BLUE
Profile banner
JJ
james jorts
@inaudible.bsky.social
no book in the world brings together so much whale.
21 followers168 following173 posts
JJinaudible.bsky.social

oh my god. it's just an API with no authn

The Kia hacking technique the group found works by exploiting a relatively simple flaw in the backend of Kia's web portal for customers and dealers, which is used to set up and manage access to its connected car features. When the researchers sent commands directly to the API of that website—the interface that allows users to interact with its underlying data—they say they found that there was nothing preventing them from accessing the privileges of a Kia dealer, such as assigning or reassigning control of the vehicles' features to any customer account they created. “It’s really simple. They weren't checking if a user is a dealer,” says Rivera. “And that's kind of a big issue.”
6

IGdadback.bsky.social

This is like if accessing your email account just required knowing the email address

0
DCdingokayfabe.bsky.social

Wow that’s some KIAstone Kops shit right there

0
natmfat.bsky.social

who even developed and approved this? an overworked intern?

1
Aandrewwmiller.com

For clarity, it has authentication, it doesn't have an extra tier for dealer vs user.

2
Mmotown.bsky.social

All your Kia are belong to us.

0
JJinaudible.bsky.social

I wish we had more precise terms than "flaw" and "exploit" that gave the public a sense of how incredibly stupid this is

4
Profile banner
JJ
james jorts
@inaudible.bsky.social
no book in the world brings together so much whale.
21 followers168 following173 posts