https://www.wired.com/story/john-deere-tractor-jailbreak-defcon-2022/ Skip to main content Open Navigation Menu To revist this article, visit My Profile, then View saved stories. Close Alert WIRED A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave * Backchannel * Business * Culture * Gear * Ideas * Science * Security More To revist this article, visit My Profile, then View saved stories. Close Alert Sign In Search * Backchannel * Business * Culture * Gear * Ideas * Science * Security * Podcasts * Video * Artificial Intelligence * Climate * Games * Newsletters * Magazine * Events * Wired Insider * Coupons Lily Hay Newman Security Aug 13, 2022 9:31 PM A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave A hacker has formulated an exploit that provides root access to two popular models of the company's farm equipment. * * * * To revist this article, visit My Profile, then View saved stories . John Deere tractor in field Photograph: Paul Marriott/Alamy * * * * To revist this article, visit My Profile, then View saved stories . farmers around the world have turned to tractor hacking so they can bypass the digital locks that manufacturers impose on their vehicles. Like insulin pump "looping" and iPhone jailbreaking, this allows farmers to modify and repair the expensive equipment that's vital to their work, the way they could with analog tractors. At the DefCon security conference in Las Vegas on Saturday, the hacker known as Sick Codes is presenting a new jailbreak for John Deere & Co. tractors that allows him to take control of multiple models through their touchscreens. The finding underscores the security implications of the right-to-repair movement. The tractor exploitation that Sick Codes uncovered isn't a remote attack, but the vulnerabilities involved represent fundamental insecurities in the devices that could be exploited by malicious actors or potentially chained with other vulnerabilities. Securing the agriculture industry and food supply chain is crucial, as incidents like the 2021 JBS Meat ransomware attack have shown. At the same time, though, vulnerabilities like the ones that Sick Codes found help farmers do what they need to do with their own equipment. John Deere did not respond to WIRED's request for comment about the research. Sick Codes, an Australian who lives in Asia, presented at DefCon in 2021 about tractor application programming interfaces and operating system bugs. After he made his research public, tractor companies, including John Deere, started fixing some of the flaws. "The right-to-repair side was a little bit opposed to what I was trying to do," he tells WIRED. "I heard from some farmers; one guy emailed me and was like 'You're fucking up all of our stuff!' So I figured I would put my money where my mouth is and actually prove to farmers that they can root the devices." This year, Sick Codes says that while he is primarily concerned about world food security and the exposure that comes from vulnerable farming equipment, he also sees important value in letting farmers fully control their own equipment. "Liberate the tractors!" he says. After years of controversy in the US over the "right to repair" the equipment one purchases, the movement seems to have reached a turning point. The White House issued an executive order last year directing the Federal Trade Commission to increase enforcement efforts over practices like voiding warranties for outside repair. That, combined with New York state passing its own right-to-repair law and creative activist pressure, has generated unprecedented momentum for the movement. Facing mounting pressure, John Deere announced in March that it would make more of its repair software available to equipment owners. The company also said at the time that it will release an "enhanced customer solution" next year so customers and mechanics can download and apply official software updates for Deere equipment themselves, rather than having John Deere unilaterally apply the patches remotely or force farmers to bring products to authorized dealerships. Most Popular * Mohsin Hamid culture A Glimpse of a Future Without White People Jason Parham * Apple Inc. iMac computers security A Single Flaw Broke Every Layer of Security in MacOS Matt Burgess * sparks coming from paper security Here's What Trump's 'Nuclear Documents' Could Be Garrett M. Graff * SpaceX Starlink internet terminal installed on roof of building security The Hacking of Starlink Terminals Has Begun Matt Burgess * "Farmers prefer the older equipment simply because they want reliability. They don't want stuff to go wrong at the most important part of the year when they have to pull stuff out of the ground," Sick Codes says. "So that's what we should all want too. We want farmers to be able to repair their stuff for when things go wrong, and now that means being able to repair or make decisions about the software in their tractors." To develop his jailbreak, Sick Codes got his hands on numerous generations of John Deere tractor control touchscreen consoles. But ultimately he focused on a few models, including the widely deployed 2630 and 4240 models, for the exploit he is presenting. It took experimentation on a number of touchscreen circuit boards over many months to find bypasses to John Deere's dealer authentication requirements, but eventually Sick Codes was able to game a reboot check to restore the device as if it were being accessed by a certified dealer. He found that when the system thought it was in such an environment, it would offer more than 1.5 GB worth of logs that were meant to help authorized service providers diagnose problems. The logs also revealed the path to another potential timing attack that might grant deeper access. Sick Codes soldered controllers directly onto the circuit board and eventually got his attack to bypass the system's protections. "I launched the attack, and two minutes later a terminal pops up," Sick Codes says of the program used to access a computer's command-line interface. "I had root access, which is rare in Deere land." The approach requires physical access to the circuit board, but Sick Codes says it would be possible to develop a tool based on the vulnerabilities to more easily execute the jailbreak. Mostly he says he is curious to see how John Deere will react. He's unsure how comprehensively the company can patch the flaws without implementing full disk encryption, an addition that would mean a significant system overhaul in new tractor designs and likely wouldn't be deployed in existing equipment. The first priority? Running custom farm-themed Doom on the tractor, of course. More Great WIRED Stories * The latest on tech, science, and more: Get our newsletters! * The big business of burying carbon * Laptops are still spying on students * Everything you should know about paxlovid * A glimpse of a future without white people * The rise and fall of a bitcoin mining sensation * [?] Explore AI like never before with our new database * [?] Want the best tools to get healthy? Check out our Gear team's picks for the best fitness trackers, running gear (including shoes and socks), and best headphones [Lily] Lily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate magazine and was the staff writer for Future Tense, a publication and project of Slate, the New America Foundation, and Arizona State University. Additionally... Read more Senior Writer * TopicsvulnerabilitieshackingDefCon More from WIRED Photo-illustration of handing appearing through hole to steal password asterisk icon Apple Just Killed the Password--for Real This Time Apple's iOS 16 and macOS Ventura will introduce passwordless login for apps and websites. It's only the beginning. Matt Burgess A handful of apartments in Lviv, Ukraine. Russian and Ukrainian cyberattacks have punctuated the war since Moscow's invasion began. The Worst Hacks and Breaches of 2022 So Far From cryptocurrency thefts to intrusions into telecom giants, state-backed attackers have had a field day in the year's first half. Lily Hay Newman Automated license plate reader cameras mounted on traffic pole above street The Danger of License Plate Readers in Post-Roe America Known as ALPRs, this surveillance tech is pervasive across the US--and could soon be used by police and anti-abortion groups alike. Thor Benson Fingerprint shown through infrared camera in orange and yellow light A Sinister Way to Beat Multifactor Authentication Is on the Rise Lapsus$ and the group behind the SolarWinds hack have utilized prompt bombing to defeat weaker MFA protections in recent months. Dan Goodin, Ars Technica Image may contain: An all seeing eye overlooking car manufacturing Is Your New Car a Threat to National Security? Putting sensor-packed Chinese cars on Western roads could be a privacy issue. Just ask Tesla. Justin Ling Concealed firearm tucked in waistband under person's jacket Gun Database Breach Leaks Details on Thousands of Owners Plus: Indian hacker-for-hire groups, Chinese student espionage efforts, and more. Matt Burgess Laptop sitting on desk in dark room and illuminating red light Russian 'Hacktivists' Are Causing Trouble Far Beyond Ukraine The pro-Russian group Killnet is targeting countries supporting Ukraine. It has declared "war" against 10 nations. Matt Burgess Copies of NFT art hanging on a wall NFTs Don't Work the Way You Might Think They Do We bust the biggest misconceptions about what "minting" actually means. Eric Ravenscraft WIRED WIRED is where tomorrow is realized. It is the essential source of information and ideas that make sense of a world in constant transformation. The WIRED conversation illuminates how technology is changing every aspect of our lives--from culture to business, science to design. The breakthroughs and innovations that we uncover lead to new ways of thinking, new connections, and new industries. * * * * * * More From WIRED * Subscribe * Newsletters * FAQ * Wired Staff * Press Center * Coupons * Editorial Standards Contact * Advertise * Contact Us * Customer Care * Jobs * RSS * Site Map * Accessibility Help * Conde Nast Store * Conde Nast Spotlight * Do Not Sell My Personal Info (c) 2022 Conde Nast. All rights reserved. Use of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Your California Privacy Rights. Wired may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices