Detroit man steals 800 gallons using Bluetooth to hack gas pumps at station

L4sBot@lemmy.worldmod to Technology@lemmy.world – 632 points –
Detroit man steals 800 gallons using Bluetooth to hack gas pumps at station
fox2detroit.com

Detroit man steals 800 gallons using Bluetooth to hack gas pumps at station::undefined

131

You are viewing a single comment

Why is that even possible?

Because people think security and privacy are a joke, and it’s times like this where it shows.

Is that the Polish train thing where you can literally send an emergency stop command with a walkie talkie?

That is funny lol but annoying for the passengers

Yeah.

Annoying for NATO, moving supplies to Ukraine through Poland, too.

Here is an alternative Piped link(s):

For example.

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I'm open-source; check me out at GitHub.

Hardware security is still overlooked a lot in the tech industry, hence there are a ton of hardware and mechanical stuff out there that are made “smarter” but still barely have any security controls. That’s why there’s the saying “The S in IoT stands for security”. Bluetooth in itself is not secure, and they probably have a very basic control where the pump is unlocked remotely via a bluetooth device.

I very distinctly remember early bluetooth amongst other interfaces explicitly discussed in college as an example of "enabling things to understand eachother, including things that shouldn't." It's up to the developer to protect their data.

There is a problem here that isn't just a hardware/software issue, it's a "I'm not gonna worry about it" problem that leads to security issues.