Jaguar?
Re: Jaguar?
Also every IT person says every other IT person is doing it wrong.
Dave!
Dave!
Re: Jaguar?
There are also many other scenarios where an IT consultancy has discovered a vulnerability and suggested a fix to be told by the customer they have no budget and will accept the risk.Mito Man wrote: Thu Sep 18, 2025 10:34 amFrom my limited knowledge it seems more complex than that. Eg an employee clicking a dodgy link giving access to the hackers. So in your case it would be like someone leaving a tap open and flooding the house and then wanting to claim from your companyjamcg wrote: Thu Sep 18, 2025 10:32 amIf I install a bathroom in your house, and it leaks through your ceilings and destroys your house, I (well the company I work for) is liable to sort it out, either from their own pocket or via our public liability insurance.Matty wrote: Wed Sep 17, 2025 10:01 pm M&S, Co-Op, Harrods and JLR all have their IT provision via Tata Consultancy Services (TCS). All companies were hit by the same cyber group. I'm not suggesting there is a pattern here, obviously.
I've a lot of sympathy for the workers and the affected 3rd party suppliers - however the fact that Unite are suggesting the tax payer should bail everyone out all because those companies chose to outsource their IT provision to increase margins? How about Tata covers all the costs? Four of their companies have been compromised, and TCS netted $5.7billion last year. They can pay it for their shitty cyber practices.
It seems baffling that there’s not some clause in the contracts that states an IT security contractor is liable if they fail to secure your IT![]()
- DeskJockey
- Posts: 5894
- Joined: Thu Apr 12, 2018 8:58 am
Re: Jaguar?
Also this. If that is the case they better have their evidence to hand (on either side, although JLR might struggle to access it).scotta wrote: Thu Sep 18, 2025 11:18 amThere are also many other scenarios where an IT consultancy has discovered a vulnerability and suggested a fix to be told by the customer they have no budget and will accept the risk.Mito Man wrote: Thu Sep 18, 2025 10:34 amFrom my limited knowledge it seems more complex than that. Eg an employee clicking a dodgy link giving access to the hackers. So in your case it would be like someone leaving a tap open and flooding the house and then wanting to claim from your companyjamcg wrote: Thu Sep 18, 2025 10:32 am
If I install a bathroom in your house, and it leaks through your ceilings and destroys your house, I (well the company I work for) is liable to sort it out, either from their own pocket or via our public liability insurance.
It seems baffling that there’s not some clause in the contracts that states an IT security contractor is liable if they fail to secure your IT![]()
---
Driving a Galaxy far far away
Driving a Galaxy far far away
Re: Jaguar?
A bit of searching suggests that Tata don't run BMWs systems - but they do have a partnership/joint venture with BMW for vehicle software developmentDeskJockey wrote: Thu Sep 18, 2025 9:41 am BMW might be next...
https://cybernews.com/news/bmw-ransomwa ... jlr-trend/
https://www.tatatechnologies.com/en/new ... rks-india/
It'd be quite, quite funny if the hacker group just happen to know a logic hole in Tatas security methodology, used that to get in via the partnership, and then pivoted to other parts of BMWs network.
I mean, it wouldn't be funny for BMW. Funny for those of us who have dealt with these massive consultancies, and have seen the laughably poor shit they sometimes do, more so.
Last edited by Beany on Thu Sep 18, 2025 12:06 pm, edited 1 time in total.
Re: Jaguar?
Is there a credible threat that hackers can get into cars and remotely make them all drive full throttle into a wall? Just wondering what the security system on those must be like and any EV sold recently is capable of operating remotely…
How about not having a sig at all?
Re: Jaguar?
I mean, unless BMW were putting in remote control to the cars, then no.
It's not Terminator 3 FFS.
It's not Terminator 3 FFS.
Re: Jaguar?
But you can turn on, move the car etc via the phone app. Surely it isn’t too far fetched to infiltrate that system?
How about not having a sig at all?
Re: Jaguar?
It's hugely far fetched, given that all the group are claiming they have is 'audit' documentation.Mito Man wrote: Thu Sep 18, 2025 12:11 pm But you can turn on, move the car etc via the phone app. Surely it isn’t too far fetched to infiltrate that system?
Cybernews Senior Information Security Researcher Aras Nazarovas explained that "we need to wait until Everest releases a sample of the alleged solen data to get a better idea of the scope of the breach.”
However, Nazarovas points out that in the group’s leak post, “they mention the data is audit-related, which could mean lots of sensitive documents, but could also be a mistranslation, which is common for Everest.”
Re: Jaguar?
Not in this specific case but more as a general thought!
How about not having a sig at all?
Re: Jaguar?
Most cars don't have the capability to be remotely controlled as in most places, that's illegal on the public road, so any control mechanisms are local - IE the feedback is done from sensors and cameras locally, not fed upstream to a server, then commands sent back - for a start, the latency is a problem.
I'm not an automotive engineer, but I am Beany, and as such speaking with authority on matters on which I have no experience is my key skill.
There is no chance a hack like this could cause your BMW to drive into a wall.
For Teslas and Waymos, there's a greater risk, as they have specific setups to allow remote control - but I'd be willing to bet they have pretty heavy additional steps to allow this to happen - IE having to use a physical security key (like a Yubikey, not an actual lock and key) on a terminal before you can take remote control.
I have to enter a password, stored on a seperate system with a seperate login, before I can get elevated rights on a customers basic web server, for example. And that's just so I can bounce the web server software.
That's not physically possible by 'hacking', by someone wearing a dark hoodie with the hood up indoors, behind three monitors with two keyboards where the password is always swordfish, etc.
I'm not an automotive engineer, but I am Beany, and as such speaking with authority on matters on which I have no experience is my key skill.
There is no chance a hack like this could cause your BMW to drive into a wall.
For Teslas and Waymos, there's a greater risk, as they have specific setups to allow remote control - but I'd be willing to bet they have pretty heavy additional steps to allow this to happen - IE having to use a physical security key (like a Yubikey, not an actual lock and key) on a terminal before you can take remote control.
I have to enter a password, stored on a seperate system with a seperate login, before I can get elevated rights on a customers basic web server, for example. And that's just so I can bounce the web server software.
That's not physically possible by 'hacking', by someone wearing a dark hoodie with the hood up indoors, behind three monitors with two keyboards where the password is always swordfish, etc.
Re: Jaguar?
Well it wouldn't be the first time!
Re: Jaguar?
We've seen Speed 2, we know what's possible!!Beany wrote: Thu Sep 18, 2025 12:36 pm Most cars don't have the capability to be remotely controlled as in most places, that's illegal on the public road, so any control mechanisms are local - IE the feedback is done from sensors and cameras locally, not fed upstream to a server, then commands sent back - for a start, the latency is a problem.
I'm not an automotive engineer, but I am Beany, and as such speaking with authority on matters on which I have no experience is my key skill.
There is no chance a hack like this could cause your BMW to drive into a wall.
For Teslas and Waymos, there's a greater risk, as they have specific setups to allow remote control - but I'd be willing to bet they have pretty heavy additional steps to allow this to happen - IE having to use a physical security key (like a Yubikey, not an actual lock and key) on a terminal before you can take remote control.
I have to enter a password, stored on a seperate system with a seperate login, before I can get elevated rights on a customers basic web server, for example. And that's just so I can bounce the web server software.
That's not physically possible by 'hacking', by someone wearing a dark hoodie with the hood up indoors, behind three monitors with two keyboards where the password is always swordfish, etc.
Dave!
-
- Posts: 3511
- Joined: Wed Apr 11, 2018 3:58 pm
- Currently Driving: Ferrari F430 Spider
BMW M4 Comp
Mini Cooper
LR Evoque P300e - Contact:
Re: Jaguar?
Everest mistranslation: so it could be Audi-related? And they’re trying to sell it to BMW..
Cheers,
Ian
Ian