According to Forbes Magazine, More than two million vehicles may be at risk thanks to insecure firmware in Progressive Insurance’s “Snapshot” dongle – a device used to track driving habits for risk assessment and premium adjustment.
Digital Bond Labs security researcher Corey Thuen discovered the vulnerability that can unlock car doors, start a car and gather engine information.
Snapshot’s firmware contains no validation or signing of updates, secure boot, cellular authentication, secure communications or encryption. A skilled hacker could control a vehicle remotely, Thuen said, but a remote attack is only possible if a u-blox modem, which handles connections between the dongle and Progressive’s servers, is compromised.
Jeff Jones is a Cyber Security Architect and Ethical Hacker for Topgallant Partners. He has been in Data Communications for over 35 years. He responsible for all day-to-day operations, technical consulting, and security design for Topgallant.
His expertise is in Security Program Design, Security Risk Analysis and Assessment and Cyber Security Testing to include Penetration Testing, Vulnerability Testing, Social Engineering, Phishing, Wi-Fi Exploitations, Password Cracking, Man-in-the Middle Attacks and Web Application Hacking.
He has a M.A. in Computer Resources Management from Webster University and a B.A. in Journalism from Purdue University. He is also a terrible golfer.
Our website uses cookies from third party services to improve your browsing experience. Read more about this and how you can control cookies by clicking "Privacy Preferences".