EcoModder.com

EcoModder.com (https://ecomodder.com/forum/)
-   The Lounge (https://ecomodder.com/forum/lounge.html)
-   -   Security OOPS (https://ecomodder.com/forum/showthread.php/security-oops-31241.html)

Frank Lee 02-20-2015 11:00 AM

Security OOPS
 
A 14-year-old hacker caught the auto industry by surprise

I'll keep me old school keys and mechanical systems, thank you.

nemo 02-20-2015 11:38 AM

Maybe he should be designing the cars. Wonder if he can figure out how to shut my DRLs off.

euromodder 02-20-2015 01:30 PM

Quote:

Originally Posted by nemo (Post 468728)
Maybe he should be designing the cars. Wonder if he can figure out how to shut my DRLs off.

Separate DRLs or headlights used as such ?

It can be done using software - doesn't mean a regular dealership can / will do it though.
If they're mandatory on the car, don't expect them to do so ...

nemo 02-20-2015 01:47 PM

Quote:

Originally Posted by euromodder (Post 468749)
Separate DRLs or headlights used as such ?

It can be done using software - doesn't mean a regular dealership can / will do it though.
If they're mandatory on the car, don't expect them to do so ...



Headlights used as DRL's. Seems there is no easy option like a fuse or relay to be removed. They can be shut off manually but are on every time the car is restarted. I will keep investigating though.

gone-ot 02-20-2015 01:48 PM

...and everyone thought I was being PARANOID for no reason what-so-ever when I disconnected the OnStar crap in our Cruze (ha,ha)!

Fat Charlie 02-20-2015 01:58 PM

I found a thread at Focus Fanatics from a couple years ago where a user who works at a dealership says it's in the BCM and can be disabled at the dealership. Can be, but YMMV: I would have cheerfully paid my Subaru store to disable mine, but they refused. 10 minutes of Googling later I had the DRL module unplugged on my own.

darcane 02-20-2015 02:50 PM

It's one thing when DARPA does it. It's entirely another when Joe Sixpack's teenage kid can hack in.

I've never owned anything with a CAN bus. I'll keep it that way for the foreseeable future.

freebeard 02-20-2015 04:33 PM

CANbus isn't the problem, it's features like remote unlock/start and updating iTunes while the car is parked in the garage. A DB-9 serial interface would require breaking into the car.

Still driving a 1971 Superbeetle.

darcane 02-20-2015 06:47 PM

Quote:

Originally Posted by freebeard (Post 468772)
CANbus isn't the problem, it's features like remote unlock/start and updating iTunes while the car is parked in the garage. A DB-9 serial interface would require breaking into the car.

Still driving a 1971 Superbeetle.

Well, CAN bus is a significant part of the problem... When someone hacks into a car, it's the CAN bus that they are manipulating to make the car do various things.

This can be done over cell networks and Wi-Fi on cars that are equipped with it... but it can also be accessed through Bluetooth which is on most, if not all, cars that utilize a CAN bus. Granted, the range is less with Bluetooth, but there is still a lot that can be done.

EDIT: I had read a report explaining much of this and just found it again:
Comprehensive Experimental Analyses of Automotive Attack Surfaces
It covers methods for connecting to a car via Bluetooth in section 4.3

freebeard 02-20-2015 08:15 PM

Thanks. I had also read something that I had to go find again.

Success!

Car Hacker's Handbook by OpenGarages
Car Hacker's Handbook

I'll have to do a side-by-side comparison. The Handbook is oriented to doing penetration testing on your own vehicle (white hat stuff). It at v0.x at this point, lots of stubs.

I presume that the Electric Vehicle conversion I'm not making progress on will use CAN Bus. From watching EVTV I take it that rolling your own, you can have multiple CAN Buses; one for infotainment and another for the mission critical stuff.


All times are GMT -4. The time now is 02:00 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Content Relevant URLs by vBSEO 3.5.2
All content copyright EcoModder.com