Flaws in John Deere Systems Show Agriculture "We could literally do whatever the heck we wanted with anything we wanted on the John Deere Operations Center, period." Efforts to reach John Deere weren't immediately successful. But in a statement provided to The Security Ledger , the company denied in broad strokes the findings demonstrated by Sick Codes and downplayed the seriousness of the claims. “None of the claims - including those identified at Def Con - have enabled access to customer accounts, agronomic data, dealer accounts, or sensitive personal information," the company says. John Deere went on to say that “contrary to claims made at Def Con, none of the issues identified by the security researchers would have affected machines in use," according to The Security Ledger. Def Con presentations are vetted by security experts before acceptance. It's also common for companies and security researchers to be somewhat at odds over the potential impacts of flaws. Sick Codes tells Information Security Media Group that John Deere should "be honest" and turn the situation into a positive one. "Own up to it," he says. John Deere's tractors may not look terribly different than tractors from 40 years ago, but there is a big difference: Everything is computerized. Similar to modern vehicles, farm equipment runs highly complex, embedded and proprietary software that connects to the internet. John Deere's equipment constantly transmits check over here data to the cloud, such as information about when a farmer sits in a cab, moisture levels in the soil and gauges of the size of a harvest. Data has always been critical to farming, but it is being collected now with unprecedented scale for smart farming or precision agriculture. That allows farmers to reduce costs - by, for example, using less pesticide - and increase yields. But in March 2016, the FBI issued a warning that the agricultural sector's increasing dependence on technology increased the potential for cyberattacks. "Farmers need to be aware of and understand the associated cyber risks to their data, including digital management tool and application developers and cloud service providers, and develop adequate cybersecurity and breach response plans," the FBI said at the time. Sick Codes' interest in the company started earlier this year after a colleague pointed out there were no CVEs for any John Deere products, an odd finding considering how the company has moved into technologies such as cloud computing. There's been some tension between Sick Codes and John Deere. After the research started earlier this year, Sick Codes tried to report security vulnerabilities to John Deere, but he says he received no response at first. Sick Codes shared the information with ICS CERT, which is part of the U.S.


Walter Schifflett, and he was trying to sell the other items for him.  When asked for his boss’ phone number, however, Johnson could not provide one. Mr. Johnson did advise Officer Meador he was out on probation for theft and burglary charges in Kentucky. He also stated that he did not know anyone named Brandon Pulley.  At that time, Deputy Meador looked in the driver’s side window of the truck and observed two magnetic signs that read ‘Shifflett Mobile Homes.’ The sign did have a phone number on it. The Rusellville Kentucky Police Department was contacted to see if they could get in touch with the business owner after several unsuccessful attempts by Officer Meador. After it was determined a crime had taken place, all three subjects were detained. A short time later, dispatch advised Officer Meador that Mr. Shifflett had been contacted and had confirmed his truck, trailer and Bobcat steerer were missing. He advised the officer that Mr. Johnson and Mr. Pulley had previously worked for him and were fired for stealing. He also advised he was making a report on the stolen items with the Logan County Sheriff’s Office.  Shifflett told the officer he had recently purchased around $20,000 in Dewalt tools and placed them in the truck. Officer Meador had already observed several Dewalt tools in the back of the Suburban that Shumake and Andes were in.  After confirming the items as stolen, all three suspects were arrested and transported to the Macon County Jail. During the booking process, two baggies containing a crystalized substance were found on Mr. Johnson’s person.  Mr. Pulley was later found at the Lafayette Walmart and was placed under arrest and brought to the Macon County jail.  The truck, trailer and Bobcat steerer and click here tools were released back to Mr. Shifflett.  Johnson was charged with Possession of Stolen Property over $200,000 and Possession of Methamphetamine. His bond was set at $40,000. Shumake, Andes and Pulley were charged with Possession of Stolen Property over $200,000. Their bonds were set at $30,000.

