Researchers found a way to hack those ubiquitous electric scooters
Full article512 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A researcher with San Francisco-based Zimperium discovered a way to manipulate a Xiaomi M365 scooters via the device's Bluetooth connection.
You can add another bullet point to the long list of things that drive people nuts about the electric scooter craze in America: the scooters can be hacked.
A researcher with Dallas-based Zimperium discovered a way to manipulate a Xiaomi M365 scooter through a Bluetooth connection. Users can access their scooter via an app that connects to the scooter, as long as users authenticate with a password. However Zimperium researcher Rani Idan determined the password fails to completely protect users.
“During our research, we determined the password is not being used properly as part of the authentication process with the scooter and that all commands can be executed without the password,” Idan wrote in a blog post Tuesday. “The password is only validated on the application side, but the scooter itself doesn’t keep track of the authentication state.”
From there, Idan wrote an app for his mobile device that allowed him to mess with a Xiaomi scooter that was in use.
Idan writes that due to the flaw, a person could lock any M365 scooter, install malicious firmware, then cause it to fully accelerate or come to a screeching halt.
Scooter-sharing companies like Bird and Spin have used the Xiaomi in the past. However, CyberScoop has learned that Bird updated the firmware on their M365 models after discovering the issue more than a year ago.
A Spin spokesperson told CyberScoop it stopped purchasing the Xiaomi model last year, and are phasing out any remaining Xiaomi scooters it had previously deployed. The majority of Spin’s scooters are made by Segway.
Xiaomi told Zimperium researchers that it was aware of the issue, blaming on “third-party products.”
Correction, 2/14/19: The location of Zimperium’s headquarters has been corrected in this article.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/scooter-hack-zimperium-bluetooth-bird-spin/