From 0d4d83b8f86bccc6ed3447c0187a45e725346110 Mon Sep 17 00:00:00 2001 From: deathrow Date: Wed, 25 Jan 2023 11:36:30 -0500 Subject: [PATCH 1/4] Initial Car section --- _information/Cars.md | 66 +++++++++++++++++++++++++++++++++++++ _information/Collections.md | 8 +++++ 2 files changed, 74 insertions(+) create mode 100644 _information/Cars.md diff --git a/_information/Cars.md b/_information/Cars.md new file mode 100644 index 0000000..c82a5e3 --- /dev/null +++ b/_information/Cars.md @@ -0,0 +1,66 @@ +--- +layout: default1 +description: A page containing various information on the privacy side of automobiles. +title: Cars +permalink: /cars +--- + +
+A page containing various information on the privacy side of automobiles. +
+
+ +
+ +
+ +
+ +Modern cars contain a lot of information about you. +Location, speed, driving patterns, and more. +There are few actual resources on what these privacy invasions are, and what you can do about them. + +The term "car" is used to describe automobiles such as sedans, SUV's, trucks, tudors, unless otherwise specified. + + +
+ +#### Table of contents: + +-\>> [Introduction](#introduction)
+ +
+ +--- + +### __Introduction__ + +Most modern cars contain an EDR, Electronic Data Recorder. +This device is also commonly known as a "black box". +This device contains detailed information such as vehicle speed, detailed engine information along with the vehicles occupancy status. + +This device is able to be read via a simple USB dongle. +The EDR is able to use the on-board pressure sensors embedded in the driver and passenger seats to have information such as how many passengers were in the vehicle, along with the status of seat belts. + +While this is used for safety purposes, it is an extreme privacy invasion. +This page is not to describe on why you might want to care about privacy, but rather an overview on the privacy concern of modern cars. + +Most modern cars include "smart features", such as an embedded display usually running a version of Android. +These devices will be referred to as a "smart screen". +The smart screen has the ability to connect to the internet along with providing apps such as Spotify, and some sort of GPS / navigational system. + +A concern of these devices is the lack of security consideration. +These devices have access to extremely sensitive information such as location and potentially account information granted that an account is signed in. +Often times, these devices to not receive proper security patches or even updates to the OS in general. + +
+ +--- + + +### Links & Resources + diff --git a/_information/Collections.md b/_information/Collections.md index eff3e06..84ddeb1 100644 --- a/_information/Collections.md +++ b/_information/Collections.md @@ -19,6 +19,14 @@ A collection of links, articles, resources and more. --- +## [Cars](./cars) + +An introduction to car threat modeling and privacy. + +
+ +--- + ## [Qubes OS](./qubes) A collection of QubesOS related content. From 432d09be736441319c62afbfa8e36a7582caa4ea Mon Sep 17 00:00:00 2001 From: deathrow Date: Wed, 25 Jan 2023 11:50:13 -0500 Subject: [PATCH 2/4] Started Security Section --- _information/Cars.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/_information/Cars.md b/_information/Cars.md index c82a5e3..3b6e53e 100644 --- a/_information/Cars.md +++ b/_information/Cars.md @@ -33,6 +33,9 @@ The term "car" is used to describe automobiles such as sedans, SUV's, trucks, tu -\>> [Introduction](#introduction)
+-\>> [Security](#security)
+ +
--- @@ -61,6 +64,26 @@ Often times, these devices to not receive proper security patches or even update --- +### __Security__ + +Unfortunately, with the rapid adoption of technology, cars are vulnerable to various types of attacks. +Certain types of attacks include spoofing the radio signal from a key Fob and utilizing vulnerabilities found in 3rd-party applications. + +Here is a list of some educational resources: + +- [Connecting to the car's network - David Bombal](https://invidious.namazso.eu/watch?v=ICOaAfLlb4o) + +- [I Hacked Into My Own Car - Steve Mould](https://invidious.snopyta.org/watch?v=5CsD8I396wo) + +
+ +--- ### Links & Resources + +
+ +--- + +### Footnotes \ No newline at end of file From 615f82677f2df0a64c1debc9224e82fa8a672ad6 Mon Sep 17 00:00:00 2001 From: deathrow Date: Thu, 26 Jan 2023 15:00:31 -0500 Subject: [PATCH 3/4] Car Section --- _items/Guide.md | 60 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) diff --git a/_items/Guide.md b/_items/Guide.md index 4b1bf81..5675c6b 100644 --- a/_items/Guide.md +++ b/_items/Guide.md @@ -86,6 +86,9 @@ _Disclaimer: This is for education / research._ - -\>> _[Tor](#tor-1)_
-\>> [Physical](#physical)
+ +- -\>> _[Cars](#cars)_
+ -\>> [Secure Communications](#secure-communications)
-\>> [Secure Hardware](#secure-hardware)
-\>> [Plausible Deniability](#plausible-deniability)
@@ -997,6 +1000,17 @@ For more information visit [JoinMatrix](https://joinmatrix.org). ## **Physical** +
+ +
+ +
+ Your physical state is just as important as your online state. If you can be physically tracked and stalked, this could potentially lead to the compromise of your online being. For instance, if someone stalks your behavior and notices you leave your device unattended, this can lead to malicious activity taking place such as compromising firmware, installing a small Bluetooth transmitter, accessing device information if the device is unencrypted, or even just outright taking the device. @@ -1029,6 +1043,52 @@ At first glance, many of this seems like defining qualities, but they can be alt
+### Cars + +Modern cars contain a lot of information about you. +Location, speed, driving patterns, and more. +There are few actual resources on what these privacy invasions are, and what you can do about them. + +The term "car" is used to describe automobiles such as sedans, SUV's, trucks, tudors, unless otherwise specified. + +
+ +#### Introduction + +Most modern cars contain an EDR, Electronic Data Recorder. +This device is also commonly known as a "black box". +This device contains detailed information such as vehicle speed, detailed engine information along with the vehicles occupancy status. + +This device is able to be read via a simple USB dongle. +The EDR is able to use the on-board pressure sensors embedded in the driver and passenger seats to have information such as how many passengers were in the vehicle, along with the status of seat belts. + +While this is used for safety purposes, it is an extreme privacy invasion. +This page is not to describe on why you might want to care about privacy, but rather an overview on the privacy concern of modern cars. + +Most modern cars include "smart features", such as an embedded display usually running a version of Android. +These devices will be referred to as a "smart screen". +The smart screen has the ability to connect to the internet along with providing apps such as Spotify, and some sort of GPS / navigational system. + +A concern of these devices is the lack of security consideration. +These devices have access to extremely sensitive information such as location and potentially account information granted that an account is signed in. +Often times, these devices to not receive proper security patches or even updates to the OS in general. + +
+ +#### Security + +Unfortunately, with the rapid adoption of technology, cars are vulnerable to various types of attacks. +Certain types of attacks include spoofing the radio signal from a key Fob and utilizing vulnerabilities found in 3rd-party applications. + +Here is a list of some educational resources: + +- [Connecting to the car's network - David Bombal](https://invidious.namazso.eu/watch?v=ICOaAfLlb4o) + +- [I Hacked Into My Own Car - Steve Mould](https://invidious.snopyta.org/watch?v=5CsD8I396wo) + +
+ + ### Walking Style Your walking style is a unique identifier, and can be used to track you. From 283d8a062de5b7cbfaa9c3aba9b677885527043e Mon Sep 17 00:00:00 2001 From: deathrow Date: Thu, 26 Jan 2023 15:00:50 -0500 Subject: [PATCH 4/4] Remove section --- _information/Cars.md | 89 ------------------------------------- _information/Collections.md | 8 ---- 2 files changed, 97 deletions(-) delete mode 100644 _information/Cars.md diff --git a/_information/Cars.md b/_information/Cars.md deleted file mode 100644 index 3b6e53e..0000000 --- a/_information/Cars.md +++ /dev/null @@ -1,89 +0,0 @@ ---- -layout: default1 -description: A page containing various information on the privacy side of automobiles. -title: Cars -permalink: /cars ---- - -
-A page containing various information on the privacy side of automobiles. -
-
- -
- -
- -
- -Modern cars contain a lot of information about you. -Location, speed, driving patterns, and more. -There are few actual resources on what these privacy invasions are, and what you can do about them. - -The term "car" is used to describe automobiles such as sedans, SUV's, trucks, tudors, unless otherwise specified. - - -
- -#### Table of contents: - --\>> [Introduction](#introduction)
- --\>> [Security](#security)
- - -
- ---- - -### __Introduction__ - -Most modern cars contain an EDR, Electronic Data Recorder. -This device is also commonly known as a "black box". -This device contains detailed information such as vehicle speed, detailed engine information along with the vehicles occupancy status. - -This device is able to be read via a simple USB dongle. -The EDR is able to use the on-board pressure sensors embedded in the driver and passenger seats to have information such as how many passengers were in the vehicle, along with the status of seat belts. - -While this is used for safety purposes, it is an extreme privacy invasion. -This page is not to describe on why you might want to care about privacy, but rather an overview on the privacy concern of modern cars. - -Most modern cars include "smart features", such as an embedded display usually running a version of Android. -These devices will be referred to as a "smart screen". -The smart screen has the ability to connect to the internet along with providing apps such as Spotify, and some sort of GPS / navigational system. - -A concern of these devices is the lack of security consideration. -These devices have access to extremely sensitive information such as location and potentially account information granted that an account is signed in. -Often times, these devices to not receive proper security patches or even updates to the OS in general. - -
- ---- - -### __Security__ - -Unfortunately, with the rapid adoption of technology, cars are vulnerable to various types of attacks. -Certain types of attacks include spoofing the radio signal from a key Fob and utilizing vulnerabilities found in 3rd-party applications. - -Here is a list of some educational resources: - -- [Connecting to the car's network - David Bombal](https://invidious.namazso.eu/watch?v=ICOaAfLlb4o) - -- [I Hacked Into My Own Car - Steve Mould](https://invidious.snopyta.org/watch?v=5CsD8I396wo) - -
- ---- - -### Links & Resources - - -
- ---- - -### Footnotes \ No newline at end of file diff --git a/_information/Collections.md b/_information/Collections.md index 84ddeb1..eff3e06 100644 --- a/_information/Collections.md +++ b/_information/Collections.md @@ -19,14 +19,6 @@ A collection of links, articles, resources and more. --- -## [Cars](./cars) - -An introduction to car threat modeling and privacy. - -
- ---- - ## [Qubes OS](./qubes) A collection of QubesOS related content.