Hi folks!
I'm back from a lovely snowboarding trip, and enjoying a few days off to catch up on some sleep :-)
Nothing Earth-shattering this week in security world, which is a good thing. But plenty of interesting articles to read and learn from. Enjoy!
P.S.: I'm looking around for a new sponsor. If your company wants to be featured next to the awesome 1Password, give me a shout.
Nice example of a corporate espionage case. The U.S. Department of Justice released information on a case involving Linwei (Leon) Ding, a former software engineer at Google, suspected of stealing Google AI trade secrets for Chinese companies. He secretely worked for two Chinese companies, while also working at Google.
Over the course of a year he uploaded over 500 files to his personal Google account to exfiltrate them. He even asked a colleague to scan his entrance badge to make it appear like he was working in the US office, while he was actually travelling to China. He now faces a prison sentence of up to 10 years and a fine of $1 million.
I was ready to more or less dismiss this, because it starts out as just a phishing attack to get someone's Tesla account credentials. But it goes on to make some good points.
As it stands, having someone's Tesla credentials, combined with being close to the car, is enough to be able to drive away with that car. That's not good, especially as the researchers demonstrate their phishing attack by setting up a malicious Wifi access point at a Tesla charging station where being close to the car is a given.
The researchers point out that there should be a requirement for the physical rfid card to be present in the car before you can add a phone key, or at least get a notification once a new key was added to your car. Neither of which exists at the moment.
If you want to be featured in the newsletter, like 1Password is every week, just reply to this e-mail and let me know.