What would you say if I told you a company didn't know some of their customer data was exposed for 5 years? It happened! Jump in today and learn how Toyota kept things in neutral and missed the on-ramp to better security! Join my special guest (my wife!) and I as we delve into how this occurred and what other companies need to watch out for!


Links of interest

Toyota defines T-Connect: http://www.toyotaconnected.co.jp/en/service/telematics.html

GitGuardian's take on this breach: https://blog.gitguardian.com/toyota-accidently-exposed-a-secret-key-publicly-on-github-for-five-years/

Toyota's Breach Notification: https://global.toyota/jp/newsroom/corporate/38095972.html

Duo's advice for monitoring GitHub for your secrets: https://duo.com/labs/research/how-to-monitor-github-for-secrets

Samsung has a similar problem: https://www.bleepingcomputer.com/news/security/hackers-leak-190gb-of-alleged-samsung-data-source-code/


audio-thumbnail
RootEd Security, episode 19
0:00
/28:48