WEBVTT - The Wheels on the CAN Bus: Car Hacks

0:00:00.480 --> 0:00:03.400
<v Speaker 1>Ridiculous Crime. It's a production of iHeartRadio.

0:00:03.600 --> 0:00:08.840
<v Speaker 2>Zaren Burnette. We meet again, Elizabeth Dunton. How you doing good?

0:00:09.360 --> 0:00:10.160
<v Speaker 2>So good to see you.

0:00:10.200 --> 0:00:12.080
<v Speaker 3>Interns told me you're going to be early, and I

0:00:12.119 --> 0:00:13.119
<v Speaker 3>was like, well, I'm going to be late.

0:00:15.760 --> 0:00:18.720
<v Speaker 2>You're looking sharp today in your little stress mariner's shirt.

0:00:19.840 --> 0:00:21.160
<v Speaker 3>I'm like a French mariner over here.

0:00:21.200 --> 0:00:22.960
<v Speaker 2>I love it. It's cute. I'm gonna get you a

0:00:23.040 --> 0:00:28.720
<v Speaker 2>can of sardine. Make your day quick question. Sure you

0:00:28.760 --> 0:00:29.680
<v Speaker 2>know what's ridiculous?

0:00:29.800 --> 0:00:30.280
<v Speaker 3>I do.

0:00:30.960 --> 0:00:31.040
<v Speaker 4>So.

0:00:31.560 --> 0:00:33.440
<v Speaker 3>Hearkening back to when I was telling you about the

0:00:33.479 --> 0:00:37.080
<v Speaker 3>Buddhist monks, I mentioned about Stevie Wonder going around at

0:00:37.080 --> 0:00:38.640
<v Speaker 3>the Shaolin temple and it's like, oh, he must have

0:00:38.640 --> 0:00:41.120
<v Speaker 3>been enjoying listening to the temple. If you ever heard

0:00:41.120 --> 0:00:43.760
<v Speaker 3>the theory that Stevie Wonder actually can see, I have right,

0:00:43.760 --> 0:00:45.479
<v Speaker 3>there's a lot of celebrities have talked about it.

0:00:45.600 --> 0:00:45.960
<v Speaker 2>Yeah.

0:00:46.000 --> 0:00:48.040
<v Speaker 3>So I have one here that I think is just

0:00:48.159 --> 0:00:50.240
<v Speaker 3>absolutely not proof positive.

0:00:49.800 --> 0:00:51.440
<v Speaker 2>But there's some interesting video proof.

0:00:51.600 --> 0:00:54.720
<v Speaker 3>It's interesting. Yeah. So Elton John has this evidence that

0:00:54.760 --> 0:00:57.000
<v Speaker 3>Stevie Wonder may be able to see. That I thought

0:00:57.080 --> 0:00:59.440
<v Speaker 3>was very convincing because the two of them happened to

0:00:59.440 --> 0:01:01.560
<v Speaker 3>be Colorado at the same time, and they, you know,

0:01:01.640 --> 0:01:03.640
<v Speaker 3>kind of bumped into each other. That's not the evidence

0:01:03.960 --> 0:01:07.520
<v Speaker 3>they were Basically they did a snowmobile tour. But I'll

0:01:07.560 --> 0:01:10.880
<v Speaker 3>let out and John tell the story. Quote musicians passing

0:01:10.880 --> 0:01:13.880
<v Speaker 3>through Denver or Boulder would drop by to visit. Stevie

0:01:13.920 --> 0:01:16.280
<v Speaker 3>Wonder turned up one day and took out a snowmobile,

0:01:16.600 --> 0:01:20.319
<v Speaker 3>insisting on driving it himself. Now, to preempt your question, no,

0:01:20.520 --> 0:01:23.480
<v Speaker 3>I have no idea how Stevie Wonder successfully piloted a

0:01:23.480 --> 0:01:26.920
<v Speaker 3>snowmobile through the rocky mountains of Colorado without killing himself

0:01:27.040 --> 0:01:30.280
<v Speaker 3>or indeed anyone else in the process. But he did.

0:01:30.800 --> 0:01:34.000
<v Speaker 2>And it's not like it's a Stevie's house, No, he just.

0:01:33.880 --> 0:01:36.679
<v Speaker 3>Like he doesn't know this track. He is not like, oh,

0:01:36.720 --> 0:01:39.920
<v Speaker 3>I've got this worked out. He took. Yeah, he went

0:01:39.920 --> 0:01:42.560
<v Speaker 3>out there and drove a snowmobile. Like, I don't think

0:01:42.600 --> 0:01:45.120
<v Speaker 3>I could do that that well and not run the

0:01:45.200 --> 0:01:49.400
<v Speaker 3>risk of bumping into something apparently flawless Stevie Rascal. So

0:01:49.440 --> 0:01:51.680
<v Speaker 3>I'm just saying, is there's an interesting one can.

0:01:51.680 --> 0:01:55.440
<v Speaker 2>Be like you can be like technically blind.

0:01:55.520 --> 0:01:59.000
<v Speaker 3>Right, you know, I guess varying degrees of Yeah, there's.

0:01:58.840 --> 0:02:01.720
<v Speaker 2>Different levels of blind, so it might not be completely

0:02:01.880 --> 0:02:02.160
<v Speaker 2>you know.

0:02:02.240 --> 0:02:05.520
<v Speaker 3>Yeah, so much like UFOs and UAPs. I'm keeping an

0:02:05.520 --> 0:02:07.840
<v Speaker 3>open mind about Stevie wonder whether or not.

0:02:09.720 --> 0:02:13.560
<v Speaker 2>Wow, there you go, very ridiculous, right, that is ridiculous.

0:02:13.800 --> 0:02:14.560
<v Speaker 3>John always got the.

0:02:14.480 --> 0:02:18.320
<v Speaker 2>Tea, always always. Do you want to know what else

0:02:18.360 --> 0:02:18.959
<v Speaker 2>is ridiculous?

0:02:19.000 --> 0:02:19.320
<v Speaker 3>Please?

0:02:19.840 --> 0:02:44.519
<v Speaker 2>Hacking a car? Bro This is Ridiculous Crime, A podcast

0:02:44.600 --> 0:02:49.519
<v Speaker 2>about absurd and outrageous capers. Heis and cons It's always

0:02:49.560 --> 0:02:53.279
<v Speaker 2>ninety nine percent murder free and one hundred percent ridiculous.

0:02:53.440 --> 0:02:54.440
<v Speaker 3>I know you done heard that.

0:02:54.720 --> 0:02:58.120
<v Speaker 2>I done heard it so many times. Hi, Elizabeth, Hey,

0:02:58.400 --> 0:03:01.680
<v Speaker 2>my name is Werner Brandis my voice? Is my passport?

0:03:02.040 --> 0:03:02.600
<v Speaker 2>Verify me?

0:03:03.440 --> 0:03:04.079
<v Speaker 3>Excuse me?

0:03:04.160 --> 0:03:05.080
<v Speaker 2>Do you know what that's from?

0:03:05.320 --> 0:03:07.400
<v Speaker 3>No, that's right, Zaren.

0:03:07.440 --> 0:03:12.480
<v Speaker 2>You're correct. It's one of my all time favorite movies. Sneakers.

0:03:12.760 --> 0:03:16.400
<v Speaker 2>Oh Hi, my name is Werner Brandis my voice? Is

0:03:16.440 --> 0:03:18.080
<v Speaker 2>my passport? Verify me?

0:03:18.280 --> 0:03:19.399
<v Speaker 3>Is it like a security check?

0:03:19.600 --> 0:03:21.959
<v Speaker 2>Yeah? So if you haven't seen have you seen Sneakers?

0:03:22.120 --> 0:03:24.760
<v Speaker 3>Yeah? But way back in the day, watch it again.

0:03:24.600 --> 0:03:27.320
<v Speaker 2>Because I love it so much. Yeah, it's like a

0:03:27.440 --> 0:03:33.600
<v Speaker 2>voice cod werner brandeis He's like a He's a tech guy,

0:03:34.160 --> 0:03:37.080
<v Speaker 2>uh an executive at this tech company, and so it's

0:03:37.080 --> 0:03:40.960
<v Speaker 2>a voice recognition, and so they needed to make a

0:03:41.040 --> 0:03:44.440
<v Speaker 2>recording of his voice to sneak in without him the

0:03:44.520 --> 0:03:49.240
<v Speaker 2>protagonists in this film, and anyway, they so they record him,

0:03:49.240 --> 0:03:51.360
<v Speaker 2>but they get like a honey trap. This woman has

0:03:51.400 --> 0:03:54.200
<v Speaker 2>to go and like get him to say these words

0:03:54.200 --> 0:03:57.720
<v Speaker 2>so they can piece it together on a blind date.

0:03:57.760 --> 0:04:00.280
<v Speaker 2>And so she's like, oh, you know what word, I love?

0:04:00.640 --> 0:04:04.520
<v Speaker 2>Passport And he's like, passport. So when it gets played back,

0:04:04.520 --> 0:04:08.240
<v Speaker 2>my voice is my passport. Anyway, I love that movie.

0:04:08.480 --> 0:04:11.040
<v Speaker 2>It's the story of some former and like side gig

0:04:11.080 --> 0:04:15.760
<v Speaker 2>hackers who do what's called penetration testing for tech security

0:04:15.760 --> 0:04:19.680
<v Speaker 2>at companies. White hat hackers. They use their powers for good,

0:04:19.720 --> 0:04:22.960
<v Speaker 2>although I believe they'd be gray hat hackers in some sense.

0:04:23.000 --> 0:04:24.000
<v Speaker 3>What's the distinction there?

0:04:24.040 --> 0:04:26.640
<v Speaker 2>A gray hat hacker is someone who engages in hacking

0:04:26.680 --> 0:04:31.160
<v Speaker 2>activities without permission, but their intentions are not always malicious,

0:04:31.200 --> 0:04:34.920
<v Speaker 2>and they may include reporting vulnerabilities you know, that they

0:04:34.960 --> 0:04:38.960
<v Speaker 2>find in these targeted organizations or even like to the public.

0:04:39.040 --> 0:04:41.040
<v Speaker 3>So if they break into to the Department of Defense

0:04:41.040 --> 0:04:43.440
<v Speaker 3>and then leave a note I found exactly and I

0:04:43.440 --> 0:04:44.279
<v Speaker 3>can tell you how I did.

0:04:44.279 --> 0:04:48.360
<v Speaker 2>Precisely, and they can exploit vulnerabilities for like personal gain

0:04:48.480 --> 0:04:51.800
<v Speaker 2>or demonstrate a point, you know, either way. In Sneakers,

0:04:51.839 --> 0:04:54.440
<v Speaker 2>the team which is led by Robert Redford, they go

0:04:54.520 --> 0:04:59.040
<v Speaker 2>up against Redford's old altruist college hacking buddy turned power

0:04:59.120 --> 0:05:02.239
<v Speaker 2>hungry tech villain, and there's some great hack in along

0:05:02.279 --> 0:05:02.560
<v Speaker 2>the way.

0:05:02.960 --> 0:05:06.560
<v Speaker 3>They hack it up, side it up. Oh, he's so good.

0:05:06.360 --> 0:05:10.479
<v Speaker 2>In that, Yeah, dan Ackroyd, that's right, hacking, hacking, so

0:05:10.640 --> 0:05:16.239
<v Speaker 2>much hacking, River Phoenix Hacking. I was thinking about that movie,

0:05:16.640 --> 0:05:20.520
<v Speaker 2>as I do sometimes when, and it got me thinking

0:05:20.560 --> 0:05:24.760
<v Speaker 2>about white hat hackers, those who used to hack illegally

0:05:25.000 --> 0:05:27.320
<v Speaker 2>for profit and or power, and then they go straight

0:05:27.680 --> 0:05:30.880
<v Speaker 2>and they help the authorities bust back the Yeah. I

0:05:31.000 --> 0:05:34.680
<v Speaker 2>like that idea. One of the most annoying characters on television,

0:05:34.920 --> 0:05:39.720
<v Speaker 2>Penelope on Criminal Minds, was a bad hacker. Yeah, and

0:05:39.760 --> 0:05:41.919
<v Speaker 2>then she was recruited by the FBI to hack the

0:05:41.960 --> 0:05:45.600
<v Speaker 2>world in pursuit of horrible violent criminals. And then they

0:05:45.640 --> 0:05:48.000
<v Speaker 2>also needed her to like teeter around the office in

0:05:48.040 --> 0:05:51.800
<v Speaker 2>clown costumes, Yeah, spouting out like stale slang while holding

0:05:51.839 --> 0:05:55.320
<v Speaker 2>something from the Archie McFee cap her. Oh I can't.

0:05:55.440 --> 0:05:57.360
<v Speaker 2>Like she's just running around with a rubber chicken pen

0:05:57.440 --> 0:05:58.560
<v Speaker 2>with a feather puff at the end.

0:05:58.680 --> 0:05:59.960
<v Speaker 3>What a rubber chicken?

0:06:00.320 --> 0:06:02.039
<v Speaker 2>Doesn't that sound like something she'd hash.

0:06:02.120 --> 0:06:03.160
<v Speaker 3>That's some real clan behavior.

0:06:03.240 --> 0:06:06.480
<v Speaker 2>Yeah it is. Anyway, I was poking around with the hackers,

0:06:06.520 --> 0:06:10.480
<v Speaker 2>basically hacking my way through Google's lousy search model, and

0:06:10.520 --> 0:06:13.800
<v Speaker 2>I found something. I caught a case there. I caught

0:06:13.839 --> 0:06:16.080
<v Speaker 2>a couple of cases. I think you're gonna like them. Please,

0:06:16.240 --> 0:06:19.320
<v Speaker 2>I should warn you that, just like the last time

0:06:19.360 --> 0:06:20.800
<v Speaker 2>I told you about hacking.

0:06:20.480 --> 0:06:22.560
<v Speaker 3>Crime, you got hacked.

0:06:23.440 --> 0:06:26.680
<v Speaker 2>No, I'm going to use a lot of technical language.

0:06:27.400 --> 0:06:29.080
<v Speaker 2>Much of it is going to go over your pretty

0:06:29.120 --> 0:06:32.560
<v Speaker 2>little head. Probably don't be intimidated, like some of us

0:06:32.600 --> 0:06:34.240
<v Speaker 2>are just more tech savvy and smarter.

0:06:34.400 --> 0:06:35.360
<v Speaker 3>No, it's very to true.

0:06:35.560 --> 0:06:39.000
<v Speaker 2>So I'm going to use terms like hacking and mainframe

0:06:39.800 --> 0:06:40.880
<v Speaker 2>and motherboard.

0:06:41.320 --> 0:06:43.520
<v Speaker 3>Are these terms like DJ's used like a motherboard? I'm

0:06:43.520 --> 0:06:44.279
<v Speaker 3>on my motherboard?

0:06:44.320 --> 0:06:46.800
<v Speaker 2>The ones and two, database and network? Have you heard

0:06:46.800 --> 0:06:47.320
<v Speaker 2>those before?

0:06:47.440 --> 0:06:50.920
<v Speaker 3>No? None of the all new to me keyboard keyboard?

0:06:50.920 --> 0:06:52.880
<v Speaker 3>Oh like oh yeah, like with the with the piano

0:06:53.040 --> 0:06:54.560
<v Speaker 3>correct correct USB drive?

0:06:55.480 --> 0:06:58.240
<v Speaker 2>Nope, Like I said, I don't want you to be intimidated.

0:06:58.320 --> 0:07:01.520
<v Speaker 2>The truth is that I has but a tenuous grasp

0:07:01.640 --> 0:07:05.120
<v Speaker 2>on all of those concepts and the items myself. So

0:07:05.160 --> 0:07:06.800
<v Speaker 2>we're on this digital journey together.

0:07:07.240 --> 0:07:08.920
<v Speaker 3>You do know, I have a bunch of friends who

0:07:08.920 --> 0:07:11.400
<v Speaker 3>are like hardcore, and then they talk to me about

0:07:11.440 --> 0:07:13.240
<v Speaker 3>stuff and I'm like, I use yellow legal pads. I

0:07:13.240 --> 0:07:14.360
<v Speaker 3>don't know what you're talking about.

0:07:14.480 --> 0:07:17.120
<v Speaker 2>No, I'm just like, you know, I'm like, why isn't

0:07:17.120 --> 0:07:21.800
<v Speaker 2>everything opening? Oh, I'm not connected to the internet. Cars,

0:07:22.600 --> 0:07:25.040
<v Speaker 2>I'm not talking about the Pixar movies there and back up,

0:07:25.440 --> 0:07:30.800
<v Speaker 2>I was like, you're going to I'm talking about the

0:07:30.800 --> 0:07:35.120
<v Speaker 2>things we drive down the street. Cars are full of

0:07:35.200 --> 0:07:38.960
<v Speaker 2>micro chips totally. And wasn't that part of the supply

0:07:39.040 --> 0:07:41.320
<v Speaker 2>chain issue during the early days of COVID, Remember there

0:07:41.360 --> 0:07:44.160
<v Speaker 2>was like the chip shortage for new cars and that's

0:07:44.360 --> 0:07:45.880
<v Speaker 2>like the cost of new cars.

0:07:45.880 --> 0:07:48.320
<v Speaker 3>And then cars they have all the screens.

0:07:48.360 --> 0:07:51.440
<v Speaker 2>Now they got like a forty inch television screen smack

0:07:51.480 --> 0:07:52.360
<v Speaker 2>in the middle of the dash.

0:07:53.240 --> 0:07:53.840
<v Speaker 3>Video games.

0:07:54.560 --> 0:07:56.840
<v Speaker 2>Yeah, you can't text and drive. That's good, but you

0:07:56.840 --> 0:07:59.880
<v Speaker 2>can have a small TV like in your lap drive.

0:08:00.640 --> 0:08:01.480
<v Speaker 3>You're making.

0:08:03.520 --> 0:08:07.440
<v Speaker 2>In some cars that'll remain nameless. It's on those screens.

0:08:07.520 --> 0:08:09.680
<v Speaker 2>We have to do stuff like adjust the AC or

0:08:09.720 --> 0:08:11.040
<v Speaker 2>like put on the turn signal.

0:08:11.080 --> 0:08:12.880
<v Speaker 3>I've heard about this, Yes, that's the wild one.

0:08:12.920 --> 0:08:14.560
<v Speaker 5>To screen.

0:08:14.600 --> 0:08:16.880
<v Speaker 2>You have to tell the car not to run over kids.

0:08:18.440 --> 0:08:21.840
<v Speaker 2>Run over fewer kids, you know, like we don't. We

0:08:21.880 --> 0:08:24.320
<v Speaker 2>don't have buttons anymore. I love buttons there, I like.

0:08:24.560 --> 0:08:25.720
<v Speaker 3>I even like knobs.

0:08:26.320 --> 0:08:29.360
<v Speaker 2>The best car I ever owned was in nineteen eighty

0:08:29.440 --> 0:08:32.720
<v Speaker 2>nine Ford Bronco. Yes, you're not a chip in sight.

0:08:32.960 --> 0:08:33.680
<v Speaker 3>No, I don't think so.

0:08:33.960 --> 0:08:36.120
<v Speaker 2>You could fix it with like a ball, peen hammer,

0:08:36.760 --> 0:08:40.520
<v Speaker 2>a butter knife and some electrical tape. Could It was perfect.

0:08:40.559 --> 0:08:43.720
<v Speaker 2>So now now I have this Subaru, right, I love it.

0:08:43.840 --> 0:08:44.920
<v Speaker 3>Yes, I've heard you talk about.

0:08:44.920 --> 0:08:47.480
<v Speaker 2>It has all sorts of not just chips and electronics,

0:08:47.520 --> 0:08:50.440
<v Speaker 2>but like online stuff. Oh really, I can lock and

0:08:50.559 --> 0:08:51.680
<v Speaker 2>unlock it with an app.

0:08:52.200 --> 0:08:54.000
<v Speaker 3>Do you use any of this? You know?

0:08:54.120 --> 0:08:56.320
<v Speaker 2>If I if I am already gone to bed and

0:08:56.320 --> 0:08:58.280
<v Speaker 2>I can't remember if I lock the car. Sometimes I just.

0:08:58.600 --> 0:08:59.679
<v Speaker 3>Check lock it.

0:08:59.240 --> 0:09:02.080
<v Speaker 2>I could start it remotely if I wanted from an app.

0:09:02.559 --> 0:09:04.360
<v Speaker 2>You can look on the app and see where it is.

0:09:04.480 --> 0:09:07.280
<v Speaker 2>It's like, oh it's in my driveway still, But like

0:09:07.440 --> 0:09:09.600
<v Speaker 2>if someone stole it, I can see where it was

0:09:09.640 --> 0:09:11.040
<v Speaker 2>and turn off the engine on them.

0:09:11.120 --> 0:09:13.360
<v Speaker 3>That's kind of fine like that, and then did would

0:09:13.360 --> 0:09:14.240
<v Speaker 3>they crash the car if you?

0:09:15.120 --> 0:09:17.079
<v Speaker 2>Yeah, Well, what do I care? I'm not in it?

0:09:18.600 --> 0:09:21.440
<v Speaker 3>Curious kind of like a good idea until you realize

0:09:21.480 --> 0:09:22.280
<v Speaker 3>what you've readen No.

0:09:22.280 --> 0:09:25.880
<v Speaker 2>I think it just boo powers down, no help, Okay,

0:09:25.960 --> 0:09:28.320
<v Speaker 2>I stole the wrong flashing lights come on and let's drive.

0:09:28.360 --> 0:09:30.880
<v Speaker 3>Other drivers know exactly.

0:09:31.200 --> 0:09:32.679
<v Speaker 2>It texts me when there's an.

0:09:32.640 --> 0:09:35.160
<v Speaker 3>Issue, used like a snarky tone.

0:09:35.200 --> 0:09:37.440
<v Speaker 2>I ran out of wiper fluid, and it kept reaching

0:09:37.440 --> 0:09:41.080
<v Speaker 2>out to me via text like a democratic fundraiser, totally

0:09:41.200 --> 0:09:43.360
<v Speaker 2>to let me know, like, hey, don't forget about me.

0:09:43.520 --> 0:09:45.680
<v Speaker 3>But is it like the duo lingo. It's kind of snarky,

0:09:45.720 --> 0:09:46.480
<v Speaker 3>like have you forgotten that?

0:09:46.480 --> 0:09:50.160
<v Speaker 2>It's very sincere and I just text back, wow, needy,

0:09:50.800 --> 0:09:54.600
<v Speaker 2>just keep going keyless entry peep peep. There was a

0:09:54.640 --> 0:09:57.640
<v Speaker 2>time recently here in Oakland where ladies were getting carjacked,

0:09:57.880 --> 0:10:01.080
<v Speaker 2>like up and down this very busy street near me,

0:10:01.800 --> 0:10:03.400
<v Speaker 2>and it seems to have calmed down, but it was

0:10:03.480 --> 0:10:07.640
<v Speaker 2>happening almost regularly for a while, like summer carjackings. Others

0:10:07.679 --> 0:10:09.720
<v Speaker 2>like guys would just run up, break the passenger window

0:10:09.760 --> 0:10:11.520
<v Speaker 2>and steal a purse on the seat.

0:10:11.600 --> 0:10:12.959
<v Speaker 3>Us like a spark plug break the window.

0:10:13.120 --> 0:10:16.080
<v Speaker 2>Yeah, and so for the carjacking. That's why I keep

0:10:16.080 --> 0:10:18.320
<v Speaker 2>my keys in my pocket when I'm driving instead of

0:10:18.360 --> 0:10:20.600
<v Speaker 2>like in my bag or like the cup holder, because

0:10:20.640 --> 0:10:22.439
<v Speaker 2>if I have my keys on me and they forced

0:10:22.480 --> 0:10:24.280
<v Speaker 2>me out, they aren't going to get very far because

0:10:24.280 --> 0:10:28.920
<v Speaker 2>you has to be close to the car to run, Sarah,

0:10:28.920 --> 0:10:31.120
<v Speaker 2>and you have to stay on the ball, keep your

0:10:31.160 --> 0:10:33.760
<v Speaker 2>head on a swivel. I don't think Subaru foresters are

0:10:33.760 --> 0:10:36.560
<v Speaker 2>like the hot Cardiff steal, but you never know.

0:10:38.320 --> 0:10:38.480
<v Speaker 6>So.

0:10:38.679 --> 0:10:42.199
<v Speaker 2>And that's another peril of the keiless entry fob is

0:10:42.240 --> 0:10:45.480
<v Speaker 2>that people can buy devices that clone keys to use.

0:10:45.320 --> 0:10:47.160
<v Speaker 3>For stealing the RFD.

0:10:47.480 --> 0:10:49.760
<v Speaker 2>Yeah, they walk by houses at night with a thing

0:10:49.880 --> 0:10:53.080
<v Speaker 2>and they can, you know, the hackens and they pick

0:10:53.160 --> 0:10:55.280
<v Speaker 2>up a signal from the keyfob and then they can

0:10:55.400 --> 0:10:56.520
<v Speaker 2>use that to start the car out.

0:10:56.840 --> 0:10:59.520
<v Speaker 3>They're buddy holding up like a wire and they're like

0:10:59.520 --> 0:11:01.439
<v Speaker 3>trying to get I would have thought it was a.

0:11:01.400 --> 0:11:04.680
<v Speaker 2>Total urban legend, but I've seen home like break camera

0:11:04.720 --> 0:11:07.160
<v Speaker 2>stuff of it, and it happened not a couple of times,

0:11:07.200 --> 0:11:09.160
<v Speaker 2>not too far from me. So you know what I do.

0:11:09.280 --> 0:11:11.680
<v Speaker 2>I put my keys in a Faraday box by the door.

0:11:14.480 --> 0:11:14.960
<v Speaker 3>I love it.

0:11:15.040 --> 0:11:17.600
<v Speaker 2>I probably overreacting, but whatever, it's a cute box.

0:11:17.880 --> 0:11:21.800
<v Speaker 3>I'm anyway, Yes, plants on it. You can override a

0:11:21.800 --> 0:11:22.640
<v Speaker 3>garden seed box.

0:11:22.800 --> 0:11:28.280
<v Speaker 2>Yes, no, it's very it's tasteful. It's brown and leathery.

0:11:28.280 --> 0:11:32.880
<v Speaker 2>There anyway. You can override the key with sentry. Other ways.

0:11:33.320 --> 0:11:37.000
<v Speaker 2>One involves a USB stick how so, but not in

0:11:37.040 --> 0:11:42.480
<v Speaker 2>the way you think, Zaren, I'm thinking nothing. It's physical hacking.

0:11:43.000 --> 0:11:45.559
<v Speaker 2>I'm sure you've heard of the Kia challenge.

0:11:45.679 --> 0:11:49.079
<v Speaker 3>Oh yes, okay, yes, this was a hacking.

0:11:49.160 --> 0:11:52.720
<v Speaker 2>I know, I totally did. It's a viral trend on TikTok.

0:11:52.760 --> 0:11:56.760
<v Speaker 2>In twenty twenty two is when it started. So people, okay, teens,

0:11:57.160 --> 0:11:59.160
<v Speaker 2>They learned how to steal certain Kia.

0:11:58.920 --> 0:12:01.199
<v Speaker 5>And Hyundai vehicle using only a.

0:12:01.240 --> 0:12:05.240
<v Speaker 2>USB cable and it started as this form of car theft,

0:12:05.280 --> 0:12:08.880
<v Speaker 2>but it quickly became a social media challenge, and like

0:12:09.080 --> 0:12:12.160
<v Speaker 2>vehicle thefts just surged across the US.

0:12:12.760 --> 0:12:15.000
<v Speaker 3>They just joy ride these cars, they don't write.

0:12:15.320 --> 0:12:18.560
<v Speaker 2>So they targeted Kias and Hyundais made between twenty ten

0:12:18.679 --> 0:12:19.679
<v Speaker 2>and twenty twenty one.

0:12:19.760 --> 0:12:20.240
<v Speaker 3>So that's a.

0:12:20.200 --> 0:12:24.520
<v Speaker 2>Pretty broad stretch. That's because they had traditional metal keys

0:12:24.559 --> 0:12:28.400
<v Speaker 2>not pushed to start, and the cars also didn't have immobilizers,

0:12:29.000 --> 0:12:32.079
<v Speaker 2>so those are like basic anti theft devices that keep

0:12:32.120 --> 0:12:36.160
<v Speaker 2>the engine from starting without the correct key. And apparently

0:12:36.200 --> 0:12:38.560
<v Speaker 2>the car alarm wouldn't go off if you broke the

0:12:38.600 --> 0:12:39.280
<v Speaker 2>back window.

0:12:39.960 --> 0:12:42.480
<v Speaker 3>Oh okay to know.

0:12:43.160 --> 0:12:45.840
<v Speaker 2>Yeah, what all that means is that it was possible

0:12:45.840 --> 0:12:48.000
<v Speaker 2>to get into the car without the alarm going off,

0:12:48.400 --> 0:12:51.640
<v Speaker 2>remove the steering column cover, use a USB cable or

0:12:51.679 --> 0:12:54.920
<v Speaker 2>anything shaped like it to turn the ignition switch, and

0:12:54.960 --> 0:12:56.280
<v Speaker 2>then start the car and drive away.

0:12:56.600 --> 0:12:57.920
<v Speaker 3>Oh you didn't have to like drop it down and

0:12:57.920 --> 0:12:58.600
<v Speaker 3>pull the wires out.

0:12:58.600 --> 0:13:03.480
<v Speaker 2>Oh no key. No hacking tools required. A group calling

0:13:03.520 --> 0:13:08.480
<v Speaker 2>themselves the Kia Boys posted videos anytime you put boys

0:13:08.520 --> 0:13:10.360
<v Speaker 2>in it, it's just you just took the wind out

0:13:10.400 --> 0:13:11.840
<v Speaker 2>of yourself. You know what I mean?

0:13:12.000 --> 0:13:14.400
<v Speaker 3>Kia Boys.

0:13:14.640 --> 0:13:16.520
<v Speaker 2>Yeah, I guess that is, but like proud Boys, No,

0:13:16.880 --> 0:13:21.600
<v Speaker 2>that's scary. They posted videos on TikTok and YouTube showing

0:13:21.600 --> 0:13:24.480
<v Speaker 2>how to steal the cars, like tutorials youtubes like keep

0:13:24.520 --> 0:13:27.679
<v Speaker 2>it Up Yeah Kia Boys tutorials. Other people copied them.

0:13:27.679 --> 0:13:31.360
<v Speaker 2>They turned it into this challenge. Some filmed themselves stealing

0:13:31.400 --> 0:13:33.599
<v Speaker 2>the cars and joy writing, and then they posted the

0:13:33.679 --> 0:13:34.600
<v Speaker 2>videos online.

0:13:34.679 --> 0:13:36.199
<v Speaker 3>Not only did they take the evidence that they made

0:13:36.200 --> 0:13:36.840
<v Speaker 3>it publicly avail.

0:13:37.000 --> 0:13:39.280
<v Speaker 2>Yes, we're talking about like, oh, don't write down your

0:13:39.280 --> 0:13:42.040
<v Speaker 2>plans for these guys are like watch it in four.

0:13:41.920 --> 0:13:43.480
<v Speaker 3>Kas and they were in like the shasty mass you

0:13:43.520 --> 0:13:44.280
<v Speaker 3>can't really see who they are.

0:13:44.440 --> 0:13:47.480
<v Speaker 2>Probably, so there was this huge spike in the thefts,

0:13:47.520 --> 0:13:51.040
<v Speaker 2>like I said, Milwaukee, La, Saint Louis Mania, all of them,

0:13:51.320 --> 0:13:54.920
<v Speaker 2>like some of these places that the car thefts increased

0:13:54.920 --> 0:13:58.439
<v Speaker 2>by like more than one hundred percent, and like I said,

0:13:58.640 --> 0:14:02.040
<v Speaker 2>big with the teens, a lot of the thieves were miners.

0:14:02.840 --> 0:14:06.880
<v Speaker 2>Law enforcement and community leaders went into like overdrive trying

0:14:06.880 --> 0:14:09.800
<v Speaker 2>to respond to this. My neighbor a couple of doors up,

0:14:09.840 --> 0:14:13.320
<v Speaker 2>had her Kia stolen three times, what yeah, three times,

0:14:13.520 --> 0:14:15.959
<v Speaker 2>so the cops would recover it in like an industrial

0:14:16.000 --> 0:14:19.240
<v Speaker 2>area uptown and she'd get the ignition repaired to how

0:14:19.280 --> 0:14:21.040
<v Speaker 2>it was before and then we could stolen again.

0:14:21.280 --> 0:14:23.800
<v Speaker 3>So they weren't really wrecking the car enjoy right now.

0:14:23.800 --> 0:14:26.800
<v Speaker 2>No, They're just scooted it around running and got trashed.

0:14:27.360 --> 0:14:29.320
<v Speaker 2>But for the most part they were just like pushing

0:14:29.320 --> 0:14:32.920
<v Speaker 2>it to Yeah, so there was a fix that the

0:14:32.960 --> 0:14:35.280
<v Speaker 2>dealership could do, but there were so many that the

0:14:35.320 --> 0:14:38.520
<v Speaker 2>parts were on back order for ages. Oh wow, So

0:14:38.520 --> 0:14:40.920
<v Speaker 2>then she got a club. But then one night some

0:14:41.040 --> 0:14:42.880
<v Speaker 2>ding dong broke into the car and tried to break

0:14:42.880 --> 0:14:46.680
<v Speaker 2>the club off with a rock. What. Yeah, he wasn't successful,

0:14:46.720 --> 0:14:50.040
<v Speaker 2>but he did get away. A cop came told him

0:14:50.080 --> 0:14:53.720
<v Speaker 2>to freeze, drew his weapon. Yeah, and the guy hopped

0:14:53.720 --> 0:14:56.160
<v Speaker 2>into another car and drove away around the cop.

0:14:56.280 --> 0:14:58.400
<v Speaker 3>What was the cop doing standing there.

0:14:58.320 --> 0:14:59.160
<v Speaker 2>With his weapon on it?

0:14:59.240 --> 0:15:01.400
<v Speaker 3>Like, why didn't pull a weapon fingers?

0:15:01.600 --> 0:15:04.360
<v Speaker 2>I think that the guy realized that the cop was

0:15:04.440 --> 0:15:06.840
<v Speaker 2>he's flying solo. He didn't have a partner with them.

0:15:07.280 --> 0:15:09.240
<v Speaker 2>The CoP's not going to open fire at two in

0:15:09.280 --> 0:15:11.960
<v Speaker 2>the morning with the possibility of hitting the houses behind

0:15:12.000 --> 0:15:13.720
<v Speaker 2>her in the air. I don't know. I watched the

0:15:13.720 --> 0:15:17.520
<v Speaker 2>whole thing from my front window and it was pretty

0:15:18.040 --> 0:15:20.080
<v Speaker 2>That was That's why I was telling you this part.

0:15:20.440 --> 0:15:22.960
<v Speaker 2>It was a ridiculous crime. It was one of the

0:15:22.960 --> 0:15:26.760
<v Speaker 2>most ridiculous things I've ever seen. And yeah, he just

0:15:27.000 --> 0:15:29.600
<v Speaker 2>swerved around and the cop put his hands down and

0:15:29.760 --> 0:15:33.800
<v Speaker 2>was just like the physical representation of dejections, Like he

0:15:33.920 --> 0:15:38.080
<v Speaker 2>just looked like now, he's got to go tell all

0:15:38.120 --> 0:15:42.680
<v Speaker 2>his pals. Yeah, so wow. There were class action lawsuits

0:15:42.680 --> 0:15:46.840
<v Speaker 2>filed against Hyundai and Kia. In twenty twenty three, the

0:15:46.840 --> 0:15:50.800
<v Speaker 2>carmakers offered free software updates to add anti theft features

0:15:50.840 --> 0:15:55.800
<v Speaker 2>like the immobilizer a longer alarm sound. They also gave

0:15:55.800 --> 0:15:58.520
<v Speaker 2>out steering wheel locks through police departments, so I guess

0:15:58.520 --> 0:15:59.800
<v Speaker 2>you could go to the cops and be like, I

0:15:59.800 --> 0:16:03.480
<v Speaker 2>need to club and they eventually settled the lawsuits for

0:16:03.480 --> 0:16:07.120
<v Speaker 2>around two hundred million dollars. Still going on though earlier

0:16:07.160 --> 0:16:10.600
<v Speaker 2>this year. In February of twenty twenty five, members of

0:16:10.760 --> 0:16:15.640
<v Speaker 2>Texas's Laredo Police Department Auto Theft Task Force. They detained

0:16:15.680 --> 0:16:20.120
<v Speaker 2>four boys ranging in age from thirteen to fifteen. There

0:16:20.200 --> 0:16:23.160
<v Speaker 2>was like the string of thefts. Two Kias and three

0:16:23.240 --> 0:16:26.560
<v Speaker 2>Hundays were actually stolen, but there were eleven other cases

0:16:26.600 --> 0:16:30.280
<v Speaker 2>where these fools tried to steal the cars and weren't successful.

0:16:30.800 --> 0:16:32.160
<v Speaker 2>They didn't watch the video all.

0:16:32.040 --> 0:16:33.600
<v Speaker 3>The way through their junior high kids.

0:16:34.400 --> 0:16:36.640
<v Speaker 2>Most of the cars that they hit were already unlocked,

0:16:36.840 --> 0:16:38.800
<v Speaker 2>which like, come on, I don't want a victim blame.

0:16:38.840 --> 0:16:43.400
<v Speaker 2>But they had the steering columns broken, the ignition switch broken, off.

0:16:43.920 --> 0:16:47.200
<v Speaker 2>All four of these boys were involved in all sixteen

0:16:47.280 --> 0:16:50.040
<v Speaker 2>of the cases, both the five successful in the eleven.

0:16:50.640 --> 0:16:54.040
<v Speaker 2>So I mean they caught counts like criminal attempt so

0:16:54.080 --> 0:16:57.760
<v Speaker 2>that's a misdemeanor, but like engaging in organized criminal activity

0:16:57.760 --> 0:17:02.240
<v Speaker 2>that's a felony left the state felonies, so they get

0:17:02.280 --> 0:17:05.040
<v Speaker 2>you know, all of these adam Yeah.

0:17:05.080 --> 0:17:05.240
<v Speaker 6>Right.

0:17:05.440 --> 0:17:08.040
<v Speaker 2>Criminal conspiracy cases like this can be found all over

0:17:08.080 --> 0:17:12.360
<v Speaker 2>the country, plus Australia and Canada, even the cool places

0:17:12.400 --> 0:17:15.800
<v Speaker 2>like that. The Canada ones are interesting because Canadian law

0:17:15.880 --> 0:17:19.640
<v Speaker 2>requires immobilizers in all new vehicles sold in Canada since

0:17:19.720 --> 0:17:22.000
<v Speaker 2>two thousand and seven, so that means that the ones

0:17:22.000 --> 0:17:24.000
<v Speaker 2>that were targeted were imported from the US.

0:17:24.960 --> 0:17:26.760
<v Speaker 3>How did they do I guess they just recognized.

0:17:28.000 --> 0:17:32.520
<v Speaker 2>Listen, let's pause for some ads. Brace yourself for savings.

0:17:33.160 --> 0:17:35.640
<v Speaker 2>When we come back, we're going to boost some more rides,

0:17:35.680 --> 0:18:01.200
<v Speaker 2>but this time was software, not hardware. Saren. I want

0:18:01.200 --> 0:18:04.960
<v Speaker 2>to introduce you to two dudes, two hack attackers, two

0:18:05.080 --> 0:18:07.879
<v Speaker 2>gray hat hackers who technically broke the law in an

0:18:07.920 --> 0:18:11.119
<v Speaker 2>effort to work for the greater good. So the first

0:18:11.119 --> 0:18:14.119
<v Speaker 2>guy is Charles Alfred Miller, Charlie Miller.

0:18:14.640 --> 0:18:17.880
<v Speaker 3>He got a handle a hacker handle, No, Charlie.

0:18:18.119 --> 0:18:22.480
<v Speaker 2>He's an American. He got a bachelor's in mass magna

0:18:22.520 --> 0:18:26.879
<v Speaker 2>cum loud from Northeast Misery State just now Truman State University.

0:18:27.240 --> 0:18:31.960
<v Speaker 2>Got a PhD in math from Notre Dame. He's basically

0:18:32.080 --> 0:18:33.920
<v Speaker 2>and that was in two thousand and he got his PhD.

0:18:33.960 --> 0:18:36.120
<v Speaker 2>He was like early on the learned to code train

0:18:36.200 --> 0:18:38.919
<v Speaker 2>it seems like it. Yeah, So he started his professional

0:18:38.960 --> 0:18:42.439
<v Speaker 2>career at the NSA and he worked as a cryptographer

0:18:42.520 --> 0:18:44.680
<v Speaker 2>slash codebreaker there for five years.

0:18:44.840 --> 0:18:45.800
<v Speaker 3>That's got to be fun and challenging.

0:18:45.840 --> 0:18:48.800
<v Speaker 2>I guess, well, sometimes when I do my cryptogram puzzles,

0:18:49.000 --> 0:18:51.399
<v Speaker 2>I wonder if the NSA is watching me through the

0:18:51.400 --> 0:18:54.080
<v Speaker 2>camera on my iPhone, and then I wonder if they'll

0:18:54.080 --> 0:18:56.080
<v Speaker 2>see how good I am at these puzzles. And then

0:18:56.080 --> 0:18:58.399
<v Speaker 2>my phone will ring. It'll be them asking me to

0:18:58.480 --> 0:19:00.520
<v Speaker 2>join the NSA team to be a hacker.

0:19:00.720 --> 0:19:02.320
<v Speaker 3>We put out the puzzles and we look for some

0:19:02.320 --> 0:19:03.200
<v Speaker 3>of the best.

0:19:03.880 --> 0:19:06.760
<v Speaker 2>We'll tell me about insurance and benefits and is the

0:19:06.800 --> 0:19:09.440
<v Speaker 2>position remote, and then they'll hang up on me because

0:19:09.480 --> 0:19:11.959
<v Speaker 2>they're looking for true patriots who aren't focused on their

0:19:11.960 --> 0:19:12.439
<v Speaker 2>own comfort.

0:19:12.520 --> 0:19:13.200
<v Speaker 3>Yeah, that's true.

0:19:13.240 --> 0:19:15.040
<v Speaker 2>I wonder about this sometimes, I.

0:19:14.760 --> 0:19:15.240
<v Speaker 3>Bet you do.

0:19:15.480 --> 0:19:15.879
<v Speaker 2>I do so.

0:19:15.960 --> 0:19:19.040
<v Speaker 3>Do you do these, by the way, on your phone? No?

0:19:19.119 --> 0:19:21.880
<v Speaker 2>I do them on paper. I can't have the government

0:19:21.920 --> 0:19:23.760
<v Speaker 2>seeing how good I am at cryptograms.

0:19:24.840 --> 0:19:26.520
<v Speaker 3>They would draft you in automatically.

0:19:26.680 --> 0:19:30.240
<v Speaker 2>I need my privacy. When he was in the NSA,

0:19:30.880 --> 0:19:36.920
<v Speaker 2>Miller conducted offensive computer security research. Offensive like on the offense,

0:19:37.040 --> 0:19:44.240
<v Speaker 2>not like oh god, gross, yeah, but his specific operations confidential,

0:19:44.560 --> 0:19:48.840
<v Speaker 2>of course, from my eyes only. He left the NSA

0:19:49.760 --> 0:19:52.400
<v Speaker 2>and then he served as a lead analyst at Independent

0:19:52.480 --> 0:19:53.680
<v Speaker 2>Security Evaluators.

0:19:53.800 --> 0:19:56.200
<v Speaker 3>Love those times, those companies and names like that, You're like, okay,

0:19:56.240 --> 0:19:57.120
<v Speaker 3>what yeah?

0:19:57.160 --> 0:19:59.240
<v Speaker 2>And then he later he worked for like he worked

0:19:59.280 --> 0:20:03.160
<v Speaker 2>for Twitter for while contributing to the information security team.

0:20:03.280 --> 0:20:06.000
<v Speaker 3>Like for like the NSA. Background. Who knows he's like

0:20:07.200 --> 0:20:07.840
<v Speaker 3>my former age.

0:20:08.000 --> 0:20:11.760
<v Speaker 2>Listen to this. He's a four time winner of the

0:20:12.000 --> 0:20:17.880
<v Speaker 2>pone to Own security competition. It's p wn numeral two.

0:20:18.160 --> 0:20:19.000
<v Speaker 6>O w N.

0:20:19.840 --> 0:20:21.080
<v Speaker 3>Do you know what I had to do?

0:20:21.080 --> 0:20:21.919
<v Speaker 5>You know what I had to do?

0:20:22.000 --> 0:20:24.639
<v Speaker 2>I went on Google. I hacked in to the Google

0:20:24.800 --> 0:20:29.440
<v Speaker 2>mainframe and I typed in, how do you pronounce p wn?

0:20:31.480 --> 0:20:33.040
<v Speaker 2>I was like, I want to say it right.

0:20:33.560 --> 0:20:34.359
<v Speaker 3>I appreciate your.

0:20:34.480 --> 0:20:40.040
<v Speaker 2>Thorough phone to own. Okay, that's known as hacking super Bowl.

0:20:40.960 --> 0:20:44.040
<v Speaker 2>So for that, he hacked a MacBook Air in under

0:20:44.040 --> 0:20:46.639
<v Speaker 2>two minutes. In two thousand and eight, he was the

0:20:46.680 --> 0:20:50.800
<v Speaker 2>first to remotely exploit an iPhone and that's like break

0:20:50.840 --> 0:20:55.160
<v Speaker 2>in hacking style, not like exploit it, like publish pictures

0:20:55.160 --> 0:21:00.400
<v Speaker 2>of it that should be published via malicious SMS message

0:21:00.480 --> 0:21:01.199
<v Speaker 2>in two thousand and.

0:21:01.200 --> 0:21:03.200
<v Speaker 3>Seven, so he sent a text message to the phone

0:21:03.240 --> 0:21:03.919
<v Speaker 3>and then gave him.

0:21:04.960 --> 0:21:07.679
<v Speaker 2>Yeah, he was the first to hack an Android device

0:21:07.760 --> 0:21:11.040
<v Speaker 2>on its launch day, and he exped He exploited the

0:21:11.080 --> 0:21:12.920
<v Speaker 2>vulnerabilities there via web kit.

0:21:13.800 --> 0:21:14.399
<v Speaker 5>What that is?

0:21:15.200 --> 0:21:18.960
<v Speaker 3>Yeah, I know that they use often things like oh,

0:21:19.000 --> 0:21:22.199
<v Speaker 3>we'll use your calendar or like this phone is like

0:21:22.320 --> 0:21:24.480
<v Speaker 3>you don't think about right.

0:21:24.400 --> 0:21:28.240
<v Speaker 2>That's and that's basically what he does. So he has

0:21:28.280 --> 0:21:34.800
<v Speaker 2>published the iOS Hackers Handbook, the Mac Hackers Handbook, Fuzzing

0:21:34.880 --> 0:21:39.200
<v Speaker 2>for Software Security Testing and Quality Assurance. Like basically is there.

0:21:39.320 --> 0:21:40.480
<v Speaker 2>This guy's a real pan.

0:21:41.440 --> 0:21:42.720
<v Speaker 3>He wrote the books on these things.

0:21:42.840 --> 0:21:47.320
<v Speaker 2>He literally wrote the books. Foreign Policy described him as

0:21:47.359 --> 0:21:50.679
<v Speaker 2>quote one of the most technically proficient hackers on Earth.

0:21:52.280 --> 0:21:53.320
<v Speaker 3>Foreign Policy given him.

0:21:53.240 --> 0:21:54.840
<v Speaker 5>The Star Buddy.

0:21:54.880 --> 0:21:56.879
<v Speaker 2>Okay, so then we have Chris.

0:21:56.760 --> 0:21:59.480
<v Speaker 3>Thallasek Okay, so not like the pile.

0:22:00.160 --> 0:22:02.280
<v Speaker 2>It's Vallisek. That's another one.

0:22:02.920 --> 0:22:04.360
<v Speaker 5>He was born in eighty.

0:22:04.080 --> 0:22:07.159
<v Speaker 2>Two in Pennsylvania. He got a BS in computer science

0:22:07.160 --> 0:22:09.280
<v Speaker 2>from University of Pittsburgh coding.

0:22:09.440 --> 0:22:11.440
<v Speaker 3>So another early com era guy.

0:22:11.560 --> 0:22:16.240
<v Speaker 2>Yeah. He built his reputation through research into Microsoft Windows.

0:22:16.640 --> 0:22:17.840
<v Speaker 2>Heap exploitation.

0:22:18.400 --> 0:22:20.359
<v Speaker 3>Sure sounds such a simple term.

0:22:20.400 --> 0:22:23.439
<v Speaker 2>And I know you know what I'm talking about Windows.

0:22:25.760 --> 0:22:29.920
<v Speaker 2>I got a window in my room. Heap exploitation. Hap.

0:22:31.200 --> 0:22:31.400
<v Speaker 4>There.

0:22:32.240 --> 0:22:34.920
<v Speaker 2>Think of a heap as a chunk of memory your

0:22:34.960 --> 0:22:38.040
<v Speaker 2>computer uses to keep track of things a program creates

0:22:38.040 --> 0:22:41.000
<v Speaker 2>while it's running. Okay, Like when a program goes like,

0:22:41.080 --> 0:22:43.399
<v Speaker 2>hey man, I need more memory to store this new

0:22:44.320 --> 0:22:47.359
<v Speaker 2>the heap. The heap gives it space. The heap is

0:22:47.400 --> 0:22:51.880
<v Speaker 2>not alive. The heap cannot hurt you. The heap absorbs.

0:22:52.680 --> 0:22:56.000
<v Speaker 2>The heap enjoys a good cheese steak. The heap vacations

0:22:56.000 --> 0:23:00.560
<v Speaker 2>in Daytona beach. All right. So, heap exploitation is when

0:23:00.560 --> 0:23:04.199
<v Speaker 2>a hacker takes advantage of mistakes in how memory is

0:23:04.280 --> 0:23:07.199
<v Speaker 2>managed in it. So they do that in order to

0:23:07.280 --> 0:23:10.919
<v Speaker 2>corrupt data, crash program take control of a computer. Do

0:23:10.960 --> 0:23:12.320
<v Speaker 2>you understand what I just said?

0:23:12.520 --> 0:23:14.600
<v Speaker 3>Some of it, like taking control of a computer.

0:23:14.640 --> 0:23:17.399
<v Speaker 2>Man, Do I understand what I just said? Absolutely not.

0:23:17.680 --> 0:23:19.520
<v Speaker 3>I had a friend who used to you be on

0:23:19.560 --> 0:23:21.480
<v Speaker 3>your computer, and he would get on your computer from

0:23:21.640 --> 0:23:25.320
<v Speaker 3>his computer like at his house, start moving the cursor around. Yeah.

0:23:25.359 --> 0:23:26.919
<v Speaker 3>I was like, I hate this, I hate all of this.

0:23:27.040 --> 0:23:28.800
<v Speaker 2>I guys do that and it's like, what do I

0:23:28.840 --> 0:23:29.680
<v Speaker 2>have open right now?

0:23:29.800 --> 0:23:31.400
<v Speaker 3>Exactly? And he was like, oh, I got in through

0:23:31.440 --> 0:23:33.000
<v Speaker 3>this exploit. And I'm like, I swear to God, I'm

0:23:33.000 --> 0:23:34.199
<v Speaker 3>gonna come over to your house and beat you up.

0:23:34.640 --> 0:23:36.560
<v Speaker 2>They're like, you're really good at spider solitary.

0:23:36.920 --> 0:23:38.640
<v Speaker 3>Can you hack my fists? How about that?

0:23:40.000 --> 0:23:44.440
<v Speaker 2>So Valasek he became an expert in both the exploitation

0:23:44.640 --> 0:23:48.399
<v Speaker 2>of heaps and the protection of heaps. And remember, the

0:23:48.440 --> 0:23:49.399
<v Speaker 2>heap cannot hurt you.

0:23:49.400 --> 0:23:50.439
<v Speaker 3>You know, I don't want to tear It.

0:23:51.280 --> 0:23:54.600
<v Speaker 2>Can hear your thoughts, and it knows your darkest intentions,

0:23:54.640 --> 0:23:55.639
<v Speaker 2>but it cannot hurt you.

0:23:55.800 --> 0:23:57.800
<v Speaker 3>Saren, Okay, I have to trust the heap.

0:23:57.840 --> 0:24:00.640
<v Speaker 2>So this guy, he had a two thousand and nine

0:24:00.640 --> 0:24:04.760
<v Speaker 2>Black Hat presentation titled Practical Windows XP two thousand and

0:24:04.760 --> 0:24:07.879
<v Speaker 2>three Heap Exploitation, and then he did a paper in

0:24:07.920 --> 0:24:12.159
<v Speaker 2>twenty ten on Windows low fragmentation heap, good stuff. I

0:24:12.200 --> 0:24:14.720
<v Speaker 2>find myself going back to my well worn copies and

0:24:14.800 --> 0:24:16.119
<v Speaker 2>just like reading them over and over.

0:24:16.000 --> 0:24:18.200
<v Speaker 3>There low frag heap. I love that.

0:24:18.080 --> 0:24:20.160
<v Speaker 2>Each time I read them, I discover something new.

0:24:20.280 --> 0:24:22.200
<v Speaker 3>I bet you do, a little, Colonel, you'd overlooked before.

0:24:22.440 --> 0:24:22.600
<v Speaker 6>Huh.

0:24:22.720 --> 0:24:25.479
<v Speaker 2>Basically, Vallisek is like a super hacker.

0:24:25.760 --> 0:24:28.600
<v Speaker 3>He sounds like sound chair right.

0:24:28.840 --> 0:24:30.080
<v Speaker 2>He shared Summer Con.

0:24:30.359 --> 0:24:30.560
<v Speaker 3>Huh.

0:24:30.680 --> 0:24:33.920
<v Speaker 2>This is one of the US's longest running hacker conferences,

0:24:33.960 --> 0:24:36.640
<v Speaker 2>and he's been their chairman Emeritis since two thousand and three.

0:24:36.720 --> 0:24:38.520
<v Speaker 3>Do you think they have good music at the Summer Con? Oh?

0:24:38.640 --> 0:24:41.680
<v Speaker 2>You know it like hot jams. They hack into all

0:24:41.720 --> 0:24:46.560
<v Speaker 2>the music mainframes and the motherboard, Sarah. When you look

0:24:46.600 --> 0:24:48.680
<v Speaker 2>online for videos about him so you can get a

0:24:48.720 --> 0:24:51.879
<v Speaker 2>sense of how to pronounce his name, you'll find yourself

0:24:51.960 --> 0:24:55.480
<v Speaker 2>waist deep in Ted talks, like this guy is like

0:24:55.640 --> 0:24:59.080
<v Speaker 2>sixty percent Ted talk. His body is six and in

0:24:59.240 --> 0:25:02.600
<v Speaker 2>all the videos he doesn't introduce himself, I imagine because

0:25:02.600 --> 0:25:03.880
<v Speaker 2>someone has already done it before.

0:25:03.720 --> 0:25:04.600
<v Speaker 3>The recording starts.

0:25:04.680 --> 0:25:04.760
<v Speaker 6>Right.

0:25:05.320 --> 0:25:07.800
<v Speaker 2>So I watched a lot of clips of him walking

0:25:07.880 --> 0:25:11.000
<v Speaker 2>onto a stage like polite applause and one of those

0:25:11.080 --> 0:25:13.879
<v Speaker 2>nude colored mics attached to his face, like lifts up

0:25:13.880 --> 0:25:16.959
<v Speaker 2>a clicker to introduce the first slide of a PowerPoint.

0:25:16.480 --> 0:25:18.520
<v Speaker 3>And you're hoping he says his name, and he doesn't.

0:25:18.600 --> 0:25:20.639
<v Speaker 2>Yep, And I'm gonna tell you I noped out of

0:25:20.640 --> 0:25:23.560
<v Speaker 2>those so fast. I just can't. I love myself too

0:25:23.640 --> 0:25:24.959
<v Speaker 2>much to do that to myself.

0:25:25.000 --> 0:25:26.360
<v Speaker 3>Yeah, don't pone yourself like that.

0:25:26.760 --> 0:25:31.120
<v Speaker 2>I will give George Santos sixty bucks to entertain listeners,

0:25:31.160 --> 0:25:34.119
<v Speaker 2>but I won't subject myself to ted talks, especially when

0:25:34.119 --> 0:25:36.800
<v Speaker 2>they're not even six minutes, especially when they're about computers.

0:25:37.320 --> 0:25:41.080
<v Speaker 2>So Valasek, He's on video a lot. He's a recognized

0:25:41.119 --> 0:25:45.919
<v Speaker 2>speaker at all these INFOSEC conferences, Black at USA, def Con,

0:25:46.440 --> 0:25:47.600
<v Speaker 2>def Comedy.

0:25:47.320 --> 0:25:49.680
<v Speaker 3>Jam, I'm just about ask Warp Tour.

0:25:50.600 --> 0:25:54.000
<v Speaker 2>He's also widely cited in media coverage for like all

0:25:54.040 --> 0:25:59.120
<v Speaker 2>these pioneering contributions that he has to automotive cybersecurity research.

0:26:00.280 --> 0:26:04.200
<v Speaker 2>Here's a quote. Quote please, when I secure cars, now,

0:26:04.280 --> 0:26:06.680
<v Speaker 2>the first thing I look at is things that communicate

0:26:06.720 --> 0:26:07.959
<v Speaker 2>with the outside world.

0:26:08.640 --> 0:26:10.560
<v Speaker 3>So he said, I just buy old cars so people

0:26:10.600 --> 0:26:12.760
<v Speaker 3>can't do any of this stuff exactly. Pretty soon, I'm

0:26:12.760 --> 0:26:16.400
<v Speaker 3>just gonna be riding around on a penny farthing wearing clothing.

0:26:17.760 --> 0:26:22.360
<v Speaker 2>So like cars, you say, Chris and Charlie they pioneered

0:26:22.359 --> 0:26:27.640
<v Speaker 2>research together into vehicle cybersecurity. So they first demonstrated that

0:26:28.480 --> 0:26:31.520
<v Speaker 2>they got physical access to both a Ford Escape and

0:26:31.560 --> 0:26:34.800
<v Speaker 2>at Toyota Prius and were able to control their systems.

0:26:35.240 --> 0:26:37.400
<v Speaker 2>So like, once they got in physically, they could get

0:26:37.440 --> 0:26:41.399
<v Speaker 2>in through the can bus c an bus, which is

0:26:41.440 --> 0:26:44.919
<v Speaker 2>the controller area network bus. Sure, but not like a

0:26:45.000 --> 0:26:47.680
<v Speaker 2>real bus, like wheels on the bus go round and round.

0:26:47.800 --> 0:26:50.040
<v Speaker 3>Take the thing that like routes traffic for the computer.

0:26:50.160 --> 0:26:53.320
<v Speaker 2>Yeah, it's an internal communication network that lets all the

0:26:53.359 --> 0:26:55.639
<v Speaker 2>systems talk to each other. Do you have any idea

0:26:55.680 --> 0:26:58.120
<v Speaker 2>how long it took me to like condense it down

0:26:58.160 --> 0:27:01.359
<v Speaker 2>into that sentence, because I would start reading things like

0:27:01.520 --> 0:27:02.560
<v Speaker 2>I think I'm having a stroke.

0:27:02.840 --> 0:27:04.040
<v Speaker 3>Look on face gives me a hint.

0:27:04.200 --> 0:27:07.000
<v Speaker 2>Yeah, can bus, which then I'm just like, now I

0:27:07.080 --> 0:27:07.800
<v Speaker 2>sound crazy.

0:27:07.920 --> 0:27:11.280
<v Speaker 3>Can bus, the bus, cannabus, canna bus.

0:27:12.119 --> 0:27:15.879
<v Speaker 2>By twenty fifteen automakers, they're just like putting more and

0:27:15.960 --> 0:27:19.679
<v Speaker 2>more stuff with internet connectivity and like what they call

0:27:19.800 --> 0:27:23.800
<v Speaker 2>infotainment systems. Oh yes, into the car. Yeah, they want

0:27:23.840 --> 0:27:27.159
<v Speaker 2>to improve the user convenience, but then it also just

0:27:27.240 --> 0:27:28.520
<v Speaker 2>opens it up to attack.

0:27:28.640 --> 0:27:30.280
<v Speaker 3>Plenty of exploits, so many.

0:27:30.080 --> 0:27:32.960
<v Speaker 2>Weak spots for the hackers and all the hackens.

0:27:33.160 --> 0:27:35.400
<v Speaker 3>It's like a smog was just Swiss cheese belly. It's

0:27:35.400 --> 0:27:38.600
<v Speaker 3>just all these spots. You just one spot. Now he's

0:27:38.600 --> 0:27:39.240
<v Speaker 3>got tough.

0:27:39.320 --> 0:27:43.840
<v Speaker 2>All the Pokey's Fiat Chrysler Automobiles, it was one of

0:27:44.000 --> 0:27:48.560
<v Speaker 2>a bunch of manufacturers integrating you Connect, which was a

0:27:48.640 --> 0:27:54.359
<v Speaker 2>proprietary infotainment system into the cars. It had like navigation,

0:27:54.640 --> 0:27:58.960
<v Speaker 2>a Wi Fi hotspot, remote start, voice command capabilities. I

0:27:58.960 --> 0:28:00.480
<v Speaker 2>think that's basically what I got down.

0:28:00.720 --> 0:28:01.359
<v Speaker 3>That's what sounds like.

0:28:02.760 --> 0:28:07.160
<v Speaker 2>Some models also had Sprint cellular connectivity that would allow

0:28:07.280 --> 0:28:09.200
<v Speaker 2>remote access and updates.

0:28:08.960 --> 0:28:12.240
<v Speaker 3>So you like play from your phone whatever your yeah

0:28:12.440 --> 0:28:13.560
<v Speaker 3>to actually connected with the OX.

0:28:14.400 --> 0:28:18.520
<v Speaker 2>Yeah. Super futuristic and great, but also making the car

0:28:19.040 --> 0:28:22.720
<v Speaker 2>super vulnerable. It's not properly secured totally. So Miller and

0:28:22.840 --> 0:28:24.840
<v Speaker 2>vallisec right. Yeah.

0:28:25.240 --> 0:28:27.840
<v Speaker 3>I had a quick question, do they make essentially like

0:28:27.880 --> 0:28:30.840
<v Speaker 3>a Faraday skin for a car? They got into that level.

0:28:30.920 --> 0:28:33.440
<v Speaker 2>That's a really good idea. Guy's got a lead line carduse,

0:28:33.520 --> 0:28:35.320
<v Speaker 2>you know, like when they do the ad wraps on

0:28:35.359 --> 0:28:38.320
<v Speaker 2>the car. But it's just like with like a with

0:28:38.400 --> 0:28:40.800
<v Speaker 2>a guy making a mean face, like don't you dare

0:28:41.160 --> 0:28:43.240
<v Speaker 2>waving his face, buddy.

0:28:43.560 --> 0:28:45.680
<v Speaker 3>The graph the crime dog on the hood of your car.

0:28:47.440 --> 0:28:50.480
<v Speaker 2>So our guys. They made it their goal to find

0:28:50.520 --> 0:28:54.840
<v Speaker 2>a remote attack vector that wouldn't require physical access to

0:28:54.920 --> 0:28:57.280
<v Speaker 2>the vehicle like they need to before. So over the

0:28:57.280 --> 0:29:00.080
<v Speaker 2>course of twenty fourteen and twenty fifteen, they set the

0:29:00.240 --> 0:29:05.280
<v Speaker 2>sites on Fiat Chrysler's U Connect system, particularly the twenty

0:29:05.360 --> 0:29:09.520
<v Speaker 2>fourteen Jeep Cherokee. So they figured, like, okay, we can

0:29:09.560 --> 0:29:13.560
<v Speaker 2>get into you connect through that Sprint cellular connection. So

0:29:13.600 --> 0:29:17.880
<v Speaker 2>they reverse engineered the firmware, discovered open ports on the

0:29:17.960 --> 0:29:22.000
<v Speaker 2>vehicle's Internet facing IP address, and found a way to

0:29:22.160 --> 0:29:27.440
<v Speaker 2>rewrite firmware on the infotainment chip like sarahen, I sound

0:29:27.480 --> 0:29:28.760
<v Speaker 2>like I work for geek Squad.

0:29:28.880 --> 0:29:30.840
<v Speaker 3>I know you're over here. I'm like, can you fix

0:29:30.880 --> 0:29:31.360
<v Speaker 3>my laptop?

0:29:31.560 --> 0:29:36.360
<v Speaker 2>Right? And like totally, I just step on it. Are done.

0:29:36.720 --> 0:29:40.720
<v Speaker 2>Using a showdowan, which is a search engine for Internet

0:29:40.760 --> 0:29:47.120
<v Speaker 2>connected devices, Sure whatever, buddy, they identified thousands of vehicles

0:29:47.200 --> 0:29:50.520
<v Speaker 2>that could be exposed through their cellular modems and they

0:29:50.560 --> 0:29:53.720
<v Speaker 2>found this chain of exploits they I mean, they could

0:29:53.720 --> 0:29:57.560
<v Speaker 2>get into all these crazy things critical vehicle systems, and

0:29:57.600 --> 0:30:00.080
<v Speaker 2>they were eventually able to bridge the gap between the

0:30:00.120 --> 0:30:02.560
<v Speaker 2>infotainment system and the.

0:30:02.560 --> 0:30:04.000
<v Speaker 3>Can bus boom.

0:30:04.000 --> 0:30:09.120
<v Speaker 2>They got in, like I want in on that can.

0:30:09.440 --> 0:30:11.760
<v Speaker 2>This means that once they were inside, they can send

0:30:11.800 --> 0:30:15.360
<v Speaker 2>commands to like key vehicle functions like the gas, pedal,

0:30:15.440 --> 0:30:19.200
<v Speaker 2>air conditioning, and radio. They could put fake images on

0:30:19.240 --> 0:30:23.120
<v Speaker 2>a dashboard. They can control the windshield wipers, they could disable.

0:30:22.720 --> 0:30:26.440
<v Speaker 3>The brakes, disable the brakes.

0:30:25.440 --> 0:30:29.080
<v Speaker 2>The steering, misnipulate steering. And they set out to do

0:30:29.320 --> 0:30:33.160
<v Speaker 2>a very dangerous and most likely illegal demonstration of this.

0:30:33.360 --> 0:30:34.800
<v Speaker 3>Yeah, I would imagine.

0:30:34.440 --> 0:30:43.320
<v Speaker 2>Zerin close your eyes. I want you to picture it.

0:30:43.320 --> 0:30:46.360
<v Speaker 2>It's July of twenty fifteen. You are sitting in a

0:30:46.440 --> 0:30:50.840
<v Speaker 2>twenty fourteen jeep Cherokee driving down the highway in Saint Louis.

0:30:51.400 --> 0:30:51.680
<v Speaker 5>There.

0:30:51.760 --> 0:30:55.120
<v Speaker 2>You are cruising along. It's seventy miles an hour. Then

0:30:55.160 --> 0:30:58.440
<v Speaker 2>suddenly the air conditioner roars to life, blasting the car

0:30:58.560 --> 0:31:02.680
<v Speaker 2>with arctic air. Haven't touched a thing. Immediately after that,

0:31:02.720 --> 0:31:05.840
<v Speaker 2>the radio comes on. What had been a silent ride

0:31:05.960 --> 0:31:08.760
<v Speaker 2>is now one with booming hip hop at top volume.

0:31:09.160 --> 0:31:12.280
<v Speaker 2>The speakers in the back rumble. You turn the volume

0:31:12.360 --> 0:31:15.280
<v Speaker 2>knob to silence the stereo system, but nothing happens. The

0:31:15.280 --> 0:31:20.000
<v Speaker 2>song is still blaring the knob. She needs nothing. Suddenly,

0:31:20.080 --> 0:31:22.800
<v Speaker 2>the windshield wipers come on. You didn't touch those either.

0:31:23.200 --> 0:31:24.760
<v Speaker 2>Wiper fluid sprays.

0:31:24.400 --> 0:31:26.880
<v Speaker 5>The windshield while you speed down the highway. You can't

0:31:26.880 --> 0:31:27.800
<v Speaker 5>get them to stop.

0:31:28.480 --> 0:31:31.320
<v Speaker 2>Just then, an image appears on the car's digital display.

0:31:31.680 --> 0:31:35.320
<v Speaker 2>It's a photo of two guys in matching tracksuits. You

0:31:35.360 --> 0:31:37.680
<v Speaker 2>take a deep breath and try to stay calm. The

0:31:37.800 --> 0:31:41.880
<v Speaker 2>radio cuts out. That's relief, but then so does the accelerator.

0:31:42.160 --> 0:31:45.080
<v Speaker 2>The transmission is dead. You pump on the gas pedal,

0:31:45.160 --> 0:31:49.520
<v Speaker 2>but nothing. The jeep quickly loses speed, moving slower and slower.

0:31:50.080 --> 0:31:52.640
<v Speaker 2>You'd pull over onto the shoulder, but you can't because

0:31:52.640 --> 0:31:55.400
<v Speaker 2>you just got to an overpass. There's no shoulder, and

0:31:55.440 --> 0:31:58.720
<v Speaker 2>you're starting to go uphill. The cars behind you slam

0:31:58.760 --> 0:32:00.640
<v Speaker 2>on their brakes and lean on the lawrence is a

0:32:00.680 --> 0:32:03.080
<v Speaker 2>swerve around you. You look in the rear view mirror

0:32:03.120 --> 0:32:06.440
<v Speaker 2>and you see a semi truck approaching. The radio comes.

0:32:06.200 --> 0:32:07.760
<v Speaker 5>Alive again with more hip hop.

0:32:08.000 --> 0:32:09.880
<v Speaker 2>Please please please let me survive this.

0:32:10.000 --> 0:32:12.360
<v Speaker 5>You think you fubble for your phone and you make

0:32:12.400 --> 0:32:12.760
<v Speaker 5>a call.

0:32:13.160 --> 0:32:15.560
<v Speaker 2>You aren't calling the highway patrol or the cops, or

0:32:15.560 --> 0:32:19.240
<v Speaker 2>state troopers or even Triple A. You are calling Charlie

0:32:19.280 --> 0:32:24.840
<v Speaker 2>Miller and Chris Vallasek. See you are Andy Greenberg, award

0:32:24.840 --> 0:32:28.640
<v Speaker 2>winning journalist and writer for Wired magazine, and you've agreed

0:32:28.680 --> 0:32:31.080
<v Speaker 2>to be their guinea pigs. They set out to prove

0:32:31.240 --> 0:32:34.000
<v Speaker 2>just how easy it is to do bad with cars

0:32:34.080 --> 0:32:37.080
<v Speaker 2>in this current system. You beg them to stop, to

0:32:37.160 --> 0:32:39.600
<v Speaker 2>give you back control of the car. You manage to

0:32:39.680 --> 0:32:41.840
<v Speaker 2>roll the jeep to an exit ramp, turn the car

0:32:41.840 --> 0:32:44.560
<v Speaker 2>off and then on again, basically rebooting it, and then

0:32:44.600 --> 0:32:47.760
<v Speaker 2>you get to an empty lot where your experiment can continue.

0:32:48.440 --> 0:32:50.280
<v Speaker 3>Now, why did they get on the road. Why didn't

0:32:50.320 --> 0:32:52.080
<v Speaker 3>he to go to like a Walmart parking lot to

0:32:52.200 --> 0:32:52.520
<v Speaker 3>do this?

0:32:53.760 --> 0:32:59.600
<v Speaker 2>No, I got so nervous, and they told him before

0:32:59.600 --> 0:33:03.320
<v Speaker 2>he got the like, don't whatever happens, don't panic. Now

0:33:03.320 --> 0:33:06.240
<v Speaker 2>here's the thing, So Greenberg he gets the jeep to

0:33:06.320 --> 0:33:09.600
<v Speaker 2>safety and they all continue their work. The guys were

0:33:09.600 --> 0:33:12.800
<v Speaker 2>at Miller's house ten miles away, so they don't have

0:33:12.880 --> 0:33:16.920
<v Speaker 2>eyes on him. From Greenberg's Wired article quote Miller and

0:33:17.040 --> 0:33:21.320
<v Speaker 2>Vallisex full arsenal includes functions that at lower speeds fully

0:33:21.400 --> 0:33:25.480
<v Speaker 2>kill the engine, abruptly engage the brakes, or disable them altogether.

0:33:25.960 --> 0:33:29.080
<v Speaker 2>The most disturbing maneuver came when they cut the jeep's brakes,

0:33:29.400 --> 0:33:32.440
<v Speaker 2>leaving me frantically pumping the pedal as the two ton

0:33:32.600 --> 0:33:36.880
<v Speaker 2>suv slid uncontrollably into a ditch. The researchers say they're

0:33:36.920 --> 0:33:39.920
<v Speaker 2>working on perfecting their steering control. For now, they can

0:33:39.960 --> 0:33:42.280
<v Speaker 2>only hijack the wheel when the jeep is in reverse.

0:33:42.720 --> 0:33:46.240
<v Speaker 2>Their hack enables surveillance too. They can track a targeted

0:33:46.280 --> 0:33:50.000
<v Speaker 2>jeep's GPS coordinates, measure its speed, and even drop pins

0:33:50.040 --> 0:33:53.840
<v Speaker 2>on a map to trace its route. Unbelievable, So, of course,

0:33:53.880 --> 0:33:57.000
<v Speaker 2>the whole thing was done with Greenberg's consent, sure as

0:33:57.040 --> 0:33:59.480
<v Speaker 2>a way to publicize the danger of you connect and

0:33:59.520 --> 0:34:02.400
<v Speaker 2>get the Endo street to respond, let's take a break.

0:34:02.520 --> 0:34:05.840
<v Speaker 2>When we get back from this ad venture, I'll tell

0:34:05.920 --> 0:34:07.600
<v Speaker 2>you just how they responded.

0:34:27.920 --> 0:34:29.960
<v Speaker 3>Zarin, Oh, Elizabeth, we're back.

0:34:30.000 --> 0:34:31.960
<v Speaker 2>We're back in the twenty fourteen cheap.

0:34:31.800 --> 0:34:32.799
<v Speaker 3>I had to shake that one off.

0:34:32.880 --> 0:34:35.000
<v Speaker 2>I know that was a nightmare, as a total daymare.

0:34:35.520 --> 0:34:36.799
<v Speaker 3>I thought it was bad and if someone took over

0:34:36.840 --> 0:34:39.000
<v Speaker 3>my computer but being in the car they're taking over

0:34:39.040 --> 0:34:40.360
<v Speaker 3>and then like I gotta trust them. Oh yeah, I

0:34:40.360 --> 0:34:41.600
<v Speaker 3>don't worry. I'll art it all back.

0:34:42.080 --> 0:34:44.560
<v Speaker 2>Very maximum overdrive. And I don't like it one bit.

0:34:44.760 --> 0:34:46.640
<v Speaker 3>And there's not enough of Meia the West of US

0:34:46.640 --> 0:34:47.680
<v Speaker 3>in that for me I feel safe.

0:34:47.960 --> 0:34:51.160
<v Speaker 2>Yeah, there needs a whole lot more so. After that

0:34:51.239 --> 0:34:56.279
<v Speaker 2>Wired article, Fiat Chrysler, they took swift action. July twenty fourth,

0:34:56.360 --> 0:35:00.359
<v Speaker 2>twenty fifteen, they issued a voluntary safety recall for one

0:35:00.440 --> 0:35:04.279
<v Speaker 2>point four million vehicles in the US in order to

0:35:04.320 --> 0:35:08.319
<v Speaker 2>fix those software vulnerabilities. And so that was models from

0:35:08.320 --> 0:35:11.200
<v Speaker 2>twenty thirteen to twenty fifteen that had eight point four

0:35:11.280 --> 0:35:16.200
<v Speaker 2>inch touchscreen. So twenty fourteen, twenty fifteen Jeep, Cherokee, twenty

0:35:16.239 --> 0:35:19.000
<v Speaker 2>fifteen Dodge Challenger, which like, I don't want one of

0:35:19.040 --> 0:35:22.440
<v Speaker 2>those self possessed rubbing down the road, twenty fifteen, Chrysler

0:35:22.440 --> 0:35:25.880
<v Speaker 2>two hundred and others. Chrysler dodged Jeep and Ram lines.

0:35:27.120 --> 0:35:30.719
<v Speaker 2>Fiat Chrysler sent out a USB drive by mail to

0:35:30.800 --> 0:35:35.640
<v Speaker 2>affected owners with the patch like diy, I guess steal

0:35:35.640 --> 0:35:39.279
<v Speaker 2>a Kia drive that around instead the owners They could

0:35:39.280 --> 0:35:42.400
<v Speaker 2>also go to a dealership for installation if they weren't hackers,

0:35:42.960 --> 0:35:48.320
<v Speaker 2>you know. In addition, Sprint closed the open cellular ports

0:35:48.400 --> 0:35:50.960
<v Speaker 2>that the hackers had used, which like, why didn't you

0:35:51.000 --> 0:35:52.160
<v Speaker 2>do that originally?

0:35:52.200 --> 0:35:53.640
<v Speaker 3>Yeah? Did they cost a penny to do?

0:35:53.840 --> 0:35:57.080
<v Speaker 2>Now, the National Highway Traffic Safety Administration they opened an

0:35:57.080 --> 0:36:01.000
<v Speaker 2>investigation and then they find Fiat Chrysler one hundred and

0:36:01.040 --> 0:36:02.240
<v Speaker 2>five million dollars.

0:36:02.560 --> 0:36:06.400
<v Speaker 3>Why did they find them for just being.

0:36:05.880 --> 0:36:09.520
<v Speaker 2>A production They're flying too close to the sun, Like

0:36:09.600 --> 0:36:12.959
<v Speaker 2>you thought you were so special, arrogance. Well, it wasn't

0:36:13.000 --> 0:36:14.960
<v Speaker 2>just for the Jeep vulnerability, but there were like a

0:36:15.000 --> 0:36:17.640
<v Speaker 2>series of recalls that were kind of mishandled leading up

0:36:17.680 --> 0:36:21.120
<v Speaker 2>to me. So like, you guys are bungling everything one

0:36:21.200 --> 0:36:26.520
<v Speaker 2>hundred and five million, but the Jeep incident was like yeah, yeah,

0:36:26.560 --> 0:36:30.880
<v Speaker 2>so the hack that had lasting implications far beyond Fiat Chrysler.

0:36:32.080 --> 0:36:36.239
<v Speaker 2>Senators Edward Markey of Massachusetts and Richard Blumenthal of Connecticut

0:36:36.640 --> 0:36:40.080
<v Speaker 2>they introduced the Security and Privacy in Your Car Act,

0:36:40.600 --> 0:36:41.800
<v Speaker 2>the Spy.

0:36:41.440 --> 0:36:44.040
<v Speaker 3>Car Act right.

0:36:44.400 --> 0:36:49.600
<v Speaker 2>The bill would require cybersecurity standards for vehicles, isolation of

0:36:49.680 --> 0:36:54.359
<v Speaker 2>critical software systems, real time hacking detection systems, and then

0:36:54.400 --> 0:36:57.920
<v Speaker 2>transparency on how car companies collect and share driver data.

0:36:58.200 --> 0:36:58.959
<v Speaker 2>It's a great bill.

0:36:59.360 --> 0:37:01.960
<v Speaker 3>Sounds like didn't pass, Oh my goodness.

0:37:01.560 --> 0:37:04.440
<v Speaker 2>Of course, not my feeling. I'm thinking the sticking point

0:37:04.520 --> 0:37:07.319
<v Speaker 2>was the transparency on how car companies collect and share

0:37:07.360 --> 0:37:11.000
<v Speaker 2>driver data, probably because that's like, you know, that's a

0:37:11.080 --> 0:37:11.839
<v Speaker 2>commodity and.

0:37:11.760 --> 0:37:14.400
<v Speaker 3>They generally avoid that for either that's our data.

0:37:14.239 --> 0:37:17.680
<v Speaker 2>Yeah, the customer like spending and travel, and then also

0:37:17.960 --> 0:37:20.200
<v Speaker 2>like how you connect to like insurance companies.

0:37:20.600 --> 0:37:23.640
<v Speaker 3>Yeah, that they didn't want like a trade secrets, like

0:37:23.760 --> 0:37:24.440
<v Speaker 3>we're selling everything.

0:37:24.880 --> 0:37:27.239
<v Speaker 2>Was just like this driver like yeah, they speed all

0:37:27.280 --> 0:37:30.520
<v Speaker 2>the time, increase their rates. Oh, they wouldn't know otherwise.

0:37:30.560 --> 0:37:31.560
<v Speaker 2>I don't know, that's my guess.

0:37:31.600 --> 0:37:33.120
<v Speaker 3>I was thinking that they were already doing that. They're

0:37:33.200 --> 0:37:34.920
<v Speaker 3>killing the insurance company for a price.

0:37:34.960 --> 0:37:37.160
<v Speaker 2>They already do. But I'm just saying like that was

0:37:37.280 --> 0:37:39.480
<v Speaker 2>that's I think that, like this is something that car

0:37:39.520 --> 0:37:41.800
<v Speaker 2>companies would kill because it's going to cost him money

0:37:42.800 --> 0:37:45.080
<v Speaker 2>beyond just like changing the tech.

0:37:45.080 --> 0:37:48.200
<v Speaker 3>It's something valuable to them. Yeah, data that is.

0:37:48.680 --> 0:37:49.640
<v Speaker 2>That's just me guessing.

0:37:49.920 --> 0:37:52.320
<v Speaker 3>I'm speculating to the BUIL didn't.

0:37:52.080 --> 0:37:55.680
<v Speaker 2>Pass, but it like spurred all these discussions about automotive

0:37:55.680 --> 0:38:00.960
<v Speaker 2>cybersecurity standards. In twenty sixteen, the Automotive Information Sharing an

0:38:01.000 --> 0:38:07.160
<v Speaker 2>Analysis Center, they released their best practices for cybersecurity, and

0:38:07.560 --> 0:38:10.480
<v Speaker 2>you know, most of the major manufacturers of automobiles they

0:38:10.600 --> 0:38:14.600
<v Speaker 2>picked that up. The gpack made it super clear infotainment

0:38:14.680 --> 0:38:18.560
<v Speaker 2>systems have to be segregated out from like the critical

0:38:18.640 --> 0:38:21.479
<v Speaker 2>vehicle control stuff. You can't have it all just riding

0:38:21.680 --> 0:38:26.399
<v Speaker 2>us together, exactly, And so Miller and Vallisek they later

0:38:26.440 --> 0:38:29.600
<v Speaker 2>got hired by Uber's Advanced Technology Center to work on

0:38:29.640 --> 0:38:32.919
<v Speaker 2>their self driving car security, and then they both worked

0:38:32.920 --> 0:38:37.160
<v Speaker 2>as principal autonomous vehicle security architects at Cruse Automation, which

0:38:37.200 --> 0:38:43.280
<v Speaker 2>was GM's self driving cars. The latest and more visible

0:38:43.360 --> 0:38:45.880
<v Speaker 2>victim of hackings is, of course Tesla.

0:38:49.400 --> 0:38:49.560
<v Speaker 4>Yeah.

0:38:49.640 --> 0:38:53.160
<v Speaker 2>Well, I should note that Tesla has a bug bounty program.

0:38:53.440 --> 0:38:55.839
<v Speaker 2>So if you can hack them and then show them how,

0:38:56.320 --> 0:38:59.880
<v Speaker 2>they'll give you cars or money or something. Of the

0:39:00.040 --> 0:39:02.600
<v Speaker 2>cyber trucks. It doesn't they can't sell you know, here

0:39:02.680 --> 0:39:04.600
<v Speaker 2>have one, you have five? Yeah, and I'm just like,

0:39:04.640 --> 0:39:06.440
<v Speaker 2>I hacked you guys. They're like, you no need to

0:39:06.440 --> 0:39:12.960
<v Speaker 2>have proof. Take a cyber's your problem now. Some of

0:39:13.000 --> 0:39:15.880
<v Speaker 2>that bacon from the diner. The whole thing, though, the

0:39:15.920 --> 0:39:18.920
<v Speaker 2>Tesla is like one big computer and the cars are

0:39:18.920 --> 0:39:22.000
<v Speaker 2>all about like connectivity and such and like you know,

0:39:22.800 --> 0:39:25.640
<v Speaker 2>things like watching YouTube while you pretend to drive while

0:39:25.680 --> 0:39:28.040
<v Speaker 2>autopilot's on and you're facetiming your buddy.

0:39:28.160 --> 0:39:29.720
<v Speaker 3>Sure important thing, yeah exactly.

0:39:30.080 --> 0:39:33.800
<v Speaker 2>In twenty sixteen, researchers from Keen Security Lab they found

0:39:34.120 --> 0:39:38.080
<v Speaker 2>multiple vulnerabilities in the Tesla model S that allowed remote

0:39:38.080 --> 0:39:41.000
<v Speaker 2>control of the car from up to twelve miles away

0:39:41.920 --> 0:39:45.520
<v Speaker 2>via the Wi Fi or cellular connection. So that's okay,

0:39:45.640 --> 0:39:49.200
<v Speaker 2>one year after this jeep thing, you know, someone's on

0:39:49.239 --> 0:39:53.640
<v Speaker 2>like an Atari sixty four driving your Tesla around. So

0:39:53.680 --> 0:39:57.359
<v Speaker 2>they found vulnerabilities in the infotainment system once again that

0:39:57.600 --> 0:40:03.120
<v Speaker 2>darned can bus access to the browser autopilot braking functions,

0:40:03.440 --> 0:40:05.520
<v Speaker 2>so they were able to like open the sun roof,

0:40:05.960 --> 0:40:10.360
<v Speaker 2>move the seats, control side mirrors, turn on the turn signal,

0:40:10.560 --> 0:40:12.719
<v Speaker 2>and then like slam on the brakes remotely while the

0:40:12.760 --> 0:40:13.120
<v Speaker 2>car was.

0:40:13.040 --> 0:40:16.560
<v Speaker 3>In so still operating like the car itself, not just the.

0:40:16.520 --> 0:40:19.160
<v Speaker 2>Features, yeah, but then like oh and the break ps

0:40:19.280 --> 0:40:22.760
<v Speaker 2>the brakes. Tesla saw this and then pushed an over

0:40:22.800 --> 0:40:26.960
<v Speaker 2>the air software update within ten days of the disclosure,

0:40:27.400 --> 0:40:30.200
<v Speaker 2>and then they also improved isolation between the systems like

0:40:30.239 --> 0:40:33.280
<v Speaker 2>we you know, infotatement and critical components.

0:40:32.880 --> 0:40:34.320
<v Speaker 3>Separated firewall that stuff.

0:40:34.400 --> 0:40:38.120
<v Speaker 2>Yes, talk, I love that, that's firewall.

0:40:38.400 --> 0:40:39.200
<v Speaker 3>That's good, thank you.

0:40:39.400 --> 0:40:43.440
<v Speaker 2>I just learned that one myself. In twenty twenty, fluoro

0:40:43.480 --> 0:40:44.520
<v Speaker 2>Acetate struck.

0:40:45.640 --> 0:40:46.200
<v Speaker 3>That's a hacker.

0:40:46.280 --> 0:40:50.080
<v Speaker 2>It's a well known security research team. So they share

0:40:50.160 --> 0:40:55.000
<v Speaker 2>a call sign Richard Zoo and amacamma. They were at

0:40:55.200 --> 0:40:59.279
<v Speaker 2>pone to own once again Vancouver hacking. Remember, yeah, the

0:40:59.280 --> 0:41:02.200
<v Speaker 2>super Bowl hack exactly, And that's where they exploited a

0:41:02.280 --> 0:41:07.000
<v Speaker 2>vulnerability in the Tesla Model threes infotainment system using a

0:41:07.480 --> 0:41:14.280
<v Speaker 2>JavaScript jit just in time jure in the WebKit engine.

0:41:14.280 --> 0:41:18.439
<v Speaker 2>We're back with webkits. The exploit allowed them to gain

0:41:18.520 --> 0:41:21.759
<v Speaker 2>control of the system when the driver visited a specially

0:41:21.840 --> 0:41:25.880
<v Speaker 2>crafted web page, so like if you're browsing around, you

0:41:25.960 --> 0:41:28.160
<v Speaker 2>have to put the web page into the giant screen

0:41:28.200 --> 0:41:31.600
<v Speaker 2>inside the car. And it gave them access to display messages.

0:41:32.080 --> 0:41:35.120
<v Speaker 2>They could control infotainment features like I'm going to put

0:41:35.160 --> 0:41:40.960
<v Speaker 2>on a different channel, interact with subsystems connected via the can,

0:41:41.120 --> 0:41:44.600
<v Speaker 2>but they couldn't directly control the driving, so.

0:41:44.560 --> 0:41:46.759
<v Speaker 3>They can make you watch criminal minds against your will.

0:41:47.760 --> 0:41:50.480
<v Speaker 2>Hundred percent, and so that was like purely infotainment. They

0:41:50.520 --> 0:41:54.160
<v Speaker 2>couldn't direct the actual car. But this was part of

0:41:54.200 --> 0:41:56.640
<v Speaker 2>a challenge at the competition, not a rogue mission to

0:41:56.680 --> 0:42:00.880
<v Speaker 2>embarrass Tesla. So Tesla awarded the hackers a Tesla Model

0:42:00.920 --> 0:42:03.320
<v Speaker 2>three and forty thousand dollars in prize money.

0:42:03.360 --> 0:42:05.200
<v Speaker 3>So it was like a sponsored hackophone.

0:42:04.960 --> 0:42:07.200
<v Speaker 2>Sponsored hackaphone. And then they patched that.

0:42:07.200 --> 0:42:09.080
<v Speaker 3>Vulnerability quickly they should.

0:42:08.880 --> 0:42:10.920
<v Speaker 2>You know, be via a software update.

0:42:11.000 --> 0:42:13.160
<v Speaker 3>So this is like their version of beta testing, is like, hey,

0:42:13.160 --> 0:42:14.759
<v Speaker 3>we're going to put the car out, then you find

0:42:14.800 --> 0:42:16.680
<v Speaker 3>the flaws and we'll fix those exactly.

0:42:17.120 --> 0:42:19.880
<v Speaker 2>Yeah, it's sort of like self check out. Suddenly I

0:42:20.000 --> 0:42:23.480
<v Speaker 2>work for the supermarket. Yeah, suddenly you work for Tesla.

0:42:24.080 --> 0:42:26.000
<v Speaker 2>So like, hold on, do you have Bluetooth in your

0:42:26.000 --> 0:42:27.520
<v Speaker 2>carp Yeah? See I do.

0:42:27.760 --> 0:42:30.320
<v Speaker 3>Yeah, I wasn't kidding about I buy older cars.

0:42:30.400 --> 0:42:33.840
<v Speaker 2>One time I let someone, someone who's a co host

0:42:33.960 --> 0:42:37.920
<v Speaker 2>of a murder free true crime podcast, connect his bluetooth

0:42:37.920 --> 0:42:42.600
<v Speaker 2>in my car. Yes, and now I know this fellow connected.

0:42:42.680 --> 0:42:45.440
<v Speaker 2>If I'm near you and your phone, you connect to

0:42:45.480 --> 0:42:47.799
<v Speaker 2>my car. So like you'll be in the parking lot

0:42:47.840 --> 0:42:51.080
<v Speaker 2>at headquarters on a phone call. I'm parked near you.

0:42:51.200 --> 0:42:53.640
<v Speaker 2>I go to start my car and suddenly your call

0:42:53.840 --> 0:42:54.240
<v Speaker 2>is in.

0:42:54.120 --> 0:42:55.960
<v Speaker 3>My bluetoth You're talking to my mother.

0:42:55.920 --> 0:42:59.560
<v Speaker 2>And I've got someone saying hello, Hello, or I'm suddenly

0:42:59.560 --> 0:43:02.759
<v Speaker 2>listening to the serious XM Radio Classics episode that you've

0:43:02.760 --> 0:43:04.120
<v Speaker 2>got playing on the radio Classic.

0:43:04.160 --> 0:43:06.560
<v Speaker 3>Oh yeah, you like Jack Benny. I hope you do.

0:43:06.239 --> 0:43:09.640
<v Speaker 2>What I'm saying is that I think my car likes

0:43:09.640 --> 0:43:11.560
<v Speaker 2>you better, which doesn't seem fair.

0:43:11.680 --> 0:43:14.239
<v Speaker 3>So your your phone doesn't connect to the bluetooth, it.

0:43:14.200 --> 0:43:18.440
<v Speaker 2>Gets kicked off by yours. Like you've basically hacked me.

0:43:19.080 --> 0:43:23.000
<v Speaker 2>You're a hacker, now hack Yeah, anyway, This dude, Leonard

0:43:23.040 --> 0:43:28.040
<v Speaker 2>Wooters is a security research at ku Leuvin University in Belgium.

0:43:28.280 --> 0:43:33.359
<v Speaker 2>June twenty twenty two, he exploited vulnerabilities in Tesla's Bluetooth

0:43:33.960 --> 0:43:37.880
<v Speaker 2>low energy keyless entry system. So we've gone through all

0:43:37.920 --> 0:43:40.480
<v Speaker 2>these other ways in now we got Bluetooth. So he

0:43:40.520 --> 0:43:43.160
<v Speaker 2>had like what's called a relay attack. He could unlock

0:43:43.239 --> 0:43:46.200
<v Speaker 2>and start a Tesla both model three and Model y

0:43:46.960 --> 0:43:49.880
<v Speaker 2>by relaying signals from the owner's phone or key card.

0:43:50.440 --> 0:43:53.120
<v Speaker 2>And he could do this even if it was inside

0:43:53.120 --> 0:43:56.000
<v Speaker 2>a nearby building. Obviously not in a fair date box.

0:43:57.239 --> 0:44:01.880
<v Speaker 2>So the bl systems there intercepted using cheap off the

0:44:01.880 --> 0:44:05.080
<v Speaker 2>shelf hard where like the Oakland car thieves use. And

0:44:05.320 --> 0:44:07.440
<v Speaker 2>it's basically the same thing. You get there, you pick

0:44:07.520 --> 0:44:10.080
<v Speaker 2>up the signal, you clone it. So he's unlocking doors,

0:44:10.080 --> 0:44:13.520
<v Speaker 2>you start in the car driving away. Tesla, though, didn't

0:44:13.560 --> 0:44:17.800
<v Speaker 2>consider it a flaw in its system, because the ble

0:44:18.040 --> 0:44:21.360
<v Speaker 2>relay attacks are a known risk with passive entry systems.

0:44:21.400 --> 0:44:25.440
<v Speaker 2>They're like, it's not just us all through the Oakland Hills.

0:44:26.400 --> 0:44:29.200
<v Speaker 2>So he was like, this guy, this hacker recommended that

0:44:29.200 --> 0:44:32.360
<v Speaker 2>people turn off passive entry or use in a Tesla

0:44:32.520 --> 0:44:36.440
<v Speaker 2>pin to drive like a personal identification number, requiring a

0:44:36.480 --> 0:44:37.480
<v Speaker 2>code to be able to drive.

0:44:37.600 --> 0:44:39.799
<v Speaker 3>I need like two factor authentication to get into my car.

0:44:40.000 --> 0:44:43.760
<v Speaker 2>Is such a hassle to get in the car. Nobody

0:44:43.800 --> 0:44:46.319
<v Speaker 2>listened to this guy. Everyone's like, whatever, I.

0:44:46.320 --> 0:44:48.360
<v Speaker 3>Will leave websites if I have to get on my iPad.

0:44:48.400 --> 0:44:50.279
<v Speaker 3>I'm like, Daily Beast, why are you making me go

0:44:50.320 --> 0:44:51.000
<v Speaker 3>to my iPad?

0:44:51.040 --> 0:44:53.319
<v Speaker 2>No, big, nope, how about do.

0:44:53.280 --> 0:44:55.680
<v Speaker 3>I want to read this story to own? They're back

0:44:55.760 --> 0:44:56.720
<v Speaker 3>the super Bowl of hacks.

0:44:57.040 --> 0:45:00.480
<v Speaker 2>They went after Tesla again in twenty twenty five. The

0:45:00.880 --> 0:45:07.080
<v Speaker 2>Sinactive team, that's Thomas Imbert, Vincent Dehores, David Barrard. They

0:45:07.120 --> 0:45:13.719
<v Speaker 2>targeted Tesla's vehicle control system Electronic controller VC secure. It's

0:45:13.760 --> 0:45:17.040
<v Speaker 2>a critical module in the Tesla Model three that's responsible

0:45:17.080 --> 0:45:21.680
<v Speaker 2>for security functions like immobilization, door locking and then handling

0:45:21.800 --> 0:45:24.240
<v Speaker 2>data from the tire pressure monitoring system.

0:45:24.360 --> 0:45:29.400
<v Speaker 3>So they turned the security specialist into the vulnerability. Yes, interesting, And.

0:45:29.400 --> 0:45:32.080
<v Speaker 2>They did that at pone to Own Automotive twenty twenty

0:45:32.080 --> 0:45:33.280
<v Speaker 2>five in Tokyo.

0:45:32.920 --> 0:45:33.640
<v Speaker 3>Twenty twenty five.

0:45:34.520 --> 0:45:36.400
<v Speaker 2>This is recent, this is earlier this year. So just

0:45:36.440 --> 0:45:39.000
<v Speaker 2>like in the other cases, they used Bluetooth, they got

0:45:39.040 --> 0:45:40.640
<v Speaker 2>into the can.

0:45:40.360 --> 0:45:41.840
<v Speaker 3>But got that can bus.

0:45:42.160 --> 0:45:45.200
<v Speaker 2>Get all on the bus. Maybe if they'd had some

0:45:45.360 --> 0:45:48.000
<v Speaker 2>heap exploitation going on, we wouldn't be in this situation.

0:45:48.040 --> 0:45:48.920
<v Speaker 3>Yeah, that's what I'm thinking.

0:45:49.719 --> 0:45:52.920
<v Speaker 2>If you can access the ratchet router with the VPN

0:45:53.040 --> 0:45:57.319
<v Speaker 2>card and so on, case closed. So now there was

0:45:57.360 --> 0:46:00.360
<v Speaker 2>also a time that Tesla itself, not the cars, got ACKed.

0:46:00.880 --> 0:46:04.800
<v Speaker 2>Two former Tesla employees who were unnamed in public filings.

0:46:04.800 --> 0:46:08.480
<v Speaker 2>They leaked over one hundred gigabytes of internal data to

0:46:08.560 --> 0:46:11.399
<v Speaker 2>a German media outlet, and that all came to light

0:46:11.400 --> 0:46:13.680
<v Speaker 2>in August of twenty twenty three, but the breach had

0:46:13.719 --> 0:46:14.839
<v Speaker 2>occurred earlier that year.

0:46:14.880 --> 0:46:16.480
<v Speaker 3>Did they use a car to hack Tesla?

0:46:16.640 --> 0:46:18.360
<v Speaker 2>They hacked Tesla with a Tesla?

0:46:18.680 --> 0:46:18.960
<v Speaker 3>Wow?

0:46:19.080 --> 0:46:23.040
<v Speaker 2>No, I don't know. Anyway, they got into the Tesla servers.

0:46:23.680 --> 0:46:30.600
<v Speaker 2>They leaked autopilot system secrets. Oh, good for them, customer secrets,

0:46:31.000 --> 0:46:38.080
<v Speaker 2>customer personally identifiable information. That's bad, employee records that's not good.

0:46:38.520 --> 0:46:41.640
<v Speaker 2>And then some of the leaked documents allegedly detailed quote

0:46:41.680 --> 0:46:46.400
<v Speaker 2>Tesla crash reports, I'm happier with that internal discussions on

0:46:46.520 --> 0:46:51.960
<v Speaker 2>auto pilot related accident. No, the internal discussions about them.

0:46:52.000 --> 0:46:54.120
<v Speaker 2>So they're like whatever, They could look like a loser anyway,

0:46:54.160 --> 0:46:56.319
<v Speaker 2>you know what I mean, Like I'm guessing. I don't know.

0:46:57.200 --> 0:47:00.759
<v Speaker 2>So Tesla immediately took legal action. They four the ex

0:47:00.760 --> 0:47:04.960
<v Speaker 2>employees to surrender devices and data, and they notified affected

0:47:05.000 --> 0:47:07.600
<v Speaker 2>individuals of the breach. I mean, this isn't like a

0:47:07.600 --> 0:47:11.680
<v Speaker 2>traditional software hack, but it exposed highly sensitive vehicle systems

0:47:11.680 --> 0:47:17.440
<v Speaker 2>and customer data, major insider cybersecurity threat Sounds like it's

0:47:17.520 --> 0:47:22.000
<v Speaker 2>like our cars are now rolling cybersecurity threats, Like we

0:47:22.120 --> 0:47:23.880
<v Speaker 2>basically drive around in big computers.

0:47:23.960 --> 0:47:26.680
<v Speaker 3>Yours are. Yeah, I'm over here in a seventy eight

0:47:26.680 --> 0:47:27.480
<v Speaker 3>catalyg I know.

0:47:27.440 --> 0:47:30.240
<v Speaker 2>It's You're so lucky. It's not just the physical actions

0:47:30.280 --> 0:47:32.360
<v Speaker 2>of the car that's vulnerable. Like we have all this

0:47:32.480 --> 0:47:35.440
<v Speaker 2>personal information. Look at me, I'm getting text messages.

0:47:36.160 --> 0:47:37.040
<v Speaker 3>Text with your car.

0:47:37.640 --> 0:47:39.759
<v Speaker 2>I think that's wild to me. Yeah, I think that's

0:47:39.760 --> 0:47:42.800
<v Speaker 2>where the Democratic Party keeps getting my information to text

0:47:42.800 --> 0:47:49.080
<v Speaker 2>mealy anytime anything happens. So cars they collect GPS, location history,

0:47:49.160 --> 0:47:51.880
<v Speaker 2>call logs, contacts. You know, you can load your contacts

0:47:51.880 --> 0:47:54.040
<v Speaker 2>from your phone into your car, so your car can

0:47:54.120 --> 0:47:56.160
<v Speaker 2>call I guess voice recordings.

0:47:56.280 --> 0:47:57.960
<v Speaker 5>They can log your behavior and give.

0:47:57.840 --> 0:47:59.280
<v Speaker 2>It to insurance companies.

0:47:59.480 --> 0:47:59.719
<v Speaker 3>Wow.

0:48:00.320 --> 0:48:02.319
<v Speaker 2>The biggest thread of this, I think is having your

0:48:02.320 --> 0:48:04.680
<v Speaker 2>information sold to marketers and corporations.

0:48:04.719 --> 0:48:05.680
<v Speaker 3>Sure, that too.

0:48:06.400 --> 0:48:08.880
<v Speaker 2>Ripe for criminal tinkering, of course, but it could go

0:48:08.960 --> 0:48:11.960
<v Speaker 2>beyond street crime because think about it, like nation state

0:48:12.000 --> 0:48:14.880
<v Speaker 2>actors could target infrastructure like fleet vehicles.

0:48:15.000 --> 0:48:17.480
<v Speaker 3>Oh yeah, I're also like the partner of somebody who

0:48:17.480 --> 0:48:19.520
<v Speaker 3>works for the government, and then they can just be

0:48:19.600 --> 0:48:21.880
<v Speaker 3>in the car talking on their phone making safe and

0:48:21.920 --> 0:48:23.040
<v Speaker 3>all of a sudden, other cars.

0:48:22.840 --> 0:48:26.200
<v Speaker 2>Listening to Oh yeah, terrorists could hijack cars for sabotage.

0:48:26.680 --> 0:48:28.759
<v Speaker 2>What I'm trying to say is that we need to

0:48:28.800 --> 0:48:31.440
<v Speaker 2>go back to an agrarian society and all ride bikes.

0:48:32.000 --> 0:48:32.480
<v Speaker 3>I love that.

0:48:32.680 --> 0:48:34.560
<v Speaker 2>Make it stop, everyone on a bike. I don't want

0:48:34.560 --> 0:48:36.279
<v Speaker 2>to do this anymore. That's what I'm trying to say.

0:48:37.160 --> 0:48:39.040
<v Speaker 2>And with that, I'm going to go get into my car,

0:48:39.560 --> 0:48:42.640
<v Speaker 2>listen to satellite radio, call my mom via bluetooth on

0:48:42.719 --> 0:48:45.680
<v Speaker 2>the stereosystem unless you hijacket, and then I'm going to

0:48:45.800 --> 0:48:47.840
<v Speaker 2>use my GPS to go do crimes in the woods.

0:48:48.160 --> 0:48:51.520
<v Speaker 2>So just take the edge off, Zarin. What's your ridiculous takeaway?

0:48:52.000 --> 0:48:54.400
<v Speaker 3>You know, as I've complained about it often exact to

0:48:54.440 --> 0:48:57.359
<v Speaker 3>deal with them. Both of my parents are Luddites, right.

0:48:57.480 --> 0:49:00.400
<v Speaker 3>They neither one has an iPhone or any Android. They

0:49:00.440 --> 0:49:02.920
<v Speaker 3>both have flip phones. They won't do email. My mother

0:49:03.040 --> 0:49:06.200
<v Speaker 3>still has an Aol account, like you know, their total

0:49:06.280 --> 0:49:08.759
<v Speaker 3>bloods with the fact that they have computers is like

0:49:08.840 --> 0:49:14.759
<v Speaker 3>a major step and unfortunately I think they're right well

0:49:15.280 --> 0:49:18.800
<v Speaker 3>kills me right. Yeah, she pays like whatever, fifty dollars

0:49:18.840 --> 0:49:21.239
<v Speaker 3>a month to do like four things or whatever. I'm like,

0:49:21.400 --> 0:49:24.160
<v Speaker 3>what is wrong with you? What is your ridiculous take away? Elizabeth?

0:49:24.239 --> 0:49:27.880
<v Speaker 2>Where did this takeaway? Is that computers bad that I

0:49:28.000 --> 0:49:31.600
<v Speaker 2>need them. We all do, so, Dave, can I please

0:49:31.680 --> 0:49:32.439
<v Speaker 2>have a talk back?

0:49:32.719 --> 0:49:35.960
<v Speaker 3>Oh yeah, oh.

0:49:37.960 --> 0:49:42.879
<v Speaker 4>My god, I love get.

0:49:47.080 --> 0:49:50.000
<v Speaker 6>Hi Elizabeth Saron and producer d This is Ali from

0:49:50.040 --> 0:49:53.759
<v Speaker 6>South Carolina. I have loved the show for years now

0:49:53.840 --> 0:49:57.520
<v Speaker 6>and I just listened to the wig jacking episode and

0:49:58.520 --> 0:50:01.600
<v Speaker 6>then about a day later, happy to come across an

0:50:01.680 --> 0:50:04.920
<v Speaker 6>image of the painting a Sundae on lagrange jat or

0:50:04.960 --> 0:50:07.920
<v Speaker 6>however you pronounce it. Who knows who cares? And as

0:50:07.960 --> 0:50:10.920
<v Speaker 6>I'm sure you know, in the bottom corner of that painting,

0:50:11.320 --> 0:50:14.320
<v Speaker 6>there is a little monkey on a leash and a

0:50:14.480 --> 0:50:18.600
<v Speaker 6>small dog staring out. And all I could think about

0:50:18.880 --> 0:50:21.480
<v Speaker 6>from that little monkey and little dog is that they

0:50:21.840 --> 0:50:24.880
<v Speaker 6>were scoping out the scene looking for their next heist

0:50:25.040 --> 0:50:27.120
<v Speaker 6>because they'd had to move on from.

0:50:27.000 --> 0:50:27.759
<v Speaker 2>Their wig work.

0:50:27.880 --> 0:50:31.040
<v Speaker 6>So maybe they were on hat stealing or just there

0:50:31.160 --> 0:50:33.880
<v Speaker 6>to cause general ruckus. I don't know, but I support

0:50:33.920 --> 0:50:37.399
<v Speaker 6>them either way. Anyways, Love you guys, love your show.

0:50:37.520 --> 0:50:39.880
<v Speaker 6>Thanks so much for all you do, and see you

0:50:39.920 --> 0:50:40.800
<v Speaker 6>again next crime.

0:50:42.840 --> 0:50:43.600
<v Speaker 3>I love that.

0:50:43.800 --> 0:50:46.040
<v Speaker 2>This is this is what the power of good art

0:50:46.200 --> 0:50:50.160
<v Speaker 2>right that tells you this story And I love this.

0:50:50.400 --> 0:50:52.680
<v Speaker 2>I love your your so perceptive picking up all the

0:50:52.719 --> 0:50:58.720
<v Speaker 2>little bits and bobs and the sool. That's it for today.

0:50:59.239 --> 0:51:01.839
<v Speaker 2>You can find us online at ridiculous Crime dot com.

0:51:02.160 --> 0:51:02.840
<v Speaker 5>This just in.

0:51:03.800 --> 0:51:08.040
<v Speaker 2>The website won the Hollywood Foreign Press Hackproof Award. They

0:51:08.120 --> 0:51:12.239
<v Speaker 2>have declared our website hackproof. Nice I know, good job team.

0:51:12.760 --> 0:51:16.000
<v Speaker 2>We're also at Ridiculous Crime on both Blue Sky Instagram.

0:51:16.120 --> 0:51:19.640
<v Speaker 2>We're on YouTube at Ridiculous Crime Pod. You can email

0:51:19.760 --> 0:51:22.160
<v Speaker 2>us at ridiculous Crime at gmail dot com, leave a

0:51:22.239 --> 0:51:31.279
<v Speaker 2>talkback on the iHeart app reach out. Ridiculous Crime is

0:51:31.320 --> 0:51:34.560
<v Speaker 2>hosted by Elizabeth Dutton and Zaren Burnett, produced and edited

0:51:34.600 --> 0:51:39.640
<v Speaker 2>by HackMaster Dave Cousten, starring Analys Rutger. This Judith research

0:51:39.760 --> 0:51:43.759
<v Speaker 2>is by aftermarket Penny Farthing Bluetooth installer Marissa Brown. The

0:51:43.880 --> 0:51:47.040
<v Speaker 2>theme song is by hacking duo The Bongo Boys aka

0:51:47.280 --> 0:51:50.600
<v Speaker 2>Thomas Lee and Travis Dutton. Post wardrobe is provided by

0:51:50.680 --> 0:51:54.239
<v Speaker 2>Botany five hundred guest here and makeup by Sparkleshot and

0:51:54.560 --> 0:51:59.800
<v Speaker 2>Mister Audrey. Executive producers are Exhausted Tesla Legal Team, Ben Bowen.

0:52:00.080 --> 0:52:11.600
<v Speaker 4>That's Old Brad, Ridicous Crime, Say it one more Timequeous Crime.

0:52:12.640 --> 0:52:15.960
<v Speaker 1>Ridiculous Crime is a production of iHeartRadio four more podcasts

0:52:15.960 --> 0:52:19.040
<v Speaker 1>from my heart Radio. Visit the iHeartRadio app, Apple Podcasts,

0:52:19.160 --> 0:52:20.920
<v Speaker 1>or wherever you listen to your favorite shows.