EVs in a war
It'a a good thing that Tanks, Ships, Planes etc still use conventional fuel systems.
Imagine the warfield with soldiers stuck at home base due to lack of charging....
Developers of rented internet of things infrastructure – stuff like public EV chargers and shared e-bikes – are prioritizing user convenience over security, and leaving themselves exposed to wide-scale denial of service attacks on their services. That frightening thesis was the subject of a Friday talk at the Black Hat Asia …
internet connected for some reason
Yep nothing that doesn't need to be connected to the internet ever is. That's why we never see hacks of water plants, dams, etc.
How exactly do you think credit cards are processed by gas pumps? Maybe you live somewhere that you still have to go inside and tell them "turn on pump 3" or whatever then go back inside to pay but most of us live in the modern world where we can pay at the pump with a credit card or Apple/Google Pay which means that pump is connected to the internet.
Now sure they COULD have an intranet connection directly to their payment processor rather than traveling on the open internet, but most convenience stores etc. that pump gas just use their ordinary internet connection without a VPN. Just SSL encoded transactions over the open internet.
@AC
Do you believe that the majority of fuel pumps are internet connected for some reason ?
I'll presume you live in an area where the answer to your question is not bleedin' obvious.
Around here, pretty much everything is IoT-infested.
I've seen convenience stores closed, with a hand-scribbled note taped to the inside of the glass door stating they are closed because their "computer is down." (computerised cash register?) I've seen convenience store slushie machines and coffee machines unable to dispense their drinks (in the case of the slushie machines, I was able to use their touch-screen panel to access a diagnostic display which indicated an Internet connection failure; I backed out of the diags screen and left it as I found it). I've seen black-background/white fixed-font error messages indicating no IP on bus arrival display panels and on advertising panels. I've seen fast-food order-taking touch-panel displays down; in the case of Taco Bell, a taped-on note directed customers to place their orders with staff at the front counter.
Megacorps love IoT display panels because they can quickly and easily have their images and messages revised, issued from the exalted central Headquarters Building (execs love the illusion they 'have control'). Similarly with IoT product dispensers; they can get 'instant' information on product reservoir levels, get status displays ('dashboards'), and such.
But the execs which buy these things are enamoured by the shiny-factor (I saw a [working] touch-screen IoT milkshake dispenser with a curvey, swoopy body-shell adorned with the Pininfarina logo!), and don't understand/don't care enough about end-to-end reliability and security.
Israel knocked out all of Iran's fuel infrastructure recently.
https://www.thesun.co.uk/news/25087670/israeli-hackers-cripple-iran-petrol-stations-revenge/
In previous incarnations, I have worked with large fuel station providers, and the pumps are all online for monitoring, flow control and payments.
These companies are basically racing to a finished product, before the funding dries up and things like security take a backseat.
It doesn't help that security is *hard* and has to be done in depth and distributed systems like e-bikes / chargers are probably using cloud services. There are plenty of potential attack vectors when things are up in the cloud and if they are not locked down properly then somebody will figure out what the endpoints are and start poking around.
The researcher tested 11 apps published by European providers of shared bikes and scooters, and found similar problems - suggesting his findings will be applicable elsewhere.
All the European (& everywhere else) providers junk is made in China, so of course if it works in China it will work in Europe (& everywhere else).
And introduce three factor authentication for the purchase of sweets, biscuits, chocolate and alcohol.
You could end the viability and use of most internet services by simply demanding authorisation so secure that nobody could be arsed to jump through all the hoops.