farmers around the world have turned to tractor hacking so they can bypass the digital locks manufacturers impose on their vehicles. Like insulin pump “looping” and iPhone jailbreaking, this allows farmers to modify and repair the expensive equipment that’s vital to their work the way they could with analog tractors. At the DefCon security conference in Las Vegas on Saturday, the hacker known as Sick Codes is presenting a new jailbreak for John Deere & Co tractors that allows him to take control of multiple models through their touchscreens.
The finding underscores the security implications of right-to-repair. The tractor exploitation Sick Codes uncovered isn’t a remote attack, but the vulnerabilities involved represent fundamental insecurity in the devices that could be exploited by malicious actors or potentially chained with other vulnerabilities. Securing the agriculture industry and food supply chain is crucial, as incidents like the 2021 JBS Meat ransomware attack have shown. At the same time, though, vulnerabilities like the ones Sick Codes found help farmers do what they need to do with their own equipment.
John Deere did not respond to WIRED’s request for comment about the research.
Sick Codes, an Australian who lives in Asia, presented at DefCon in 2021 about tractor application programming interface and operating system bugs. After he made his research public, tractor companies, including John Deere, started fixing some of the flaws. “The right-to-repair side was a little bit opposed to what I was trying to do,” he tells WIRED. “I heard from some farmers; one guy emailed me and was like ‘you’re fucking up all of our stuff!’ So I figured I would put my money where my mouth is and actually prove to farmers that they can root the devices.”
This year, Sick Codes says that while he is primarily concerned about world food security and the exposure that comes from vulnerable farming equipment, he also sees important value in letting farmers fully control their own equipment. “Liberate the tractors!” he says.
After years of controversy in the United States over right-to-repair, the movement seems to have reached a turning point. The White House issued an executive order last year that directed the Federal Trade Commission to increase enforcement efforts over practices like voiding warranties for outside repair. That combined with New York state passing its own right-to-repair law and creative activist pressure, which together generated unprecedented momentum for right-to-repair. Facing mounting pressure, John Deere announced in March that it would make more of its repair software available to equipment owners. The company also said at the time that it will release an “enhanced customer solution” next year so customers and mechanics can download and apply official software updates for Deere equipment themselves rather than having John Deere unilaterally apply the patches remotely or force farmers to bring products to authorized dealerships.
“Farmers prefer the older equipment simply because they want reliability, they don’t want stuff to go wrong at the most important part of the year when they have to pull stuff out of the ground,” Sick Codes says. “So that’s what we should all want, too. We want farmers to be able to repair their stuff for when things go wrong, and now that means being able to repair or make decisions about the software in their tractors.”