Teen hacker finds bug that lets him control 25+ Teslas remotely. Also 1000s of auth tokens expired silmutaneously

A young hacker and IT security researcher found a way to remotely interact with more than 25 Tesla electric vehicles in 13 countries, according to a Twitter thread he posted yesterday.

David Colombo explained in the thread that the flaw was “not a vulnerability in Tesla’s infrastructure. It’s the owner’s faults.” He claimed to be able to disable a car’s remote camera system, unlock doors and open windows, and even begin keyless driving. He could also determine the car’s exact location.

[…]

On a related note, early on Wednesday morning, a third-party Tesla app called TezLab reported that it saw the “simultaneous expiry of several thousand Tesla authentication tokens from Tesla’s side.” TezLab’s app makes use of Tesla APIs that allow apps to do things like log in to the car and enable or disable the anti-theft camera system, unlock the doors, open the windows, and so on.

Source: Teen hacker finds bug that lets him control 25+ Teslas remotely | Ars Technica

Ransomware puts New Mexico prison in lockdown, closes doors, security cameras to personnel

[…]

Commissioners told the court that all of Bernalillo County, which covers the US state of New Mexico’s largest city Albuquerque, had been affected by a January 5, 2022, ransomware attack, including the Metropolitan Detention Center (MDC) that houses some of the state’s incarcerated.

[…]

Over the phone, a spokesperson for the facility told The Register on Wednesday that services are still being repaired.

The attack took automatic security doors offline on January 5th, requiring officials to open doors manually with keys until that particular function could be revived.

Officials said in their filing that County-operated databases, servers, and internet service had been compromised. At MDC, this has meant limited access to email and no access to County wireless internet. This is particularly problematic, the officials say, because the MDC’s structure and location interferes with cellular service.

“One of the most concerning impacts of the cyber attack is that MDC is unable to access facility cameras,” they explained. “As of the evening of January 5th, there was no access to cameras within the facility.”

MDC instituted a temporary lockdown in response to the situation. Court-related video conferences are also not happening.

Several County databases at MDC are also believed to have been corrupted by the attack.

“The Incident Tracking System (ITS), the database in which MDC creates and houses all incident reports, including inmate fights, use of force, allegations of violations of the Prison Rape Elimination Act, is not currently available as it is suspected to be corrupted by the attack,” the filing states.

“Further, the Offender Management System (OMS) which MDC uses to store and access information about inmates including inmate account data is likewise unavailable at the present.”

[…]

The plaintiffs in the case have taken the opportunity to submit the statement [PDF] of a registered nurse who announced that she was quitting her job at MDC because of concerns about conditions there. The nurse, Taileigh Sanchez, describes dire staff shortages at MDC and problems with a new electronic medical records system, issues that have been made worse by the ransomware attack.

The attack denied access to current medical records, she said, which may have prevented some inmates from getting their medications.

Sanchez said she told supervisors about her concerns – which date back before the ransomware hit – but faced retaliation. “Even though I like my job, and have even been here 11 years, I will be resigning my full-time position effective immediately due to the safety concerns I have for our clientele and our staff,” she said in her declaration.

Source: Ransomware puts New Mexico prison in lockdown • The Register

Open source maintainer PLC4X hits out at corporate freeloaders, stops offering free support

Yet another developer of open source software has tired of companies utilizing the code he helps maintain without giving anything back to support the project.

On Tuesday, Christofer Dutz, creator of Apache PLC4X, said he will stop providing community support for the software if corporate users fail to step up and open their wallets.

“The industry seems to like using PLC4X and open-source in general, but doesn’t seem to be willing to support the people working on it,” he wrote in a post to GitHub. “So, I will stop providing free community support for PLC4X.”

Dutz is one of six listed maintainers of Apache PLC4X, a set of libraries for communicating with programmable logic controllers – industry-specific devices involved in the automation of various manufacturing tasks. His demand for support exists outside his involvement with the Apache Foundation; he maintains a separate IT consultancy called c-ware to help companies design and implement PLC4X software to suit their respective businesses.

C-ware has launched several crowdfunding initiatives to adapt Apache PLC4X to Python, Rust, and TypeScript, among other enhancements, but these have barely attracted any funding commitments.

[…]

Source: Open source maintainer hits out at corporate freeloaders • The Register

With log4j fresh in memory it’s pretty clear that this widespread use of FOSS without any money going the way of the non-university funded maintainers is not sustainable

FTC’s latest monopoly lawsuit against Meta Facebook gets go-ahead

The Federal Trade Commission’s antitrust complaint that Facebook, er, Meta operates as a monopoly will be heard by the courts after the US watchdog’s initial lawsuit was dismissed.

In December 2020, the FTC accused Meta of “illegally maintaining its personal social networking (PSN) monopoly through a years-long course of anticompetitive conduct.” It threatened to break up the mega-corporation and undo its acquisitions Instagram and Whatsapp.

This legal challenge fell flat, however, when judges threw the case out six months later. Evidence supporting the idea it unlawfully dominated social media was said to be lacking though the regulator was given another chance to file an amended lawsuit. A federal judge has now agreed to hear the case this time.

“First, the FTC has now alleged enough facts to plausibly establish that Facebook exercises monopoly power in the market for PSN services,” Judge James Boasberg ruled [PDF] this week.

“Second, it has adequately alleged that the company’s dominant market share is protected by barriers to entry into that market. Third, the agency has also explained that Facebook not only possesses monopoly power, but that it has willfully maintained that power through anticompetitive conduct — specifically, the acquisitions of Instagram and WhatsApp.”

The amended lawsuit brings up pretty much the same allegations as the first lawsuit. It claims Meta has been operating as a monopoly for years with Instagram and Whatsapp under its belt, and that it has enforced anticompetitive practices to deter or thwart rivals.

[…]

Source: FTC’s latest monopoly lawsuit against Meta gets go-ahead • The Register

UltraRAM Breakthrough Brings Combined Memory and Storage to a single wafer

Scientists from the Physics and Engineering Department of the UK’s Lancaster University have published a paper detailing a breakthrough in the mass production of UltraRAM. Researchers have pondered over this novel memory type for several years due to its highly attractive qualities, and the latest breakthrough means that mass production on silicon wafers could be within sight. UltraRAM is described as a memory technology which “combines the non-volatility of a data storage memory, like flash, with the speed, energy-efficiency, and endurance of a working memory, like DRAM.”

ULTRARAM fabrication

(Image credit: Lancaster University)

Importantly, UltraRAM on silicon could be the universal memory type that will one day cater to all the memory needs (both RAM and storage) of PCs and devices.

[…]

The fundamental science behind UltraRAM is that it uses the unique properties of compound semiconductors, commonly used in photonic devices such as LEDs, lasers, and infrared detectors can now be mass-produced on silicon. The researchers claim that the latest incarnation on silicon outperforms the technology as tested on Gallium Arsenide semiconductor wafers.

An ULTRARAM cell

(Image credit: Lancaster University)

Some extrapolated numbers for UltraRAM are that it will offer “data storage times of at least 1,000 years,” and its fast switching speed and program-erase cycling endurance is “one hundred to one thousand times better than flash.” Add these qualities to the DRAM-like speed, energy efficiency, and endurance, and this novel memory type sounds hard for tech companies to ignore.

If you read between the lines above, you can see that UltraRAM is envisioned to break the divide between RAM and storage. So, in theory, you could use it as a one-shot solution to fill these currently separate requirements. In a PC system, that would mean you would get a chunk of UltraRAM, say 2TB, and that would cover both your RAM and storage needs.

The shift, if it lives up to its potential, would be a great way to push forward with the popular trend towards in-memory processing. After all, your storage would be your memory – with UltraRAM; it is the same silicon.

[…]

Source: UltraRAM Breakthrough Brings New Memory and Storage Tech to Silicon | Tom’s Hardware