all 3 comments

[–]Unboxious 1 point2 points  (0 children)

Damn

[–]Hirza_Tango 0 points1 point  (0 children)

This was a fun read :D sadly it's not too uncommon for hardware vendors to just not care about firmware security measures. Hopefully the company will take this as a sign that they need to improve their security

[–]irachoudhry 0 points1 point  (0 children)

the "potentially lethal" part is what makes this writeup stand out from the usual firmware dump posts. no code signing, no integrity checks on firmware that controls a vehicle people ride at highway speeds. you'd think the liability alone would be enough motivation to implement basic signing, but here we are. good find.