Thursday, February 25, 2016

Insecure APIs allow anyone to mess with Nissan LEAF electric car

A vulnerability in the mobile app used to interact with Nissan LEAF, a popular electric car, can be exploited by remote, unauthenticated attackers to switch the car’s AC and heating system on and off, but also to extract details about the owner’s journeys, security researcher Troy Hunt has demonstrated. The weakness rests in the fact that the app interacts with the car via APIs that require no authentication to be accessed, and can therefore be … More
from Help Net Security http://ift.tt/1LetVz9

No comments:

Post a Comment