Archive for the ‘Car Hacking’ Category

Tubemoneyheading

 

 

Tubularsock has been boarding up his windows in his top floor corner office in his underground bunker overlooking Washington, D.C. from Oakland, CA as a precaution.

Tubularsock has a bank account.

You may not have been following this story but Tubularsock has been following it for several months now and it’s rather weird to say the least.

Since March, 2013 there have been 51 bankers that have died. Some by suicide, some by questionable circumstances still up in the air, and some by “accidents”. According to Deutsche Wirtschafts Nachrichten (Economic News of Germany).

Now hell, people die everyday but these are all successful bankers and they are dropping like flies.

Now why is that?

For example Geert Tack, a 52 year old “flawless, athletic, slim, successful” banker who worked at ING Group and handled portfolios for wealthy bank customers washed up on the beach in the port city of Ostend, Belgian on Wednesday December 3rd.

He left his villa in Vondelen and headed to work but never arrived. He had left his laptop and his cell phone in his mansion.

The autopsy has not been completed so suicide, perhaps or maybe murder, perhaps. Or maybe a total collapse upon finding himself without his laptop and cell phone. You know, in todays world one can not be “unplugged” for even a minute?

Or lets look at Shawn Miller, the CEO of Citigroup. He advised managers and other customers on sustainability, including environmental and social policies. These include the areas of mining and renewable energy. He worked for Citibank in various monitoring functions in over 100 countries.

Miller was found dead in his New York apartment in March 2013. His cause of death is still unclear. His body was found by the police in the bathtub with his neck completely cut open. No half way job here!

They found no weapons and no apparent “violent external force” but murder is suspected.

Which if you look closely Dr. Watson it would be rather difficult for a person to cut open his own neck and not leave behind a weapon. Cleaver devil, I should say.

Now the house camera did show that he allowed an “unknown” man into his apartment that WAS NOT his current lover.

Now how about the “accidental death” of Robert Evans a 30 year old vice-president of Bank of America Merrill Lynch who fell off his bike and smashed his head on a rock after losing control on a fast descent as he competed an Iron Man triathlon on the French Riviera.

An eyewitness saw Mr Evans swerving repeatedly before he hit the rock.

“Accidental”? Seems like it ………

Robert was Vice President of Electronic Trading Technology at Bank of America Merrill Lynch in the London office.

Another “accidental death” was 54 year old J. Patrick Sheehan, a managing director for public finance at Well Fargo in New York.

According to a police statement, he died at the scene, as did the driver of his livery car, after a Ford Explorer sport-utility vehicle crossed the median and struck his limo.

“Accidental”? seems like it.

Why does Michael Hastings car “accident” come to Tubularsock’s mind? That was just a regular car accident …….. right, right?

Sometimes some people seem to know too much ………

Now like Tubularsock has stated, people die all the time and accidents do happen but when they happen within a curious “trend” well just maybe something else is happening.

IT'S ONLY MONEY

For example:

March 11, 2013: Mohammed Hamwi, IT specialist financial company Trepp in New York. Was on the street and was shot three times in the head, reports New York Post .

July 29, 2013: Hussein Najadi, founder of the Arab­Malaysian Banking Group was shot dead in a car park in Kuala Lumpur by a shooter at close range. A suspect was arrested in September 2013, reported The Star .

April 13, 2014: Tanji Dewberry Vice President of WL Ross investment in New York and Deputy Vice Presi of Credit Suisse. She and her son burned to death at their home in New Jersey, reports The Daily Mail .

April 18, 2014: Benedict Philippines, Director of the Bank Ans­Saint­Nicolas, was shot dead along with his wife and child by unknown assailants in their house, Reuters reports.

July 6, 2014: Julien Knott, Director at JP Morgan. He and his wife were shot dead at their home in New Jersey, reports the International Business Times.

And then there are the suicides which make up about a third of the total number.

Now for the Tubularsock disclaimer. The world is a big place and lists like this could be created based on a variety of professions but Tubularsock does find this curious and is only bringing this to your attention to alert you about this and thereby maybe you’ll find a connection. Or not.

It just reminded Tubularsock of the ending of the movie “Wag The Dog”, that’s all!

Oh well, Tubularsock over thinks sometimes but what if ……….

Oh, and Tubularsock closed his bank account ……… too scary!

           Screen Shot 2012-07-21 at 11.55.56 PM

TUBEHEADING ISSUE

Well Tubularsock was minding his own business, no really I was. I was going off, a few blogs back, on how some people’s deaths appear more than just coincidences. Now if I tell you that a key witness in some mob trial gets offed most people would say, “why sure, that’s not a surprise”.

But if I tell you that some former CIA agent, or military special ops officer, or some journalist dies suddenly and unexpectedly the response is more likely, “well people die all the time, why make a case out of it”.

So. Back to Tubularsock minding his own business. In that recent blog about interesting and untimely deaths I received two comments. One was from Doggy Dix a person who has a fast mind and sharp wit and he informs me that a journalist was killed in LA that ties into my Blog post. He couldn’t remember details but Tubularsock had enough to go on to research for the details but could not find anything on the subject.

Then a blogger (Deconstructing Myths by Jeff Nguyen) who follows Tubularsock occasionally filled in the missing information. The journalist was Michael Hastings and he was the Rolling Stone reporter who embarrassed General McChrystal. Hastings died in a suspicious car crash in LA last month.

So Tubularsock checked into this incident and what was the first thing that JUMPED OUT when I Googled it?

CAR HACKING!

Now Tubularsock is not one to be interested in cars in general. I live in a city and my primary mode of transportation is my two wheeler. So when it comes to cars I have a very limited interest.

However, CAR HACKING now that’s another story. I had never even heard about CAR HACKING before and so my direction was charted and thus my story unfolds.

So of course being a modern man I googled it specifically!

And ….. Was Michael Hastings’ Car Hacked? Richard Clarke Says It’s Possible was the first thing that jumped out from the list of articles.

But knowing Clarke’s general take on things I decided to check out other information first and so the first article I was drawn to was from Popular Science  and the article was The Science Of Car Hacking by Kelsey Atherton. And right from the get-go something seemed to be amiss ……… the focus of the article was one of trying to dissuade the idea that Michael Hastings’ car was hacked.

“Limitations first: hackers cannot magically gain control of a car. While cars are increasingly computerized, not every system involved in driving is hooked up to external controls. Let me repeat that for clarity: in almost every car currently on the road, it’s impossible to hack the steering. A hacker trying to kill someone via car can’t just take over and pilot the vehicle into a tree or off a cliff.”

Now if Richard Clarke says that car hacking is possible and Popular Science says it’s not likely then is Popular Science trying to mis-direct the reader? And if so then why?

The main reason I believe is that the Bonnier Corporation that owns the Popular Science magazine and 39 other American magazines is a Swedish holding company.  Its headquarters are located In Winter Park, Florida. They are a conservative company and are not interested in ruffling any U.S. governmental agency.

So the focus of the article is away from any possible controversy. And the article was written with this in mind. Not that the article isn’t true to some degree and information was provided that hacking may be possible but just highly unlikely.

Now Richard Clarke who was the former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism says, “What has been revealed as a result of some research at universities is that it’s relatively easy to hack your way into the control system of a car, and to do such things as cause acceleration when the driver doesn’t want acceleration, to throw on the brakes when the driver doesn’t want the brakes on, to launch an air bag. You can do some really highly destructive things now, through hacking a car, and it’s not that hard.”

By far the best informed source I found was Darlene Storm’s article Car hacking: Car cyberattack a possible theory behind journalist’s death at Computerworld Blogs.

Darlene Storm covers the entire story of Michael Hastings and links you up to two major studies done on car hacking. The one I liked best was the Comprehensive Experimental Analyses of Automotive Attack Surfaces a joint study done by the University of California, San Diego and the University of Washington in 2011.

In that study you’ll discover that any computer control in the car could be hacked, including the “engine, lights, radio, wipers and electronic display.” And these all can be accessed through wireless devices in the car like cellular, Bluetooth, radio and even the tire pressure monitoring system.

Also according to the study:

“Perhaps the most important part of the long-range wireless attack surface is that exposed by the remote telematics systems (e.g., Ford’s Sync, GM’s OnStar, Toyota’s SafetyConnect, Lexus’ Enform, BMW’s BMW Assist, and Mercedes-Benz’ mbrace) that provide continuous connectivity via cellular voice and data networks.

These cellular channels offer many advantages for attackers. They can be accessed over arbitrary distance (due to the wide coverage of cellular data infrastructure) in a largely anonymous fashion, typically have relatively high bandwidth, are two-way channels (supporting inter- active control and data exfiltration), and are individually addressable.” 

Hastings was driving a 2013 Mercedes C250 coupe with all the bells and whistles. The more expensive the car the more susceptible to hacking!

The Comprehensive Experimental Analyses of Automotive Attack Surfaces joint study is actually a fun read if you like that kind of shit and by the time Tubularsock was finished he knew way too much. It did make me feel a bit more secure because when I do have to drive it’s in a RED 1987 Suzuki Samara and so I’m used to the horn, wipers, accelerator, and radio all working on their own without my control. So what’s the big deal?

The LA police department is treating this as a routine car accident but Tubularsock looks at it like Sherlock Holmes and routine is so boring.

So Hasting’s Mercedes C250 coupe was coming southbound on Highland Avenue and it was “. . . going really fast and all of a sudden I seen it jackknife”, according to Luis Cortez a witness to the scene in an interview with KTLA.

So we have high speed (acceleration) ………. we have jackknife (brakes)

“The car was going so fast, the engine was found more than 100 feet away from the crash.” according to The Los Angeles Times from information they gathered from Gary Grossman and his neighbor in the area.

So we have high speed ………… we have jackknife ……….. we have ejected engine

Another neighbor described hearing a huge explosion drawing him and several others outside their homes.

So we have high speed  ………. we have jackknife ……….. we have ejected engine …….. we have explosion

The car fire was so intense that it took the LA coroner two days to identify Hastings’ body.

Hasting's car fire

So we have high speed  ………. we have jackknife ……….. we have ejected engine …….. we have explosion ………. we have intense fire

Hastings had sent an email hours before his death stating, “FBI Investigation re: NSA”, “go off the radar for a bit.” AND He “was researching a story about a privacy lawsuit brought by Florida socialite Jill Kelley against the Department of Defense and the FBI.”

So we have high speed (acceleration)  ………. we have jackknife (brakes) ……….. we have ejected engine (?) …….. we have explosion (foul play?) ………. we have intense fire (?) …….. we have intrigue (plenty)

Now according to Clarke, the “expertise to trace such an (cyber) attack” is beyond  the expertise of the LA Police Department and “I think whoever did it would probably get away with it.” Clarke emphasized that he was not saying that there was a cyberattack only that a cyberattack on the vehicle would have been nearly impossible to trace ‘even if the dozen or so computers on board hadn’t melted’.”

Ok, ok …………. Tubularsock says maybe yes, maybe no.

Sherlock Holmes says ………… why not check the cell phones records and see if any calls were made to that car’s computer system at the time of the accident. I’m sure the LA police are capable of that! What is there to lose?

Now really, aren’t you just curious?

Screen Shot 2012-07-21 at 11.55.56 PM