è»ã«æœãç¥ãããããã©ã€ãã·ãŒãªã¹ã¯
å°å ã®èªåè»è§£äœå Žã¯ãã¯ã©ã·ãã¯ã«ãŒæå¥œå®¶ãæŽåå·¥å Žã®ãªãŒããŒã«ãšã£ãŠãå ¥æå°é£ãªéšåãèŠã€ããããå®ã®å±±ã§ããããããå£ããã·ã£ã·ãŒãéå±ã¹ã¯ã©ããã®å±±ã®äžã«ã¯ãç®ã«èŠããªãããäžã€ã®âå®âããèšå€§ãªå人æ å ±ããæœãã§ããŸãããããããæªæãã第äžè ã®æã«æž¡ãã°ããã©ã€ããŒã®ãã©ã€ããŒããªç§å¯ãå人æ å ±ãæµåºãããªã¹ã¯ããããŸãã
ãã®çç±ã¯ãç§ãã¡ãæ¥åžžçã«ä¹ã£ãŠããè»ããããŸããèµ°ãã³ã³ãã¥ãŒã¿ãŒããžãšé²åããŠããããã§ãããããã®è»ã¯èšå€§ãªéã®ããŒã¿ãåéã»åŠçã»å ±æããŠããããã€ã¯ãã«ã¡ã©ãåçš®ã»ã³ãµãŒã®æèŒã«ãã£ãŠããœãããŠã§ã¢ã»ããã¡ã€ã³ãã»ããŒã¯ã«ïŒSDVïŒãæ±ãå人æ å ±ã®éã¯ãã€ãŠãªãã»ã©å¢ããŠããŸããã€ãŸããããªããSDVãé転ããŠãããªããç¥ããªããã¡ã«ãã©ã€ãã·ãŒãå±éºã«ãããããŠããå¯èœæ§ãããã®ã§ãã
èªåè»ã¡ãŒã«ãŒãã¢ããªæäŸè ãåéããŠããããŒã¿ã®å®æ ããæ¶è²»è ãèŠå¶åœå±ã®éã§åºãèªèãããããã«ãªãã«ã€ãããããŒã¿ãã©ã€ãã·ãŒãã¯èªåè»ã¡ãŒã«ãŒããã©ã€ããŒã«ãšã£ãŠããã¯ããªããŠã¯ãªããªãæ©èœãžãšé²åããŠããŸãã
èªåè»è§£äœå ŽïŒãããšãããã«ãŒã®æ¥œåïŒ
PlaxidityXã®Threat Research Labãæè¿å ¬è¡šããã»ãã¥ãªãã£èª¿æ»ã§ã¯ãè»èŒãœãããŠã§ã¢ãäžååãªããŒã¿ä¿è·ã®å®æ ããã©ã®ããã«ãã©ã€ããŒã®å人æ å ±ãå±éºã«ããããŠããããæããã«ããŸããã調æ»çµæã«ãããšãäžåœã§é«ã人æ°ãèªããã黿°èªåè»ããããã©ã€ããŒã®äœçœ®æ å ±ãé£çµ¡å ãå®¶æã®å¥åº·æ å ±ãå€åå äœæãããã«ã¯Spotifyã®é³æ¥œå奜ãšãã£ã極ããŠæ©åŸ®ãªå人ããŒã¿ããé©ãã»ã©å®¹æã«æœåºã§ããŠããŸãããšã瀺ãããŠããŸãã
ãã®èª¿æ»ã®ç®çã¯ãè»ããåéããããŒã¿ãè§£æããŠãããã«ãŒãã©ããŸã§å人ã®ç§ç掻ã«èžã¿èŸŒããŠããŸãã®ããæããã«ããããšã§ããã調æ»ã¯ãå°å ã®èªåè»è§£äœå Žããå§ãŸããŸãããããã§ãããŒã¿æ¶å»ãããŠããªã2023幎補BYD ATTO 3ã®ãã«ãã¡ãã£ã¢ããããŠãããïŒIVIïŒãå ¥æããŸãããéåžžã«äººæ°ãé«ãè»çš®ã§ãããšããããšããŸãäžåœã®èªåè»ã¡ãŒã«ãŒã¯äžè¬çã«ããŒã¿ãã©ã€ãã·ãŒãžã®é æ ®ãååãšã¯èšããªããããç 究察象ãšããŠçæ³çãªã±ãŒã¹ã§ããã
ç§ãã¡ã¯ã©ãã§ãã®IVIã«æ¥ç¶ããä¿åã»åŠçãããŠããããŒã¿ã調æ»ããŸããããããšé©ããããšã«ãæ
å ±ã®æå·åãå§çž®ã¯äžåè¡ãããŠãããã匷åãªãã¹ã¯ãŒããèšå®ãããŠããŸããã§ããã
ããã¯ãããŒã¿ããã°ãã¡ã€ã«ãžã®äžæ£ã¢ã¯ã»ã¹ã詊ã¿ãããã«ãŒã«ãšã£ãŠãããŸãã«ãããŒãã«ãäœãå±éºãªç¶æ
ã§ãããã©ã€ããŒãžã®ã¡ãã»ãŒãžã¯æç¢ºã§ããèªåã®è»ãåéããŠããããŒã¿ãå®å
šã«ä¿è·ãããŠãããšéä¿¡ããªãããšããããŠãèªåã«ã¯é¢ä¿ãªããšèããªãããšã§ãã
調æ»ã®éçšã§ãç§ãã¡ã¯BYDã®DiLink 3.0 OSïŒATTO 3ãªã©ã®ã¢ãã«ã«æèŒïŒã«ãããã·ã¹ãã ãã°ãã³ãæ©èœã«ãæå·åå®è£ ã®äžåã«ããè匱æ§ãååšããããšãçºèŠããŸããããã®çºèŠã¯ã責任ããé瀺ããã»ã¹ã«åŸãBYD瀟ã«å ±åãããã®åŸASRGããCVE-2025-7020ãšããŠå ¬éããŠããŸãã
å人æ å ±ã®å®åº«
ç§ãã¡ãè»äž¡ãã°ããçºèŠããå人ããŒã¿ã®éãšãã®è©³çްã¬ãã«ã¯ããŸãã«é©æã®äžèšã§ããããã©ã€ããŒã®ã¹ããŒããã©ã³ããååŸãããŠããããŒã¿ã«ã¯ãé¢ä¿æ§ã瀺ãã¡ã¿ããŒã¿ä»ãã®å®å šãªé£çµ¡å ãªã¹ããå«ãŸããŠããã圌女ã®ç¶èŠªã»æ¯èŠªã»å åŒå§åŠ¹ã®æ°åãšé£çµ¡å ãããããŸãããããã«ãåœŒå¥³ãæ°çå ç§å»ããããã€ãã«ããŠããããšããèµ€ã¡ãããããããšãåãããè¬å€åž«ã®ååãŸã§ç¹å®ã§ããŸãããã©ãžãªå±ã®å¥œã¿ãSpotifyã®åçãªã¹ãããããããã圌女ã¯ãµããªãã»ã«ãŒãã³ã¿ãŒãããªãŒã»ã¢ã€ãªãã·ã¥ã®ãã¡ã³ã§ããããšãŸã§ããã£ãŠããŸãã®ã§ãã
ããã«ãæºåž¯ç«¯æ«ã®å®å šãªè奿 å ±ïŒCCIDãIMSIãMACã¢ãã¬ã¹ãIMEIïŒãæœåºããããšãã§ããŸããããããã¯æªçšããããšãæ¬äººãžã®ãªãããŸãããã®ä»ã®æ·±å»ãªãã©ã€ãã·ãŒäŸµå®³ã«çµã³ã€ãæãããããŸãã
1幎åã®GPS远跡ããŒã¿ãããè»èŒäœçœ®æ å ±ãåºã«éå»1幎éã«åœŒå¥³ã蚪ããå Žæã®ã»ãŒãã¹ãŠããããããæ°åã¡ãŒãã«ã®èª€å·®ç¯å²ã§ç¹å®ã§ããŸãããããã«ãããããã«ãŒã¯ããŒãããããäœæãããã©ã€ããŒã®èªå® ãå€åå ãããã«ã¯ç¹å®ã®äººç©ãšã®äŒåå ŽæãŸã§æšå®ããããšãå¯èœã«ãªããŸãã
圌女ã®é»è©±çªå·ã䜿ã£ãŠãTruecallerïŒçºä¿¡è IDã»è¿·æé»è©±ãããã¯ã¢ããªïŒãã圌女ã®èªæ®ãåçãååŸããŸãããããã¯ãé»è©±çªå·ããå³åº§ã«ææè ã®æ°åãé¡åçãå ¥æã§ãããäžè¬çãªææ³ã®äžäŸã«éããŸããããŸãããã©ã€ããŒã®æ³šæåãã¢ãã¿ãŒããããã®è»å ã«ã¡ã©ã䟵害ããã°ãèªæ®ãåçãååŸã§ããå¯èœæ§ããããŸãïŒä»åã®èª¿æ»ã§ã¯ãã®æ»æçµè·¯ã®æ€èšŒã¯è¡ã£ãŠããŸããïŒã
ããªãã®è»ãåéããããŒã¿ãäžåœãžéä¿¡ãããŠãããããããŸãã
ç§ãã¡ã®èª¿æ»ã«ãã£ãŠãBYDè»ã§ããã°æå 端ã®ããŒã«ã䜿ããªããŠããããã«ãŒãç°¡åã«ãã©ã€ããŒã®å人æ å ±ã«ã¢ã¯ã»ã¹ã§ããããšãæããã«ãªããŸãããããã«åé¡ãªã®ã¯ãããããæ å ±ããããããæèŒãããGSMã¢ãã ãéããŠãäžåœåœå ã®ãµãŒããŒãžç¶ç¶çã«éä¿¡ãããŠããç¹ã§ãããã®äºå®ã ãã§ããBYDã®ãã©ã€ããŒã«ãšã£ãŠã¯ååã«è¡æçã§ããèªåã®å人æ å ±ãéä¿¡ãããŠãããšç¥ãã°ãæ å ±éä¿¡ã忢ããããBYDã«æ±ããããªãã®ãåœç¶ã§ãããã
å°æ¿åŠçãªèгç¹ããèŠããšãããããå人æ å ±ãäžåœãžéä¿¡ãããŠããäºå®ã¯ãåœå®¶å®å šä¿éããµã€ããŒè«å ±æŽ»åã®èгç¹ã§éå€§ãªæžå¿µãåŒãèµ·ããå¯èœæ§ããããŸããç±³åœååçããäžåœããã·ã¢çµç±ã®ã³ãã¯ãããã«ãŒåãããŒããŠã§ã¢ããã³ãœãããŠã§ã¢ã®è²©å£²ã»èŒžå ¥ãçŠæ¢ããæçµèŠåãçºè¡šããããšã¯ãæµ·å€ã®é¢ä¿æ©é¢ãžã®ããŒã¿æµåºãå¶éããå¿ èŠæ§ãžã®èªèãäžå±€é«ããŸããããã®æèã«ãããŠãè»äž¡ããåéãããå人æ å ±ããæ¿åºé¢ä¿è ãè»é¢ä¿è ã®å®å šãè ããããã«æªçšããããªã¹ã¯ãååã«èããããŸãã
èªåè»åéã®ããŒã¿ãã©ã€ãã·ãŒå¯Ÿçã¯ããŸã é ããåã£ãŠãã
ããŒã¿ãã©ã€ãã·ãŒã«é¢ããèŠå¶ãç¹ã«GDPRïŒäžè¬ããŒã¿ä¿è·èŠåïŒã¯ãå人ããŒã¿ãããªãã¡ãç¹å®ãŸãã¯ç¹å®å¯èœãªèªç¶äººã«é¢é£ããããããæ å ±ãã«å¯ŸããŠãå人ããã匷ãç®¡çæš©éãæãŠãããã«ããããããããŠEUå šäœã§çµ±äžãããããŒã¿ä¿è·ã«ãŒã«ã確ç«ããããã«å¶å®ãããŸãããããããèªåè»æ¥çã«ãããŠã¯ãä»ã®æ¥çãšæ¯ã¹ããšãããã®ãã©ã€ãã·ãŒèŠå¶ã®é©çšãå·è¡ã¯ãããŸã çºå±éäžã®æ®µéã«ããããã§ãã
Mozillaã®èª¿æ»ã«ãããšãçŸä»£ã®èªåè»ã¯ããã©ã€ãã·ãŒã«é¢ããŠãããŸã§ã«è©äŸ¡ããäžã§ææªã®è£œåã«ããŽãªãŒãã§ãããšãããŠããŸããããã¯ãèªåè»ã¡ãŒã«ãŒã«ããããŒã¿ä¿è·äœå¶ã®äžåãäž»ãªçç±ã§ããå®éãã»ãŒãã¹ãŠã®èªåè»ã¡ãŒã«ãŒãMozillaã®ãPrivacy Not IncludedïŒãã©ã€ãã·ãŒé察å¿ïŒããªã¹ãã«æ²èŒãããŠããŸãããGDPRã®ããšã§èªåè»æ¥çã«å¯ŸããŠèª²ããã眰éã¯ããããŸã§ã®ãšããããã3ä»¶ã«ãšã©ãŸã£ãŠããŸãã
- 2022幎ã«ã¯ããã©ã«ã¯ã¹ã¯ãŒã²ã³ïŒVWïŒããæ©è¡è ã®åæãåŸãã«ADASïŒå é²éè»¢æ¯æŽã·ã¹ãã ïŒã®åŠç¿çšããŒã¿ãšããŠæ åã䜿çšããããšã«ããã110äžãŠãŒãã®çœ°éãç§ãããŸããã
- 2023幎ã«ã¯ããã©ã«ã¯ã¹ã¯ãŒã²ã³ã»ãªãŒã¹ïŒVolkswagen Leasing GmbHïŒãã顧客ããã®èŠè«ã«å¯Ÿããå瀟ãä¿æããåœè©²é¡§å®¢ã®å人ããŒã¿ãæäŸããªãã£ããšããŠã4äžãŠãŒãã®çœ°éãç§ãããŸããã
- 2024幎ã«ã¯ãããšã¿ã®ããŒã©ã³ãéèåäŒç€Ÿã§ããããšã¿éè¡ãã«ã¹ã«ïŒToyota Bank PolskaïŒããããŒã¿æŒããçºçåŸ72æé以å ã«åœå±ãžå ±åããªãã£ããšããŠã1äž8,000ãŠãŒãã®çœ°éãç§ãããŸããã
ãã®ãããªã®ã£ãããçããŠããèæ¯ã«ã¯ãããŒã¿ä¿è·ã®å ·äœçãªèŠä»¶ãããšãã°æå·åã®æ¹æ³ãªã©ãæç¢ºã«å®çŸ©ãããŠããªãããšã倧ããªèŠå ãšããŠæããããŸããGDPRã§ã¯ãå人ããŒã¿ã®éä¿¡ãä¿åã«é¢ããæäœéã®ã»ãã¥ãªãã£èŠä»¶ã¯å®ããããŠãããã®ã®ãæªæããæ»æè ããæ¶è²»è ïŒãããã¯äŒæ¥ïŒãä¿è·ããããšèªäœã¯äž»ãªç®çã§ã¯ãããŸããããã®é åã¯ãUNR 155ãªã©ãä»ã®ãµã€ããŒã»ãã¥ãªãã£é¢é£èŠå¶ã«ãã£ãŠã«ããŒãããŠããŸãã
ããšãã°ãGDPRã«ã¯æå·ã®åŒ·åºŠã«é¢ããå ·äœçãªåºæºãå®ããããŠããŸããããã®ãããä»®ã«OEMãWi-Fiã®ãã¹ã¯ãŒããã123456ãã«èšå®ãããšããŠããããã¹ã¯ãŒããèšå®ããŠããããšããèŠä»¶èªäœã¯æºãããŠããããšã«ãªããŸããããããããã§ããªãã®ããŒã¿ãå®å šã«å®ãããããã§ã¯ãããŸããã
ããã«ãããŒã¿ãã©ã€ãã·ãŒé¢é£ã®èŠå¶ã§ã¯ãäŒæ¥ãäœçœ®æ å ±ãé£çµ¡å ãšãã£ãå人æ å ±ãåéããéããŠãŒã¶ãŒããæç€ºçãªåæãåŸãããšã矩åä»ããããŠããŸãããããç§ãã¡ã®èª¿æ»ã§ã¯ããŠããããå·¥å Žåºè·æèšå®ã«ãªã»ããããåŸã§ããããã®ãããªåæãæ±ãã確èªã¯äžå衚瀺ãããŸããã§ããããããŠçŸåšãããã®åé¡ãBYDè»äž¡ã«ãããŠåºãæ®ã£ãŠããããšã確èªããŠããŸãã
è»ã®ãªãŒããŒãçŽé¢ãããªã¹ã¯
ããŒã¿ä¿è·ã®æ¹åã«å¯Ÿãã責任ã¯ãèªåè»ã¡ãŒã«ãŒã ãã«ãšã©ãŸããŸãããããšãã°ãããªãããšãŒãããã§2é±éã®äŒæãéããéã«ã¬ã³ã¿ã«ãŒãå©çšãããšããŸãããããã®ãšããèªåã®ã¹ããŒããã©ã³ãè»ã®ãã«ãã¡ãã£ã¢ã·ã¹ãã ã«æ¥ç¶ããããšæããŸããïŒèªåã®ããŒã¿ãå€éšãµãŒããŒã«éä¿¡ãããããæŒããããããããªã¹ã¯ãåããã§ããããïŒãããŠãããªããåããè»ã«ã©ã®çšåºŠã®ããŒã¿ä¿è·å¯ŸçãæœãããŠããã®ããææ¡ããŠãã人ã¯ã»ãšãã©ããªãã®ãçŸå®ã§ãã
ãã©ã€ããŒèªèº«ã®æèããããå人æ å ±ãå®ãããã®æãéèŠãªéµã§ãããããã¬ã³ã¿ã«ãŒã«èªåã®ã¹ããŒããã©ã³ãã©ãããŠãæ¥ç¶ããå¿ èŠãããå Žåã¯ãè¿åŽæã«å¿ ãèªåïŒãããã¯ã¬ã³ã¿ã«ãŒäŒç€ŸïŒã§ããŒã¿ãå®å šã«æ¶å»ããããã«ããŠãã ãããåæ§ã®ãªã¹ã¯ã¯ãèªåè»ã¡ãŒã«ãŒãæäŸãããªãŒã¹å¥çŽããèªå®¶çšè»ã売åŽããå Žåã«ãååšããŸããè»ãææŸãåã«ã¯ãå人æ å ±ãé転履æŽããŒã¿ããã¹ãŠç¢ºå®ã«åé€ãããŠããããå¿ ã確èªããããšãéèŠã§ãã
çµè«
PlaxidityXã®ãã®èª¿æ»ã¯ãè»èŒãœãããŠã§ã¢ã®è匱æ§ããã©ã€ããŒãçŸå®çãªãªã¹ã¯ã«ããããŠããããšããã¯ã£ãããšç€ºããŠããŸããããããè匱æ§ã«ããããã©ã€ããŒã®æ¥µããŠãã©ã€ããŒããªå人æ å ±ããããã«ãŒãäžåœãªã©åœå€ã®èªåè»ã¡ãŒã«ãŒã®æã«æž¡ãå¯èœæ§ãããã®ã§ãã
ãããŠããã®åé¡ã¯ããã«ã¯è§£æ±ºãããã«ãããŸããããã³ããŒå瀟ã¯ä»åŸããèªç€Ÿè£œåã®æ¹åããã©ãã«å¯Ÿå¿ããããŠæ°ããªåçåã®æ©äŒãåŸãããã«ããŒã¿åéãç¶ããŠããã§ããããäžæ¹ã§ãŠãŒã¶ãŒåŽããããè¯ã補åããµãŒãã¹ãæäŸããŠããããã®ã§ããã°ãå人æ å ±ã®æäŸã«äžå®ã®çè§£ã瀺ããŠããŸãã
解決ã®åã«ãªããããªã®ã¯ãæ¶è²»è ãšèªåè»ã¡ãŒã«ãŒãšã®éã«ããããããé«ãéææ§ã®ç¢ºä¿ã§ããã¡ãŒã«ãŒåŽã¯ã©ã®ãããªæ å ±ããã©ã®ç¯å²ã§ãã©ã®ç®çã§åéããŠããã®ãããããæç¢ºã«äŒããåãçµã¿ãé²ããã¹ãã§ãããããŠæ¶è²»è ããŸãããããåœç¶ã®æš©å©ãšããŠæ±ããå¿ èŠããããŸããããšãã°ãæ å ±åéã®ã¿ã€ãã³ã°ã§ãŠãŒã¶ãŒã®åæãæ±ããæšæºçãªæ¹æ³ãAndroidã®å®è¡æã®æš©éãå±éºãªæš©éïŒdangerous permissionsïŒãã«äŒŒãä»çµã¿ãæ¥çå šäœã§å°å ¥ããããšãèããããŸãã
ãã®ãªã¹ã¯ãžã®èªèãé«ããããšã¯ãèªåè»ã¡ãŒã«ãŒããã©ã€ããŒã®å人ããŒã¿ãé©åã«ä¿è·ããããã®è¡åãåãããã§æ¬ ãããŸãããå®å šæ§ãæåªå ã§ããããšã¯èšããŸã§ããããŸããããä»åŸã¯ããŒã¿ä¿è·ããŸããèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠéèŠãªç«¶äºèŠä»¶ã®1ã€ãšãªã£ãŠããã§ãããã
å·çïŒ2025幎10æ27æ¥