Sponsored
Status
Not open for further replies.

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 
Rivian’s CISO, Mike Johnson is a well regarded guy in the security community. They are one of the companies trying to do things the right way. Glad to see them sponsor events like this.
 

McLovin

Well-Known Member
Joined
Jul 30, 2024
Threads
7
Messages
508
Reaction score
1,153
Location
Virginia
Vehicles
R1T
Clubs
 
For those of us who had no idea what “CTF” was…from Google AI:

DEF CON CTF is a premier hacking and cybersecurity competition held annually at the DEF CON security conference, featuring attack-defense and Jeopardy-style formats to test participants' skills in exploiting vulnerabilities and defending systems. Originating in 1996, it's the oldest continuously running CTF and serves as a benchmark for cybersecurity skill, with challenges ranging from cryptography to radio frequency hacking. The competition attracts a global community of hackers, security professionals, and enthusiasts.
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,749
Reaction score
10,139
Location
Washington
Vehicles
2022 Rivian R1T LE
For those of us who had no idea what “CTF” was…from Google AI:

DEF CON CTF is a premier hacking and cybersecurity competition held annually at the DEF CON security conference, featuring attack-defense and Jeopardy-style formats to test participants' skills in exploiting vulnerabilities and defending systems. Originating in 1996, it's the oldest continuously running CTF and serves as a benchmark for cybersecurity skill, with challenges ranging from cryptography to radio frequency hacking. The competition attracts a global community of hackers, security professionals, and enthusiasts.
That's a shite definition. CTF stands for "Capture the Flag". Vendors set up a vulnerable system and embed 'flags' - just encoded strings - in specific locations that hackers get in order to prove access to certain systems or locations.
 

Sponsored

McLovin

Well-Known Member
Joined
Jul 30, 2024
Threads
7
Messages
508
Reaction score
1,153
Location
Virginia
Vehicles
R1T
Clubs
 
That's a shite definition. CTF stands for "Capture the Flag". Vendors set up a vulnerable system and embed 'flags' - just encoded strings - in specific locations that hackers get in order to prove access to certain systems or locations.
lol…I just noticed that Google AI left out the actual definition of “CTF”, which I found in other hits. I just assumed it had the definition in there.

Proof that AI isn’t all it’s cracked up to be at this point. If it can’t provide a simple definition of an acronym…
 

CharonPDX

Well-Known Member
First Name
Charon
Joined
Jul 12, 2021
Threads
31
Messages
2,497
Reaction score
4,171
Location
Cascadia
Vehicles
'22 R1T LE, '16 Model S, '19 Arcimoto FUV
Occupation
InfoSec Geek
Clubs
 
Dang, sad I'm missing it this year! (I usually go to DEFCON, but had multiple previous commitments this weekend.)
 

Wat5

Active Member
Joined
May 22, 2024
Threads
1
Messages
36
Reaction score
31
Location
Vancouver, WA
Vehicles
Polestar 2 (soon R1T)
Occupation
SW Engineer
Ahh I missed this. Would have loved to poke around but the venue was huge and there's always more things to do than there is time.
 

usulio

Well-Known Member
Joined
Jun 2, 2023
Threads
8
Messages
1,031
Reaction score
1,249
Location
CO
Vehicles
R1S
Clubs
 
Rivian’s CISO, Mike Johnson is a well regarded guy in the security community. They are one of the companies trying to do things the right way. Glad to see them sponsor events like this.
I appreciate him trying ... but given this is the company that keeps a database of video footage of you and your children and a log of everywhere you go ... I think his definition of security is different than mine.
 

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 
I appreciate him trying ... but given this is the company that keeps a database of video footage of you and your children and a log of everywhere you go ... I think his definition of security is different than mine.
You are referring to privacy, not security. Privacy is a component of security (confidentiality), but consumers are given choices about how their personal data is handled, which they don't technically have to offer. They could just say that in buying this vehicle you are agreeing to ALL these policies. So that is what I mean by "trying to do things the right way". Rivian is telling you what data they collect, what they do with it, and allowing you to opt out if you want.

For example, you can opt out of the GPS if you are that worried about it. But if that is true I would think you wouldn't use GPS navigation on your phone either. So it's a question of each person's tolerance, which Rivian is attempting to account for by providing options. Google Maps in this case is not connected to your Google account, or even your specific Rivian.

The “security“ part of this is more about protection of your data, which they do:
https://rivian.com/support/article/...a-both-on-the-vehicle-and-in-the-rivian-cloud

They are not ”keeping footage of you and your children” :rolleyes: Gear Guard footage is only stored in the vehicle.
https://rivian.com/support/article/...deos-can-rivian-provide-a-copy-of-a-video-fro

They even give you the option to turn off ALL data collection if you desire:
https://rivian.com/support/article/can-i-disable-all-data-collection-from-my-vehicle
 

Sponsored

Dark-Fx

Well-Known Member
First Name
Brian
Joined
Jul 15, 2020
Threads
147
Messages
13,521
Reaction score
27,288
Location
Michigan
Vehicles
R1T, R1S, Livewire One, Sierra EV, R1S
Occupation
Engineering
Clubs
 

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 

usulio

Well-Known Member
Joined
Jun 2, 2023
Threads
8
Messages
1,031
Reaction score
1,249
Location
CO
Vehicles
R1S
Clubs
 

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 
I seem to have been wrong about footage, but they do upload still images from the cameras for "product improvement". You are also right that one can opt out.
https://rivian.com/support/article/faq-what-choices-do-i-have-regarding-my-vehicle-cameras
I should have added that you are right to be protective of your data and privacy. Our Rivians are like big data vacuums and if we ignored the potential risks, we would all be pretty ignorant. I have spent more time than I care to admit reading through all the privacy policies :facepalm:
 

usulio

Well-Known Member
Joined
Jun 2, 2023
Threads
8
Messages
1,031
Reaction score
1,249
Location
CO
Vehicles
R1S
Clubs
 
You are referring to privacy, not security. Privacy is a component of security (confidentiality), but consumers are given choices about how their personal data is handled, which they don't technically have to offer. They could just say that in buying this vehicle you are agreeing to ALL these policies. So that is what I mean by "trying to do things the right way". Rivian is telling you what data they collect, what they do with it, and allowing you to opt out if you want.
Yeah, privacy is a component of security, not all of security.

I do generally opt out of location services. There is no technical need for Rivian to store a history of my precise location in order to offer GPS navigation. They do store it, and say they may share my data with advertisers and with law enforcement even when not legally required to do so.

With the new map update, Rivian also makes you agree to Google TOS.

I know Rivian isn't the worst company out there, but they follow lots of "industry standard" shady anti-consumer practices with regard to privacy.
Sponsored

 
Status
Not open for further replies.
 








Top