, 2021
08/21
by
BBCNEWS
tv
eye 27
favorite 0
quote 0
so, on wallbox, you could take full control of the charger. remove the usual owner's access on the charger. it could stop them from charging their own vehicles and provide free charging to an attacker vehicle. for the project ev, it's way worse because you can sideload finware, you can brick it, you can make it to be part a botnet and you could also make attack other servers. the problem in both cases is the lack of proper authentication between the mobile app on our smartphones often used to control these chargers and the computer servers that relay instructions to the boxes, known as apis. do you think it's an easy hack to do? could anyone do it? yes. well, the word "anyone" is quite broad, but anyone who understands apis could easily do it, yes. ken munro heads up pen test partners. after a quick charge—up, we went back to his place where he showed me something else particularly worrying. if you've got one of these chargers at home then you might be surprised to find this inside. ken and his team found a 2015 raspberry pi, more of an educat
so, on wallbox, you could take full control of the charger. remove the usual owner's access on the charger. it could stop them from charging their own vehicles and provide free charging to an attacker vehicle. for the project ev, it's way worse because you can sideload finware, you can brick it, you can make it to be part a botnet and you could also make attack other servers. the problem in both cases is the lack of proper authentication between the mobile app on our smartphones often used to...
38
38
Aug 6, 2021
08/21
by
BBCNEWS
tv
eye 38
favorite 0
quote 0
it told us: wallbox, based in spain, did not reply wallbox, based in spain, did not reply to us, buteam that they had fixed the online problems. time to see if the units are safe. retesting took place this week and suggests most of the problems in both chargers have been fixed. but ken says owners still need to take action. check for updates, solve the problem. the wallbox charger uses hardware that is not secure enough. there's really nothing you can do to make it completely secure. so unless wallbox have found a way of fixing that, which would be beyond me, i'd suggest perhaps supergluing it's worth noting that all smart home chargers will still be usable if you just want to plug yourcar in. but when it comes to security when using them with a phone app or home wi—fi, it seems some are smarter than others. that was dan, and more great work there from the "white hat" hackers, catching a problem before it ever really becomes one. now, iceland may be hot under the surface but it can get quite chilly up top, which is also pretty useful. back in 2018, we visited a cryptocurrency mining
it told us: wallbox, based in spain, did not reply wallbox, based in spain, did not reply to us, buteam that they had fixed the online problems. time to see if the units are safe. retesting took place this week and suggests most of the problems in both chargers have been fixed. but ken says owners still need to take action. check for updates, solve the problem. the wallbox charger uses hardware that is not secure enough. there's really nothing you can do to make it completely secure. so unless...
62
62
Aug 1, 2021
08/21
by
BBCNEWS
tv
eye 62
favorite 0
quote 0
so, on wallbox, you could take full control of the charger.nd remove the usual owner's access on the charger. it could stop them from charging their own vehicles and provide free charging to an attacker vehicle. and for the project ev, it's way worse because you can sideload finware, you can make it — you can brick it, you can make it to be part a modnet and you could also make attack other servers. make it attack other servers. the problem in both cases is the lack of proper authentication between the mobile app on our smartphones often used to control these chargers and the computer servers that relay instructions to the boxes�*. do you think it's an easy hike to do? could anyone do it? —— easy hack. yes. well, the word "anyone" is quite broad, but anyone who understands apis could easily do it, yes. ken munro heads up pen test partners. after a quick charge—up, we went back to his place where he showed me something else particularly worrying. if you've got one of these chargers at home, then you might be surprised to find this inside. ken a
so, on wallbox, you could take full control of the charger.nd remove the usual owner's access on the charger. it could stop them from charging their own vehicles and provide free charging to an attacker vehicle. and for the project ev, it's way worse because you can sideload finware, you can make it — you can brick it, you can make it to be part a modnet and you could also make attack other servers. make it attack other servers. the problem in both cases is the lack of proper authentication...
29
29
Aug 1, 2021
08/21
by
BBCNEWS
tv
eye 29
favorite 0
quote 0
so on wallbox, you could take full control of the charger.also make attack other servers. the problem in both cases is the lack of proper authentication between the mobile app on our smartphones often used to control these chargers and the computer servers that relay instructions to the boxes'. do you think it's an easy hike to do? could anyone do it? —— hack to do? yes. well, the word "anyone" is quite broad, but anyone who understands apis could easily do it, yes. ken munro heads up pen test partners. after a quick charge—up, we went back to his place where he showed me something else particularly worrying. if you've got one of these chargers at home, then you might be surprised to find this inside. ken and his team found a 2015 raspberry pi — more of an educational piece of hardware rather than something that you may want to rely on to store your details securely. get hold of one of these and because this is connected to your home by wi—fi, well then, you can get straight onto the home network. could let you do all sorts of things. shall w
so on wallbox, you could take full control of the charger.also make attack other servers. the problem in both cases is the lack of proper authentication between the mobile app on our smartphones often used to control these chargers and the computer servers that relay instructions to the boxes'. do you think it's an easy hike to do? could anyone do it? —— hack to do? yes. well, the word "anyone" is quite broad, but anyone who understands apis could easily do it, yes. ken munro...