Exactly how the patch will be deployed to customers isn’t quite clear either. The company writes that âriders can perform a firmware update on the rear derailleurâ using Shimanoâs E-TUBE Cyclist smartphone app. But it fails to mention whether the fix will apply to the front derailleur. âMore information about this process and steps riders can take to update their Di2 systems will be available shortly,â it concludes.
While Shimano’s patching plan leaves a week or two-week gap between the researchers’ public presentation of their bike-hacking technique at Usenix and the broad rollout of a fix for customers, UCSD professor Fernandes argues it’s unlikely that average riders will be targeted with their techniqueâat least not immediately. âI find it hard to believe that someone will want to launch such an attack on me during my Saturday group ride,â Fernandes says.
Professional cyclists, however, should be sure to implement the early patch that Shimano has already provided, the researchers say. They note, too, that other brands of wireless shifters may be vulnerable to similar hacking techniques: They focused on Shimano only because it has the largest market share.
In the ruthless world of competitive cycling, which has been rocked to its foundations in recent decades by doping scandals, they argue that rivals hacking each others’ shifters is not at all a far-fetched scenario. âThis is, in our opinion, a different kind of doping,â says Fernandes. âIt leaves no trace, and it allows you to cheat in the sport.â
More broadly, they argue that their radio-based bike hacking research is a cautionary tale about the temptation to add wireless electronic features to every technology, from garage doors to cars to bicycles, and the unintended consequences of that long-term trendânamely, that they’ve all become vulnerable to forms of replay and jamming attacks of the kind that Shimano is now scrambling to fix.
âThis is a repeating pattern,â says Northeastern’s Ranganathan, who has also developed solutions for replay attacks on carsâ keyless entry systems. âWhen manufacturers start putting in wireless features in their products, it has an impact on real-world control systems. And that can cause real physical harm.â
+ There are no comments
Add yours