Kompas.com - HP belakangan tersandung sejumlah masalah sekuriti. November lalu, perusahaan tersebut dituding diam-diam memasang spyware di PC Windows buatannya.
Showing posts with label Security Vulnerability. Show all posts
Showing posts with label Security Vulnerability. Show all posts
Dec 28, 2017
Sep 8, 2016
Dropbox Diretas, 68 Juta "Password" Bocor
Kompas.com - Data username dan password dari 68 juta pengguna Dropbox telah dicuri oleh hacker yang meretas sistem internal layanan cloud storage itu.
Dec 12, 2015
Dell Mengaku Laptopnya Bawa Malware dari Pabrik
Kompas.com - Dell mengaku bahwa ada sejumlah komputer buatannya yang dijual sudah terkontaminasi malware mirip Superfish. Mereka berjanji akan segera merilis solusi agar pengguna bisa bebas dari program jahat tersebut.
Jul 29, 2015
Text Message Could Hijack Your Android Phone
Tomsguide.com - All a hacker needs to get access to most Android phones is the telephone number tied to the device, according to security researcher Joshua Drake. Exploits Drake revealed today (July 27) don't require a user to open a corrupted website or download a malicious attachment; a phone simply needs to be able to accept texts and have Stagefright (Android's default media playback engine) installed.
Drake is the VP of Platform Research and Exploitation at Zimperium, a mobile-security firm based in Tel Aviv and San Francisco. A Zimperium company blog post stated that the Stagefright flaws are "the worst Android vulnerabilities discovered to date," due in part to how widespread Stagefright is. They estimate "95 percent of Android devices, an estimated 950 million devices," are at risk until a patch is applied.
Stagefright, which has been a part of Android the release of Android 2.2 Froyo in 2010, is still present in the current Android 5.1.1 Lollipop. Regarding the upcoming version of Android, Drake pointed out on Twitter that "Android M uses Stagefright," though he assured users that they should not worry, continuing by saying "I expect that the release version of Android M will ship with these bugs fixed already."
More recent versions of Android have been engineered to keep application data separated, but the further back one's device is in the platform's history, the more access hackers could gain to one's phone. The turning point for Android security seems to be around Android 4.1 Jelly Bean, with Zimperium noting that pre-4.1 devices "(roughly 11 percent of devices) are at the worst risk due to inadequate exploit mitigations."
(The Zimperium post noted that SilentCircle's Blackphone handset, which runs a customized, "hardened" version of Android called PrivatOS, was already protected against Stagefright exploits.)
While Google worked with Drake to deftly create a patch to fix the Stagefright flaws, users now need Android device manufacturers to push the update down to devices. Those who have watched carriers and manufacturers take ages to issue updates may not hold their breath waiting for the fix.
Not only are devices running older software more at risk, but according to Zimperium, "Devices older than 18 months are unlikely to receive an update at all."
Drake is the VP of Platform Research and Exploitation at Zimperium, a mobile-security firm based in Tel Aviv and San Francisco. A Zimperium company blog post stated that the Stagefright flaws are "the worst Android vulnerabilities discovered to date," due in part to how widespread Stagefright is. They estimate "95 percent of Android devices, an estimated 950 million devices," are at risk until a patch is applied.
Stagefright, which has been a part of Android the release of Android 2.2 Froyo in 2010, is still present in the current Android 5.1.1 Lollipop. Regarding the upcoming version of Android, Drake pointed out on Twitter that "Android M uses Stagefright," though he assured users that they should not worry, continuing by saying "I expect that the release version of Android M will ship with these bugs fixed already."
More recent versions of Android have been engineered to keep application data separated, but the further back one's device is in the platform's history, the more access hackers could gain to one's phone. The turning point for Android security seems to be around Android 4.1 Jelly Bean, with Zimperium noting that pre-4.1 devices "(roughly 11 percent of devices) are at the worst risk due to inadequate exploit mitigations."
(The Zimperium post noted that SilentCircle's Blackphone handset, which runs a customized, "hardened" version of Android called PrivatOS, was already protected against Stagefright exploits.)
While Google worked with Drake to deftly create a patch to fix the Stagefright flaws, users now need Android device manufacturers to push the update down to devices. Those who have watched carriers and manufacturers take ages to issue updates may not hold their breath waiting for the fix.
Not only are devices running older software more at risk, but according to Zimperium, "Devices older than 18 months are unlikely to receive an update at all."
Jul 26, 2015
Jun 28, 2015
Pre-installed keyboard leaves 600 million Samsung smartphones vulnerable to hackers
Foxnews.com - If you're rocking a Samsung smartphone, you could be vulnerable to hackers, thanks to a preinstalled keyboard on your device.
The vulnerability was discovered by Ryan Welton from mobile security specialists NowSecure. The issue is with the preinstalled SwiftKey keyboard which looks for language pack updates over an unencrypted line. Welton found that a hacker could create a spoof proxy server and send a fake update to the device with malicious code. The hacker could then exploit the device by eavesdropping on incoming and outgoing messages or voice calls, access personal data such as pictures or text messages, tamper with apps, and even install other malicious apps.
Welton first discovered the flaw last year and subsequently notified Samsung in December 2014. Samsung immediately worked on a patch and sent updates to various carriers for devices running Android 4.2 or higher in March 2015. However, it's unknown whether these patches have made their way to devices. Carriers are notorious for taking their time with updates due to their so-called rigorous testing for bugs.
Unfortunately, there is no other fix because users can't simply uninstall the SwiftKey app -- one of the not so joyous benefits of carrier bloatware. Users are still vulnerable even when SwiftKey isn't set as the default keyboard.
What's even scarier about this vulnerability is it even affects the Galaxy S6, which was released in April. Welton detailed this security flaw earlier today at the Blackhat Security Summit in London. He stated that he was able to hack into a Galaxy S6 running on Verizon Wireless. "We can confirm that we have found the flaw still unpatched on the Galaxy S6 for the Verizon and Sprint networks, in off the shelf tests we did over the past couple of days," a NowSecure spokesperson confirmed.
According to the NowSecure website, it's likely that the Galaxy S4 Mini, Galaxy S4, Galaxy S5, and Galaxy S6 are all affected, but it's unclear which carrier-specific models received updates. The site only mentions U.S. carriers, so we aren't sure if owners of international variants need to be worried.
Now before everyone with a Samsung phone goes into a panic attack, we need to point out that chances are rare that your device will be attacked through this vulnerability. A hacker can only use this method via a public Wi-Fi network, like those found at a coffee shop, hotel, or other public spaces. More importantly, a hacker has to have knowledge of this exploit and has to be on the same network as you. Chances are very slim that a hacker who knows about this security flaw will be at your local Starbucks at the same exact time as you.
Nevertheless, a security flaw should never be taken lightly, so NowSecure recommends staying away from public Wi-Fi networks if you have one of these Samsung devices. That might be easier said then done, though, especially for those who are on capped data plans and don't want to use their carrier's mobile network all day. The other thing you can do is contact your carrier and demand that your phone gets updated with the patch if it hasn't already.
The vulnerability was discovered by Ryan Welton from mobile security specialists NowSecure. The issue is with the preinstalled SwiftKey keyboard which looks for language pack updates over an unencrypted line. Welton found that a hacker could create a spoof proxy server and send a fake update to the device with malicious code. The hacker could then exploit the device by eavesdropping on incoming and outgoing messages or voice calls, access personal data such as pictures or text messages, tamper with apps, and even install other malicious apps.
Welton first discovered the flaw last year and subsequently notified Samsung in December 2014. Samsung immediately worked on a patch and sent updates to various carriers for devices running Android 4.2 or higher in March 2015. However, it's unknown whether these patches have made their way to devices. Carriers are notorious for taking their time with updates due to their so-called rigorous testing for bugs.
Unfortunately, there is no other fix because users can't simply uninstall the SwiftKey app -- one of the not so joyous benefits of carrier bloatware. Users are still vulnerable even when SwiftKey isn't set as the default keyboard.
What's even scarier about this vulnerability is it even affects the Galaxy S6, which was released in April. Welton detailed this security flaw earlier today at the Blackhat Security Summit in London. He stated that he was able to hack into a Galaxy S6 running on Verizon Wireless. "We can confirm that we have found the flaw still unpatched on the Galaxy S6 for the Verizon and Sprint networks, in off the shelf tests we did over the past couple of days," a NowSecure spokesperson confirmed.
According to the NowSecure website, it's likely that the Galaxy S4 Mini, Galaxy S4, Galaxy S5, and Galaxy S6 are all affected, but it's unclear which carrier-specific models received updates. The site only mentions U.S. carriers, so we aren't sure if owners of international variants need to be worried.
Now before everyone with a Samsung phone goes into a panic attack, we need to point out that chances are rare that your device will be attacked through this vulnerability. A hacker can only use this method via a public Wi-Fi network, like those found at a coffee shop, hotel, or other public spaces. More importantly, a hacker has to have knowledge of this exploit and has to be on the same network as you. Chances are very slim that a hacker who knows about this security flaw will be at your local Starbucks at the same exact time as you.
Nevertheless, a security flaw should never be taken lightly, so NowSecure recommends staying away from public Wi-Fi networks if you have one of these Samsung devices. That might be easier said then done, though, especially for those who are on capped data plans and don't want to use their carrier's mobile network all day. The other thing you can do is contact your carrier and demand that your phone gets updated with the patch if it hasn't already.
May 31, 2015
"Factory Reset" Android Tidak Hapus Data Rahasia
Kompas.com - Smartphone Android memang memberikan fitur Factory Data Reset untuk mengembalikan kondisi sistem operasi smartphone seperti dari pabriknya. Opsi tersebut sekaligus menghapus data yang tersimpan dalam memori internal smartphone.
Namun dikutip KompasTekno dari Phone Arena, Senin (24/5/2015), baru-baru ini seorang peneliti dari Cambridge University menemukan bahwa data yang telah di-reset itu bisa dikembalikan lagi.
Data yang dimaksud bukan hanya data seperti password akun Google, melainkan juga data foto, pesan teks, daftar kontak, dan media lain yang pernah ditulis dalam memori internal.
Menurut penelitian yang dilakukan oleh pihak universitas, jumlah perangkat yang mereka uji memang hanya sedikit jika dibandingkan dengan jumlah perangkat Android yang ada di pasaran. Namun perangkat-perangkat tersebut banyak digunakan oleh pengguna.
Dengan menguji 21 perangkat buatan lima vendor smartphone berbeda, yang menjalankan sistem operasi Android 2.3 Gingerbread hingga 4.3 Jelly Bean, peneliti masih bisa mengembalikan data setelah smartphone di hard reset.
Peneliti juga mengklaim bahwa 80 persen dari perangkat yang diambil datanya itu juga bisa memberikan akses kepada data Google.
Data tersebut bahkan masih bisa diambil walau telah dienkripsi sebelum dilakukan factory reset. Hal tersebut dimungkinkan sebab penyimpanan flash yang dimiliki smartphone Android memiliki kelemahan.
Selain itu, vendor pembuat smartphone juga jarang ada yang memberikan driver software yang benar-benar bisa menghapus penyimpanan.
Berikut adalah daftar perangkat smartphone yang menurut penelitian dari Cambridge University masih rentan datanya diambil walau telah dilakukan factory reset.
Android 2.2.x Froyo:
HTC Nexus One
Motorola Defy
Android 4.0.x ICS:
HTC Sensation
Samsung Galaxy S3
HTC Desire C
Samsung Galaxy S2
LG Optimus L5
Android 2.3.x Gingerbread:
Samsung Galaxy S+
HTC Wildfire S
HTC Desire S
Samsung Galaxy S
Samsung Galaxy S2
Samsung Galaxy ACE
LG Optimus L3
Nexus S
Android 4.(1-3).x Jelly Bean:
Nexus 4 (2)
Motorola RAZR i
LG Optimus L7
Nexus S
Samsung Galaxy Note
HTC One S
HTC One X
Namun dikutip KompasTekno dari Phone Arena, Senin (24/5/2015), baru-baru ini seorang peneliti dari Cambridge University menemukan bahwa data yang telah di-reset itu bisa dikembalikan lagi.
Data yang dimaksud bukan hanya data seperti password akun Google, melainkan juga data foto, pesan teks, daftar kontak, dan media lain yang pernah ditulis dalam memori internal.
Menurut penelitian yang dilakukan oleh pihak universitas, jumlah perangkat yang mereka uji memang hanya sedikit jika dibandingkan dengan jumlah perangkat Android yang ada di pasaran. Namun perangkat-perangkat tersebut banyak digunakan oleh pengguna.
Dengan menguji 21 perangkat buatan lima vendor smartphone berbeda, yang menjalankan sistem operasi Android 2.3 Gingerbread hingga 4.3 Jelly Bean, peneliti masih bisa mengembalikan data setelah smartphone di hard reset.
Peneliti juga mengklaim bahwa 80 persen dari perangkat yang diambil datanya itu juga bisa memberikan akses kepada data Google.
Data tersebut bahkan masih bisa diambil walau telah dienkripsi sebelum dilakukan factory reset. Hal tersebut dimungkinkan sebab penyimpanan flash yang dimiliki smartphone Android memiliki kelemahan.
Selain itu, vendor pembuat smartphone juga jarang ada yang memberikan driver software yang benar-benar bisa menghapus penyimpanan.
Berikut adalah daftar perangkat smartphone yang menurut penelitian dari Cambridge University masih rentan datanya diambil walau telah dilakukan factory reset.
Android 2.2.x Froyo:
HTC Nexus One
Motorola Defy
Android 4.0.x ICS:
HTC Sensation
Samsung Galaxy S3
HTC Desire C
Samsung Galaxy S2
LG Optimus L5
Android 2.3.x Gingerbread:
Samsung Galaxy S+
HTC Wildfire S
HTC Desire S
Samsung Galaxy S
Samsung Galaxy S2
Samsung Galaxy ACE
LG Optimus L3
Nexus S
Android 4.(1-3).x Jelly Bean:
Nexus 4 (2)
Motorola RAZR i
LG Optimus L7
Nexus S
Samsung Galaxy Note
HTC One S
HTC One X
Apr 15, 2014
Ini Daftar Layanan Internet yang Wajib Ganti "Password"
Kompas.com - Sebuah celah keamanan yang disebut sebagai "heartbleed" ditemukan pada protokol OpenSSL. Sebagian penyedia layanan web yang memakai OpenSSL untuk enkripsi harus menyalurkan patch untuk menangkal kerawanan yang timbul.
Dengan mengeksploitasi celah heartbleed pada OpenSSL, hacker bisa mencuri informasi meskipun sebuah situs atau penyedia layanan sudah melakukan enkripsi (ditandai dengan gambar "gembok" dan prefiks "https:" pada URL).
Masalahnya menjadi besar karena OpenSSL digunakan oleh 66 persen dari seluruh bagian web internet untuk mengenkripsi data sehingga celah keamanan tersebar luas. Nama-nama besar, antara lain Gmail, Facebook, dan Yahoo, ikut terpengaruh.
Dari sisi pengguna, tak ada yang bisa dilakukan untuk mengatasi bug ini kecuali menunggu penyedia layanan bersangkutan agar menambal celah heartbleed (heartbeat), lalu mengganti password untuk berjaga-jaga apabila kata kunci yang lama telah bocor.
Nah, berikut ini daftar beberapa layanan populer yang diketahui memiliki/tidak memiliki celah keamanan heartbeat, sebagaimana dirangkum oleh Mashable.
Daftar lengkap nama layanan yang terkena dampak heartbleed bisa dilihat dalam sebuah daftar yang dibuat pada 8 April. Semenjak daftar tersebut dipublikasikan, beberapa penyedia layanan telah menyalurkan patch untuk menambal celah keamanan yang ada.
Di samping melihat daftar tersebut, untuk memeriksa apakah sebuah situs atau layanan ikut terpengaruh oleh heartbleed atau tidak, pengguna internet bisa menggunakan sebuah tool dari Last Pass.
Dengan mengeksploitasi celah heartbleed pada OpenSSL, hacker bisa mencuri informasi meskipun sebuah situs atau penyedia layanan sudah melakukan enkripsi (ditandai dengan gambar "gembok" dan prefiks "https:" pada URL).
Masalahnya menjadi besar karena OpenSSL digunakan oleh 66 persen dari seluruh bagian web internet untuk mengenkripsi data sehingga celah keamanan tersebar luas. Nama-nama besar, antara lain Gmail, Facebook, dan Yahoo, ikut terpengaruh.
Dari sisi pengguna, tak ada yang bisa dilakukan untuk mengatasi bug ini kecuali menunggu penyedia layanan bersangkutan agar menambal celah heartbleed (heartbeat), lalu mengganti password untuk berjaga-jaga apabila kata kunci yang lama telah bocor.
Nah, berikut ini daftar beberapa layanan populer yang diketahui memiliki/tidak memiliki celah keamanan heartbeat, sebagaimana dirangkum oleh Mashable.
Daftar lengkap nama layanan yang terkena dampak heartbleed bisa dilihat dalam sebuah daftar yang dibuat pada 8 April. Semenjak daftar tersebut dipublikasikan, beberapa penyedia layanan telah menyalurkan patch untuk menambal celah keamanan yang ada.
Di samping melihat daftar tersebut, untuk memeriksa apakah sebuah situs atau layanan ikut terpengaruh oleh heartbleed atau tidak, pengguna internet bisa menggunakan sebuah tool dari Last Pass.
Jan 5, 2014
Use This Tool to See If Your Snapchat Info Was Leaked
Cnn.com - Use Snapchat? Hear about the leak? If so, you’ll want to check to see if your username and phone number have made their way out into the wild (spoiler: probably).
Security firm LastPass has cobbled together a tool you can use to input your Snapchat username to see if it’s been leaked alongside your phone number. LastPass also recommends deleting your Snapchat account since you can’t change usernames, and to change the password associated with your account just as a safety precaution.
Security firm LastPass has cobbled together a tool you can use to input your Snapchat username to see if it’s been leaked alongside your phone number. LastPass also recommends deleting your Snapchat account since you can’t change usernames, and to change the password associated with your account just as a safety precaution.
Dec 11, 2013
Malware Bisa Kirim Data Curian Tanpa Internet
Kompas.com - Selama ini program jahat atau malware selalu membutuhkan semacam medium digital untuk bisa mencuri data dari satu perangkat untuk diteruskan ke perangkat lain, biasanya melalui jaringan komputer dan internet.
Lalu, apakah komputer yang tidak tersambung ke jaringan bisa disebut "steril" dari kemungkinan pencurian data?
Ternyata tidak juga. Sekelompok peneliti dari Fraunhofer Institute of Communications, Jerman, membuktikan bahwa ternyata malware juga bisa mencuri data dari komputer lewat gelombang suara tanpa butuh koneksi data.
Seperti dilaporkan oleh Ars Technica, para peneliti tersebut mengembangkan prototipe malware yang berkomunikasi dan mengirim data lewat mikrofon dan speaker. Caranya adalah dengan mengirim sinyal frekuensi tinggi dari komputer yang terinfeksi ke komputer lain.
Transfer data hanya bisa dilakukan dengan kecepatan sangat rendah, yaitu 20 bit per detik, tapi ini sudah cukup untuk mengirim informasi-informasi vital semacam password dengan cepat.
Terlebih lagi jangkauan metode pengiriman lewat suara ini lumayan luas, mencapai 65 kaki atau 20 meter. Jarak itu bisa diperluas dengan menciptakan jaringan komputer yang terinfeksi untuk melakukan relay sinyal suara.
Malware tersebut membuktikan bahwa isolasi komputer dari internet dan jaringan sudah tidak bisa dipandang cukup untuk mengamankan perangkat. "Konsep jaringan berbasis sinyal suara membuat metode sekuriti konvensional menjadi tidak berguna karena biasanya tak mempertimbangkan komunikasi audio," tulis tim peneliti dari Fraunhofer Institute itu dalam laporan yang dipublikasikan di Journal of Communications.
Tim peneliti dari Fraunhofer Institute itu sendiri tidak benar-benar membuat malware, melainkan hanya membuktikan konsep untuk meningkatkan kesadaran mengenai kemungkinan serangan di masa depan dan cara menangkalnya. Salah satu "penangkal" yang disarankan adalah dengan memakai filter audio yang memblokir suara frekuensi tinggi dan penganalisa audio.
Lalu, apakah komputer yang tidak tersambung ke jaringan bisa disebut "steril" dari kemungkinan pencurian data?
Ternyata tidak juga. Sekelompok peneliti dari Fraunhofer Institute of Communications, Jerman, membuktikan bahwa ternyata malware juga bisa mencuri data dari komputer lewat gelombang suara tanpa butuh koneksi data.
Seperti dilaporkan oleh Ars Technica, para peneliti tersebut mengembangkan prototipe malware yang berkomunikasi dan mengirim data lewat mikrofon dan speaker. Caranya adalah dengan mengirim sinyal frekuensi tinggi dari komputer yang terinfeksi ke komputer lain.
Transfer data hanya bisa dilakukan dengan kecepatan sangat rendah, yaitu 20 bit per detik, tapi ini sudah cukup untuk mengirim informasi-informasi vital semacam password dengan cepat.
Terlebih lagi jangkauan metode pengiriman lewat suara ini lumayan luas, mencapai 65 kaki atau 20 meter. Jarak itu bisa diperluas dengan menciptakan jaringan komputer yang terinfeksi untuk melakukan relay sinyal suara.
Malware tersebut membuktikan bahwa isolasi komputer dari internet dan jaringan sudah tidak bisa dipandang cukup untuk mengamankan perangkat. "Konsep jaringan berbasis sinyal suara membuat metode sekuriti konvensional menjadi tidak berguna karena biasanya tak mempertimbangkan komunikasi audio," tulis tim peneliti dari Fraunhofer Institute itu dalam laporan yang dipublikasikan di Journal of Communications.
Tim peneliti dari Fraunhofer Institute itu sendiri tidak benar-benar membuat malware, melainkan hanya membuktikan konsep untuk meningkatkan kesadaran mengenai kemungkinan serangan di masa depan dan cara menangkalnya. Salah satu "penangkal" yang disarankan adalah dengan memakai filter audio yang memblokir suara frekuensi tinggi dan penganalisa audio.
Aug 2, 2013
Volkswagen stops academics from revealing car hack
Foxnews.com - A British university is delaying the release of an academic paper on how the anti-theft systems of millions of Volkswagen vehicles are at risk of being hacked after the German carmaker took legal action against it.
In a statement, the University of Birmingham said it would "defer publication" of the paper — which explains how researchers were able to subvert Volkswagen's security system — after an interim injunction issued by England's High Court. It said it was "disappointed with the judgment which did not uphold the defense of academic freedom and public interest, but respects the decision."
The university did not elaborate on how long the paper would be held, saying it was still getting legal advice.
The paper — which a group of academics including Birmingham's Flavio Garcia had planned to publish next month — revealed three ways to bypass a brand of computer chip used by several auto manufacturers to fight vehicle theft.
Often referred to as immobilizers, such chips use a secret algorithm to ensure that a car can only be started with the right key, and they've been a mandatory in all new vehicles sold in Britain over the past 15 years.
Crucially, the researchers planned to reveal how they were able to reverse-engineer the algorithm — and publish a copy of it in their paper.
Volkswagen said that publishing the formula would be "highly damaging" and "facilitate theft of cars," according to a ruling handed down last month by High Court Justice Colin Birss. The judge said that millions of Volkswagen vehicles were issued with the chip, including high-end cars such as Porsches, Audis, Bentleys, and Lamborghinis.
The researchers countered that Volkswagen's claim that the paper would be a boon to car thieves was overblown, that they had warned the chip's manufacturer about the vulnerability six months ago, and that a gag order would interfere with their legitimate academic work.
Birss said he sympathized with the researchers' rights, but that he had to weigh them against public safety.
"I recognize the high value of academic free speech, but there is another high value, the security of millions of Volkswagen cars," he said.
It's not yet clear if the case will go to trial. The University of Birmingham declined further comment Tuesday. Volkswagen also declined comment, citing ongoing proceedings.
In a statement, the University of Birmingham said it would "defer publication" of the paper — which explains how researchers were able to subvert Volkswagen's security system — after an interim injunction issued by England's High Court. It said it was "disappointed with the judgment which did not uphold the defense of academic freedom and public interest, but respects the decision."
The university did not elaborate on how long the paper would be held, saying it was still getting legal advice.
The paper — which a group of academics including Birmingham's Flavio Garcia had planned to publish next month — revealed three ways to bypass a brand of computer chip used by several auto manufacturers to fight vehicle theft.
Often referred to as immobilizers, such chips use a secret algorithm to ensure that a car can only be started with the right key, and they've been a mandatory in all new vehicles sold in Britain over the past 15 years.
Crucially, the researchers planned to reveal how they were able to reverse-engineer the algorithm — and publish a copy of it in their paper.
Volkswagen said that publishing the formula would be "highly damaging" and "facilitate theft of cars," according to a ruling handed down last month by High Court Justice Colin Birss. The judge said that millions of Volkswagen vehicles were issued with the chip, including high-end cars such as Porsches, Audis, Bentleys, and Lamborghinis.
The researchers countered that Volkswagen's claim that the paper would be a boon to car thieves was overblown, that they had warned the chip's manufacturer about the vulnerability six months ago, and that a gag order would interfere with their legitimate academic work.
Birss said he sympathized with the researchers' rights, but that he had to weigh them against public safety.
"I recognize the high value of academic free speech, but there is another high value, the security of millions of Volkswagen cars," he said.
It's not yet clear if the case will go to trial. The University of Birmingham declined further comment Tuesday. Volkswagen also declined comment, citing ongoing proceedings.
Subscribe to:
Posts (Atom)