DEF CON 23 - Samy Kamkar - Drive it like you Hacked it: New Attacks and Tools to Wireles

Sdílet
Vložit
  • čas přidán 25. 06. 2024
  • Gary Numan said it best. Cars. They’re everywhere. You can hardly drive down a busy freeway without seeing one. But what about their security?
    In this talk I’ll reveal new research and real attacks in the area of wirelessly controlled gates, garages, and cars. Many cars are now controlled from mobile devices over GSM, while even more can be unlocked and ignitions started from wireless keyfobs over RF. All of these are subject to attack with low-cost tools (such as RTL-SDR, GNU Radio, HackRF, Arduino, and even a Mattel toy).
    We will investigate how these features work, and of course, how they can be exploited. I will be releasing new tools and vulnerabilities in this area, such as key-space reduction attacks on fixed-codes, advanced "code grabbers" using RF attacks on encrypted and rolling codes, and how to protect yourself against such issues.
    By the end of this talk you’ll understand not only how vehicles and the wirelessly-controlled physical access protecting them can be exploited, but also learn about various tools for car and RF research, as well as how to use and build your own inexpensive devices for such investigation.
    Ladies and gentlemen, start your engines. And other people’s engines.
    Samy Kamkar is a security researcher, best known for creating The MySpace Worm, one of the fastest spreading viruses of all time. He (attempts to) illustrate terrifying vulnerabilities with playfulness, and his exploits have been branded:
    “Controversial”, -The Wall Street Journal
    “Horrific”, -The New York Times
    “Now I want to fill my USB ports up with cement”, -Gizmodo
    He’s demonstrated usurping typical hardware for surreptitious means such as with KeySweeper, turning a standard USB wall charger into a covert, wireless keyboard sniffer, and SkyJack, a custom drone which takes over any other nearby drones allowing them to be controlled as a massive zombie swarm. He’s exposed issues around privacy, such as by developing the Evercookie which appeared in a top-secret NSA document revealed by Edward Snowden, exemplifying techniques used by governments and corporations for clandestine web tracking, and has discovered and released research around the illicit GPS and location tracking performed by Apple, Google and Microsoft mobile devices. He continues to produce new research and tools for the public as open source and open hardware.
    Twitter: @samykamkar
  • Věda a technologie

Komentáře • 42

  • @disarmyouwitha
    @disarmyouwitha Před 7 lety +113

    Samy is always a very entertaining speaker. :3
    But most of all.. Samy is my hero.

  • @token112
    @token112 Před 8 lety +46

    Samy is my hero

  • @anonymousanonymous-ye5hi
    @anonymousanonymous-ye5hi Před 8 lety +18

    SAMMY IS MY HERO

  • @L0t3x
    @L0t3x Před 8 lety +28

    but most of all, samy is my hero

  • @geraldellis1177
    @geraldellis1177 Před 7 lety +13

    samy is my hero

  • @astra_joe
    @astra_joe Před 5 lety +2

    Samy Kamkar is a genius mind & great entertainer!

  • @Syncopator
    @Syncopator Před 8 lety +4

    Awesome, great talk.

  • @MarkPashmfouroush
    @MarkPashmfouroush Před 8 lety +5

    Finally Samy!

  • @cipheroth
    @cipheroth Před 4 lety +1

    The Great Sammy !!!

  • @freem4nn129
    @freem4nn129 Před 5 lety +2

    i love samy

  • @blazer6248
    @blazer6248 Před 5 lety +2

    This is a good one to watch after the vid you did with what's his face where you hacked his garage doors with the IM Me.

  • @jordanblair5474
    @jordanblair5474 Před 7 lety +1

    This is a really cool talk. I enjoyed seeing the Matel IM-ME be modified into a useful tool .

  • @bart8P
    @bart8P Před 7 lety +6

    to be totally fair, no native english speaker can pronounce "De Bruijn "correctly, ij is a unique Dutch sound.

  • @katiedonovanAlt
    @katiedonovanAlt Před 2 lety

    27:33 ALWAYS the right answer.

  • @Frosty-oj6hw
    @Frosty-oj6hw Před 8 lety +3

  • @chaotemagick3
    @chaotemagick3 Před 3 lety +1

    I know none of this is illegal but how close does it come? Can anyone talk briefly on how illegality applies to this field

  • @Marienkarpfen
    @Marienkarpfen Před 5 lety +1

    33:20

  • @user-fw9cw2oy6e
    @user-fw9cw2oy6e Před 6 lety +1

    Do you remember last year when it can be said, ROLLJAM to do the smaller, as the size of a remote? Do you have any samples? Can be sold to Southeast Asian countries? I want to do this business! Are you interested in?

  • @ameen5785
    @ameen5785 Před 7 lety

    16:51 we'll do it live. lol

  • @Baegus
    @Baegus Před 6 lety

    Facebook hack 2017:
    Samy is my city

  • @alockworkorange7296
    @alockworkorange7296 Před 3 lety

    He missed a great opportunity to put EFF about you! Instead of below

  • @joseaguirre9828
    @joseaguirre9828 Před 7 lety

    hy Samy I would like to buy a rolljam divice where can I buy it

  • @leocurious9919
    @leocurious9919 Před 8 lety

    He didnt put Obama in the "Thank you" at the end :(

    • @mipmipmipmipmip
      @mipmipmipmipmip Před 7 lety

      Leo Curious Of course, because Obama made garage door openers less secure than a two-character password.

    • @groowy
      @groowy Před 5 lety +1

      And so hackers should thank him :)

  • @mariarahelvarnhagen2729
    @mariarahelvarnhagen2729 Před 11 měsíci

    Drive It Faster

  • @AB-these-handles-are-stupid

    I'm pausing cause I smell a Rick roll coming.

  • @micheledwards9309
    @micheledwards9309 Před 6 lety

    I won to a roll jam please call me

  • @OcRefrig
    @OcRefrig Před 6 lety

    So, i just watched the first 10 minutes of this video. So, it looks like this channell is dedicated to thieves and how to steal stuff. Do i have that right ?

    • @htiffirg1987
      @htiffirg1987 Před 6 lety +6

      That is an oversimplification. The entire channel is dedicated to security and security testing. No security system is infallible, if you think it is then you're overlooking something. These researchers test and look at vulnerabilities in systems and try to point out any severe flaws. Often they will contact the companies and try to tell them about a vulnerability to fix, such as what he did with GM at czcams.com/video/UNgvShN4USU/video.html and he provided them with info to fix a vulnerability.
      A lot of these guys work in security setting up and maintaining the digital or physical security of private companies. Some of them even work with the government. Some of them are actually thieves, though what they steal is usually not cars and such.
      Still, the main purpose of these talks is to educate about security and security vulnerabilities. Not just thievery.

  • @edbegley5858
    @edbegley5858 Před 7 lety

    windows babbies BTFO

  • @JamieTransNyc
    @JamieTransNyc Před 5 lety +1

    So this is EXACTLY the same presentation Samy made at APPSEC 2016 ....... boring..

  • @anonymousanonymous-ye5hi
    @anonymousanonymous-ye5hi Před 8 lety +9

    SAMMY IS MY HERO

  • @jamisusijarvi646
    @jamisusijarvi646 Před 6 lety +4

    Samy is my hero

  • @isaaclammers8328
    @isaaclammers8328 Před 4 lety +1

    Samy is my hero