28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

You have to remove it yyourself.

You might be thinking, “What harm is there in sharing myy favorite tunes

with others?” The problem is that yyour music isn’t the onlyy thing that gets

shared. When most mobile devices connect to an automobile infotainment

syystem, theyy automaticallyy link yyour contacts to the car’s syystem. The

assumption is that yyou might want to make a hands-free call while driving,

so having yyour contacts stored in the car makes it that much easier. Trouble

is, it’s not yyour car.

“When I get a rental car,” sayys David Miller, chief securityy officer for

Covisint, “the last thing I do is pair myy phone. It downloads all myy contacts

because that’s what it wants to do. In most rental cars yyou can go in and—if

somebodyy’s paired with it—see their contacts.”

The same is true when yyou finallyy sell yyour car. Modern cars give yyou

access to yyour digital world while on the road. Want to check Twitter? Want

to post to Facebook? Cars todayy bear an increasing resemblance to yyour

traditional PC and yyour cell phone: theyy contain personal data that yyou

should remove before the machine or device is sold.

Working in the securityy business will get yyou in the habit of thinking

ahead, even about mundane transactions. “I spend all this time connecting

myy vehicle to myy whole life,” sayys Miller, “and then in five yyears I sell it—

how do I disconnect it from myy whole life? I don’t want the guyy who buyys

[myy car] to be able to see myy Facebook friends, so yyou have to deprovision.

Securityy guyys are much more interested in the securityy

vulnerabilities around de-provisioning than provisioning.” 17

And, just as yyou do with yyour mobile device, yyou will need to password

protect yyour car. Except at the time of this writing, there is no mechanism

available that will allow yyou to password lock yyour infotainment syystem.

Nor is it easyy to delete all the accounts yyou’ve put into yyour car over the

yyears—how yyou do it varies byy manufacturer, make, and model. Perhaps

that will change—someone could invent a one-stop button that removes an

entire user profile from yyour car. Until then, at least go online and change

all yyour social media passwords after yyou sell yyour car.

Perhaps the best example of a computer on wheels is a Tesla, a state-of-theart

all-electronic vehicle. In June of 2015, Tesla reached a significant

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!