When Your Used Car is a Little Too ‘Mobile’

Many modern vehicles let owners use the Internet or a mobile device to control the car’s locks, track location and performance data, and start the engine. But who exactly owns that control is not always clear when these smart cars are sold or leased anew. Here’s the story of one former electric vehicle owner who discovered he could still gain remote, online access to his old automobile years after his lease ended.

Mathew Marulla began leasing a Ford Focus electric vehicle in 2013, but turned the car back in to Ford at the end of his lease in 2016. So Marulla was surprised when he recently received an email from Ford.com stating that the clock in his car was set incorrectly.

Out of curiosity, Marulla decided to check if his old MyFordMobile.com credentials from 2016 still worked. They did, and Marulla was presented with an online dashboard showing the current location of his old ride and its mileage statistics.

The dashboard also allowed him to remotely start the vehicle, as well as lock and unlock its doors.

Mathew Marulla turned in his leased Ford EV to Ford 4 years ago, so he is no longer the legal owner of the car. But he can still remotely track its location and usage, lock and unlock it, and start the engine.

“It was a three-year lease from Ford and I turned it in to Ford four years ago, so Ford definitely knows I am no longer the owner,” Marulla said, noting that the dashboard also included historic records showing where the Focus had been driven in days prior.

“I can track its movements, see where it plugs in,” he said. “Now I know where the current owner likely lives, and if I watch it tomorrow I can probably figure out where he works. I have not been the owner of this vehicle for four years, Ford knows this, yet they took no action whatsoever to remove me as the owner in this application.”

Asked to comment on Marulla’s experience, a spokesperson for Ford said all Ford dealerships are supposed to perform a “master reset” as part of their used car checklist prior to the resale of a vehicle. A master reset (carried out via the vehicle’s SYNC infotainment screen by a customer or dealer) disassociates the vehicle from all current accounts.

“A master reset cleans phone data and removes previous Ford Pass and My Ford Mobile connections,” the company said in a statement released to KrebsOnSecurity. “Once complete, a previous owner will no longer be able to connect to the vehicle when they log in to My Ford Mobile or Ford Pass.”

As Marulla’s experience shows, if you’re in the market for a used car you should probably check whether it’s possible to reset the previous owner’s control and/or information before purchasing it, or at least ask the dealership to help you ensure this gets done once the purchase is made.

And if you’re thinking of selling your car, it’s a good idea to clear your personal data from the vehicle first. As the U.S. Federal Trade Commission advises, some cars have a factory reset option that will return the settings and data to their original state.

“But even after a factory reset, you may still have work to do,” reads an FTC consumer privacy notice from 2018. “For example, your old car may still be connected to subscription services like satellite radio, mobile Wi-Fi hotspots, and data services. You need to cancel these services or have them transferred to your new vehicle.”

By the way, this issue of de-provisioning is something of a sticky wicket, and it potentially extends well beyond vehicles to a number of other “smart” devices that end up being resold or refurbished. This is doubly so for Internet-connected/capable devices whose design may give the previous owner a modicum of access to or control over the device in question regardless of what steps the new owner takes to limit such access (particularly some types of security cameras).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Alleged Human Trafficker Accused of Faking Social Media to Contact Victim

Alleged Human Trafficker Accused of Faking Social Media to Contact Victim

A Kentucky resident charged with human trafficking and the online promotion of underage sex workers has been accused of creating fake social media profiles to contact victims and dissuade them from testifying against him.

Nigel Nicholas was first arrested in February 2018 and charged with two counts of human trafficking and one count of promoting two or more sex workers. According to arrest reports, the 53-year-old Louisville resident sold sex with underage teens, which was advertised on Backpage.com and other websites.

Backpage and its affiliated websites were seized in April 2018 as part of an enforcement action by the Federal Bureau of Investigation. 

Nicholas allegedly worked in cahoots with a woman named Abigail Varney, profiting from the sale of the teenagers’ bodies. He is said to have paid for a hotel room in which the transactions were carried out and for props that were used to make the notices advertising the teenagers more appealing. 

The alleged human trafficker, who was out on bail, was arrested again on Friday in Louisville for using “deception and fraud to coerce the victim, offering both finances and property in exchange for a retraction of allegations,” according to a news release. 

Nicholas is accused of paying someone to come to Kentucky from Texas and help him put pressure on one of his alleged victims not to testify against him. The victim was allegedly offered an apartment, car, and money in return for keeping their mouth shut. 

A further accusation now being waged against Nicholas is that he created fake social media pages to contact the victim.

Nicholas now faces an additional charge of tampering with a witness, a Class D felony. As a result of the new charge, $20,000 has been added to Nicholas’ initial $10,000 bond. 

In a statement released on Saturday, Attorney General Daniel Cameron said: “Our Cyber Crimes Unit is committed to partnering with local, state, and federal law enforcement to apprehend human trafficking criminals who attempt to intimidate and coerce witnesses.

“I am grateful to our hardworking investigators and law enforcement for their diligent work on this case.”

Jefferson County Commonwealth Attorney Christie Foster, who is prosecuting the case, said more arrests are expected.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Racine Mayor Refuses to Pay Cyber-Ransom

Racine Mayor Refuses to Pay Cyber-Ransom

The mayor of a Wisconsin city in the grips of a ransomware attack has said that any demands for a ransom payment will not be met. 

Computer systems in the city of Racine were infected with ransomware on Friday morning. As a result, the city’s website, email, voicemail, and payments systems have been knocked offline. 

Citizens are being encouraged to conduct their business in person at City Hall during a recovery process that officials say could take over a week to complete.

“If you need to interact electronically, for all intents and purposes, this week we need you to go back to an older, more analog time,” Racine Mayor Cory Mason said on Monday. “Come on into City Hall, say hello.”

The city is yet to receive a ransom demand from whomever was behind the cyber-attack. 

“While we have received this ransomware in our system, we have not received a specific ransomware request. And, if we did receive such a request, we would not pay it,” said Mason. 

The mayor added that Racine has a cyber-insurance policy, which should cover the city for most of the expenses incurred restoring computer services.

While over 700 city employees have been impacted by the cybersecurity incident, the city’s library and emergency dispatch departments are continuing to operate as normal. 

Racine Police reported being unable to process fee payments or provide copies of police or accident reports in a Facebook post.

State and federal agencies have been notified of the incident, and an investigation into how the attack occurred and who was behind it is currently under way. 

Mason said: “We’ve been doing forensics on all of our systems citywide. For now, most systems are offline; this includes our website, email, and voicemail.”

The mayor said the city was not aware of any sensitive data’s having been exposed as a consequence of the ransomware attack.

“It appears that none of our backup data has been breached; that includes all personal identification information and files,” said Mason.

Racine is the second Wisconsin city to suffer a ransomware attack in a week, after Oshkosh was hit last Tuesday in a similar incident. Neither city has so far received an actual ransom demand.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Democrats Deny Iowa Caucus App Hack

Democrats Deny Iowa Caucus App Hack

America’s Democratic Party has said that cybersecurity issues are not responsible for the unprecedented delay in calculating the results of the 2020 Iowa caucuses.

Members of the Democratic and Republican parties gathered in precincts across the state yesterday to vote for their preferred candidates in the first major contest of the United States’ presidential primary season. 

While the Republican Party returned results last night naming President Donald Trump as their preferred presidential candidate, the results of the votes cast by Democratic Party members had still not been released as of 9:45 a.m. this morning Eastern Time (ET).

Technological failures of the Democratic Party’s phone system and of an app introduced to aid the voting process are being blamed for the delay, which Iowa Democratic Party Communications Director Mandy McClure has said was definitely not caused by a cyber-attack.

McClure issued the following statement: “We found inconsistencies in the reporting of three sets of results. In addition to the tech systems being used to tabulate results, we are also using photos of results and a paper trail to validate all results match and ensure we have confidence and accuracy in the numbers we report. 

“This is simply a reporting issue, the app did not go down, and this is not a hack or an intrusion. The underlying data and paper trail is found and will simply take time to further report the results.”

Precinct chairs reportedly experienced difficulties when trying to download the app and when logging in to report voting results. Phone lines designed to act as a back-up were subsequently overrun, with some precinct chairs reporting waiting on hold for over an hour to report results. 

The app was built by Shadow Inc., a small company based in Washington, DC, at a cost of $63,000. According to a report in the New York Times, the app had not been tested by end-users and precinct chairs had not received training on how to use it.

This morning, Biden campaign general counsel Dana Remus sent a letter to top Iowa Democratic Party officials demanding “full explanations and relevant information” for the “failed” systems the IDP deployed for the caucuses. 

Remus wrote: “The app that was intended to relay Caucus results to the Party failed; the Party’s back-up telephonic reporting system likewise failed. Now, we understand that Caucus Chairs are attempting to—and in many cases, failing to—report results telephonically to the Party. These acute failures are occurring statewide.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk