666
submitted 10 months ago by L4s@lemmy.world to c/technology@lemmy.world

Detroit man steals 800 gallons using Bluetooth to hack gas pumps at station::undefined

you are viewing a single comment's thread
view the rest of the comments
[-] Eezyville@sh.itjust.works 32 points 10 months ago

Wait so they haven't caught them yet? The article gave no names. And why do these pumps have Bluetooth? You might as well put in a USB service port.

[-] foggy@lemmy.world 35 points 10 months ago

USB is way safer lol.

Bluetooth is notoriously bad with security. Especially Bluetooth 4 and earlier. I'd put money on a gas station pumps Bluetooth to not be using the most up to date protocol.

[-] MeanEYE@lemmy.world 51 points 10 months ago

It's like saying TCP has bad security. That is to say, pointless comparison. Bluetooth is just transport layer and security is done on higher level. This is most likely the classic example of "security through obscurity". Meaning they did nothing special and hoped no one will figure it out, just like recent TETRA vulnerability.

[-] carl_dungeon@lemmy.world 29 points 10 months ago

Come on now! The pumps required you to enter the secret pairing code: โ€œ12345โ€

[-] BarrelAgedBoredom@lemm.ee 19 points 10 months ago

You fool! It was 00000, now you'll never have free gas!

[-] foggy@lemmy.world 18 points 10 months ago* (last edited 10 months ago)

Transport layer is absolutely a security vulnerability vector.

TCP is absolutely low security if not configured correctly.

I don't know what it is you're trying to say. I agree that this instance was probably security through obscurity failing, but to say that Bluetooth, TCP, and other transport layer protocols are not security considerations is absolutely ridiculous (see for example, heartbleed). It's exactly the reason there are multiple versions of Bluetooth. It's why FTP is (should be) all but deprecated and SFTP and FTPS are standard. It's why Google doesn't index webpages without an SSL certificate.

USB is way safer

[-] MeanEYE@lemmy.world 2 points 10 months ago

Of course wired connection is inherently safer than wireless. There's no question about it. And yes you can absolutely exploit at every layer of communication, but this here is not the case of exploiting Bluetooth as transport layer. It's simply someone not configuring anything or adding any additional verification and just hoping no one finds out.

[-] foggy@lemmy.world -2 points 10 months ago

Okay, but your claim that my comparing Bluetooth to USB being like comparing Bluetooth to TCP is misinformed at best.

[-] MeanEYE@lemmy.world 1 points 10 months ago

My comment had nothing to do with Bluetooth vs. USB comparison. I only said Bluetooth is a transport layer and claiming it's "notoriously bad security" is not all that correct since most of the security parts come on top of it. So in many ways Bluetooth is quite similar to TCP, at least from point of communication. From the software point of view, both with Bluetooth and TCP, you create a socket then send and receive data through it. Literally the same interface. Protecting data that goes through either method is meant to be done at that point be it with encryption, identity verification, whatever.

Same thing applies to USB, but being physical it has added benefit of having to connect to it but that opens whole set of new potential issues. So it's easier to physically protect it, but should that protection fail, you might end up in even more trouble.

[-] foggy@lemmy.world 0 points 10 months ago

You can disable a USB port and require remote SSH to enable it.

USB is way safer.

[-] jarfil@lemmy.world 0 points 10 months ago

You can disable Bluetooth and require remote SSH to enable it... ๐Ÿ™„

BTW, have you heard about BadUSB?

[-] MeanEYE@lemmy.world 0 points 10 months ago

That then in turn complicates things and requires maintenance people to be educated, etc. It's possible to do authentication and handshakes properly without complicating matters. It just wasn't done.

[-] foggy@lemmy.world 2 points 10 months ago

It does not complicate things in a way that makes things less secure than using Bluetooth 4.0 or earlier.

USB is way safer.

It's amusing that you won't just give up and admit that the blanket statement is 100% accurate. But you do you; just remind me not to use any services that you're on the opsec team for.

[-] MeanEYE@lemmy.world 0 points 10 months ago

Am just telling you there are ways to do security properly and make it good, be it Bluetooth, WIFI, GSM, LAN or USB. There's no such thing as blanket 100% correct statements. I distinctly remember security issues with USB when protocol allowed DMA access which was used to leak all kinds of important data. Luckily it was patch fast, but that is the doing security properly part. There's nothing completely secure in this world.

[-] foggy@lemmy.world 1 points 10 months ago

And you still won't agree to the simple and obvious truth that USB is way safer than Bluetooth 4.0 or earlier. Nice.

You do you.

[-] MeanEYE@lemmy.world 0 points 10 months ago

Why would I agree to something that's not correct. You just pulled that out of your ass and claiming it's true.

[-] sturmblast@lemmy.world -4 points 10 months ago
[-] foggy@lemmy.world -1 points 10 months ago

Ah, brilliant. Another expert.

Yes, it is how it works. Cheers.

[-] some_designer_dude@lemmy.world 5 points 10 months ago

This is the kind of rigorous debate Iโ€™m here for.

[-] ScreamingFirehawk@feddit.uk 18 points 10 months ago

At least you can lock a usb port behind an access panel

this post was submitted on 03 Oct 2023
666 points (97.4% liked)

Technology

57226 readers
4731 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS