Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

mahatmakanejeeves

(57,613 posts)
Wed Aug 17, 2022, 02:20 PM Aug 2022

A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave

LILY HAY NEWMAN | SECURITY | AUG 13, 2022 9:31 PM

A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave

A hacker has formulated an exploit that provides root access to two popular models of the company’s farm equipment.

FARMERS AROUND THE world have turned to tractor hacking so they can bypass the digital locks that manufacturers impose on their vehicles. Like insulin pump “looping” and iPhone jailbreaking, this allows farmers to modify and repair the expensive equipment that’s vital to their work, the way they could with analog tractors. At the DefCon security conference in Las Vegas on Saturday, the hacker known as Sick Codes is presenting a new jailbreak for John Deere & Co. tractors that allows him to take control of multiple models through their touchscreens.

The finding underscores the security implications of the right-to-repair movement. The tractor exploitation that Sick Codes uncovered isn't a remote attack, but the vulnerabilities involved represent fundamental insecurities in the devices that could be exploited by malicious actors or potentially chained with other vulnerabilities. Securing the agriculture industry and food supply chain is crucial, as incidents like the 2021 JBS Meat ransomware attack have shown. At the same time, though, vulnerabilities like the ones that Sick Codes found help farmers do what they need to do with their own equipment. ... John Deere did not respond to WIRED's request for comment about the research.

Sick Codes, an Australian who lives in Asia, presented at DefCon in 2021 about tractor application programming interfaces and operating system bugs. After he made his research public, tractor companies, including John Deere, started fixing some of the flaws. “The right-to-repair side was a little bit opposed to what I was trying to do,” he tells WIRED. “I heard from some farmers; one guy emailed me and was like ‘You’re fucking up all of our stuff!’ So I figured I would put my money where my mouth is and actually prove to farmers that they can root the devices."

This year, Sick Codes says that while he is primarily concerned about world food security and the exposure that comes from vulnerable farming equipment, he also sees important value in letting farmers fully control their own equipment. “Liberate the tractors!” he says.

{snip}
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave (Original Post) mahatmakanejeeves Aug 2022 OP
I was today years old when I learned about tractor hacking. underpants Aug 2022 #1
There are thousands of videos on YT discussing jailbreaking equipment. Probatim Aug 2022 #2
This was new to me. I agree. That's total BS. underpants Aug 2022 #3
Unintended Greed 4Q2u2 Aug 2022 #4
My brother sent me a long text on McDonalds ice cream machines underpants Aug 2022 #5
Chechens who looted the top of the line, GPS enabled equipment from Ukraine Warpy Aug 2022 #6
Huh Farmer-Rick Aug 2022 #7

underpants

(182,883 posts)
1. I was today years old when I learned about tractor hacking.
Wed Aug 17, 2022, 02:44 PM
Aug 2022

So you HAVE to use their dealerships or approved (I’d guess) repair locations. You can’t even get into it without John Deere programming it. At the Vice link it also sounded like they charge $230 and $130/hour to come out and do this.

Amazing. Crazy and amazing.

Probatim

(2,542 posts)
2. There are thousands of videos on YT discussing jailbreaking equipment.
Wed Aug 17, 2022, 02:48 PM
Aug 2022

The whole idea that the manufacturer alone is the only one permitted to repair their equipment is an abomination for the right to repair folks.

And it should be for most of us as well.

underpants

(182,883 posts)
3. This was new to me. I agree. That's total BS.
Wed Aug 17, 2022, 02:56 PM
Aug 2022

I’ve been told that Mercedes used to shut down if regular maintenance on like brakes wasn’t completed. I don’t know if you had to take them to certified garages but I do know that those existed.

I know someone who bought an Accura and was told AFTER the sale that he had to use premium gas. If he didn’t the warranty was voided.

 

4Q2u2

(1,406 posts)
4. Unintended Greed
Wed Aug 17, 2022, 03:20 PM
Aug 2022

This is all buried in the Patriot Act and Copyright Acts. Large manufacturers put language in to make impossible to work on their platforms. Thus holding your equipment hostage.

underpants

(182,883 posts)
5. My brother sent me a long text on McDonalds ice cream machines
Wed Aug 17, 2022, 03:39 PM
Aug 2022

Same type thing. That’s why they aren’t working a lot. He worked at another place with an ice cream machine. One mistake (like the mixture on the overnight clean) and you have to call a specific technician.

Warpy

(111,351 posts)
6. Chechens who looted the top of the line, GPS enabled equipment from Ukraine
Wed Aug 17, 2022, 05:24 PM
Aug 2022

will just love this libertarian claptrap if it manages to come true before those fancy machines rust solid.

The truth is that these things aren't bought by Mom and Pop farms, they're for big agribusiness spreads. They're largely autonomous, meaning somebody with a monitor screen miles away keeps an eye on several at a time, nobody's sitting in an uncomfortable seat in the hot sun and driving them, which is controlling your own equipment.

Is this stuff over complicated and over proprietary? Oh, yeah, definitely. Are a bunch of hackers going to fix that? My guess is that they'll cause more problems than they solve. I would also guess the main lockout people are looking to override is the one that happens if the machine is stolen or if somebody misses a payment.

Farmer-Rick

(10,212 posts)
7. Huh
Wed Aug 17, 2022, 07:32 PM
Aug 2022

I have a Kubota that I do regular maintenance on...no problems. I did let the corporation do the first few usage milestone maintenance. But now that's it over 10 years old, I do the maintenance regularly.

I guess they couldn't come from Japan to fix it.....just kidding.

But really it's a good little tractor with enough ballast that can take most of my hilly land. And the attachments cover most my needs.

Huh, I never knew they did this with tractors.

Latest Discussions»Issue Forums»Economy»A New Jailbreak for John ...