On Saturday, I sat in a crowded ballroom at Caesar's Forum in Vegas and watched @sickcodes jailbreak a John Deere tractor's control unit live, before an audience of cheering @defcon 30 attendees (and, possibly, a few undercover Deere execs, who often attend Sickcodes's talks). 1/
If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
The presentation was significant because Deere - along with Apple - are the vanguard of the war on repair, a company that has made wild and outlandish claims about the reason that farmers must pay the company hundreds of dollars every time they fix *their own tractors*. 3/
Best Defcon talk so far, how a high school senior Rick rolled his entire school district, hijacking every projector, locking out their remotes, disabling their physical off switches, and pwning every PA speaker in every building in the district.
The point of entry was the extraordinarily invasive spyware used by the district to monitor student laptops, which was also wildly insecure... And installed on staff computers, including campus security.
They also discovered multiple vulns and even manufacturer's backdoor. Lots of default passwords... And in one instance, a password that had been changed from the default to the example from the manual.