7 ms·
I would never ever want to be in a car which acceleration can be controlled remotely via Internet, even in theory.
by aleh 11y ago
I would never ever want to be in a car which acceleration can be controlled remotely via Internet, even in theory.
- quonn 11y agoThese are security issues, it's not by design. We will see more issues like this one and they _are_ bad, but this would be the least of my worries. There is no money in exploiting these bugs and even so-called script kiddies will probably not want to risk killing anyone. There are real risks, like buggy software in your ECUs wich can be deadly without any Internet connection.
- tomp 11y agoIt is by design, it must be. There is the acceleration module, then there is a wireless networking me dule, and there is a physical wire connecting them. Very shitty, very dangerous design.
- TeMPOraL 11y agoMore like, there is this acceleration module and there is this pedal that must hook into it, and there is this handy bus going through the car that you can connect the two systems to in order to make them talk with each other. And then you add a radio, and a knob under the steering wheel to control it, and think - hey, I have this handy bus I can reuse so that they talk with each other. And suddenly, your radio talks to your brakes. I don't think it's malicious design. More likely stupid one, or just a result of people being used to treating car hardware as trusted environment - where obsessing over security is just a waste of resources. It's just that when you introduce an Internet-connected device to that environment, it's not trusted anymore.
- tomp 11y agoI'd still argue that anyone who connects radio, travel computer or air condition systems (non-critical, not real time) with breaking, acceleration and external lightning systems (mission-critical, realtime, potentially lethal) is maliciously stupid.
- alienasa 11y agoIn almost all cars there are in fact two CAN buses - a high speed, low security bus that connects the radio to the entertainment system and so on, and a low-speed, high security (in terms of components, not actual security) but that connects the brakes to the ECU and so forth. The issue is that frequently systems like OnStar sit on both buses, because they are used for things like engine diagnostics. If you investigate you'll notice that every single one of these car hacking attacks starts somewhere, pivots to an OnStar like system, then can control the car. Doesn't really make your point less true, but fits perfectly in the features over security mindset.
- Too 11y agoTwo CAN buses is a quite low number. Last system i saw, which was pretty old, had at least half a dozen from what i could tell from my end of the system, probably even more internally inside or behind other components. Modern cars also use flexray, LIN, MOST and all other kinds of buses. The reason for this is safety, bandwidth and that the delay jitter on a highly loaded can bus can be relatively unpredictable for high frequency control requirements like suspension, traction and other engine related control.
- cjrp 11y agoAdd to that the fact that some cars, like a Mercedes C-Class I rented recently, allow you to change the 'agility' setting from the entertainment screen (changing throttle response, steering and suspension).
- Lawtonfogle 11y agoOr there is always the chance of management overriding building a separate system due to higher costs. The gains in safety did not justify the costs to them. Don't contribute to malice what could be explained by stupidity. Don't contribute to stupidity what could be explained by greed.
- andygates 11y agoThere is a common bus, and there are reasons for it existing, but the fault is with an internet-connected module being able to break out of its role. Fixing that is the traditional game of whac-a-mole that we have in IT every day, at least until a secure-by-design Bus 2 comes along.
- laumars 11y agoIt is partly by design since the ECU is physically connected to the infotainment system for diagnostics / user configuration. If ever there was an example of when systems should be airgapped, this should be one of them. ECU's have no business being integrated into infotainment systems. It's fine to have a physical wire that can be connected for diagnostics, but don't have then permanently connected by default. Just don't. edit: just read the article (doh for commenting before reading) and this attack is different from the previous ones. This one uses a feature that was built into the cars purposely for unlocking the vehicle and controlling the engine. That feature seems monumentally dumb from the outset - and very much implemented by design.
- MichaelApproved 11y ago> There is no money in exploiting these bugs - Murder for hire. - Killing political opponents. - Another country could use it to kill our leaders. I'm looking forward to self-driving cards but my only real fear is a bug being used to kill people in the manner I just described.
- laumars 11y agoYou're replying to the wrong post. That should have been to my parent commenter.
- MichaelApproved 11y agoYou're right. Thankfully, I had a quote to give some context to what I was trying to rebut. It'd be great if a mod could change the location of the reply.
- JoeAltmaier 11y agoOr this: http://www.xkcd.com/1559/ http://www.xkcd.com/1559/
- rwmj 11y agoOn the bright side, these cars can now be used as an open platform for developing open source driverless car software. You can even use the stereo to run the control software. (I'm only being slightly flippant)
- lolbertarian 11y agoThese exploits give the attacker the ability to inconvenience, harm or kill their intended victim with limited accountability. That's valuable.
- brandonwamboldt 11y agoThere is no money in swatting either, but yet it's becoming a growing problem for popular streamers (and police departments).
- TeMPOraL 11y ago> There is no money in exploiting these bugs There's such an obvious way to make money on them I'm surprised it isn't happening yet - if you have a zero-day for a car, just make a deal with your lawyer friend, that you'll crash some poor schmuck's car and your friend will help the victim sue car manufacturer for $shitton, which you'll split between the two of you.
- toyg 11y ago> There is no money in exploiting these bugs and even so-called script kiddies will probably not want to risk killing anyone. I'm sure plenty of international "agencies" would pay very good money to be able to exploit these bugs. Gotta take out somebody driving a GM car? No sweat!
- mtgx 11y agoWhat about the NSA, CIA, Russia, China or drug cartels. Do you think they will want to "risk" killing anyone like this?
- balabaster 11y agoThere may be no money in exploiting these bugs, but it's bugs like these that make a police state even closer to possible... if these bugs aren't found and squashed, they can and will be exploited by anyone who decides they need to coerce and control whatever they need to. One more tool for to be used against... whoever.
- fnordfnordfnord 11y agoIf this kind of exploit could be exploited en masse it could wreak huge economic havoc in addition to the life safety issues. Even if the attackers were warm and fuzzy types and they only took control of cars that were stationary. Forgetting about the safety problems for a moment it's kind of amusing to imagine thousands of logo-turtle-cars ambling around parking lots, clogging up traffic, making unprotected left-turns, etc.
- balabaster 11y agoHahaha @ Logo Turtle... that brought back memories long since suppressed/forgotten from back in primary school
- na85 11y agoYou don't think "Send bitcoin to this address or your daughter's car will suffer an unexpected malfunction" will be a thing?
- shultays 11y agoThe worst thing is, people can hack your car through your 'entertainment system' on your car. I don't even want to know how such a system exists, why my radio has access to brakes?
- JustSomeNobody 11y agoWhat I don't understand is why are there no regulations that require the control system to be completely separate. Maybe because even the Government didn't think anyone was so stupid?
- ams6110 11y agoRegulations generally arise retroactively, as a response to demonstrated bad behavior or information learned in accident investigations.
- JustSomeNobody 11y agoI get that. But how much forward thinking does it take? Back in the 80's or early 90's when "Drive by wire" was the buzzword and old timers were saying they'd never drive a car that didn't have physical linkages, how much forward thinking would it have taken for regulators to say controls system circuitry needs to be completely isolated from other systems in the car? Something like this would still apply today and maybe we wouldn't be seeing these issues.
- mseebach 11y ago> how much forward thinking would it have taken a lot. You can start by looking up if any of these old timers raised anything remotely similar to that concern. Remember how insanely unprotected the Internet was in the beginning? How SMTP basically still is? That was build by some of the smartest people in the world, and they didn't have the foresight to predict that there might be adversaries, and thus build (in retrospect, quite simple) protections in. Also, those old timers were wrong about drive by wire, there is zero evidence that it's any less safe than physical linkages. One of the reasons it would have been extremely difficult to predict, is that the phenomenon of consumer devices having a general purpose computer (and that this might be connected to the rest of the car), much less one networked in any sense, as its interface is pretty new. [edit: added analogy to the internet]
- baseballmerpeak 11y agoModern cars run on CANbus. Everything is linked. No, seriously, everything: steering (at low speeds, the park assist can be exploited), brakes, lights, radio, a/c. You'd have to go back at least ten years to find cars without it.
- lifeeth_ 11y agoLinked but not linked to the internet by default :)
- artmageddon 11y agoIt's true, and it's the whole basis for CAN networks. The whole car runs without a central computer, but rather, a set of microcontrollers for all of the different functions of the car. Every single microcontroller, more or less, broadcasts messages to all of the other ones along the bus. I'd say you'd probably have to go back even further than 10 years as the latest CAN spec, 2.0, was published in 1991.
- joezydeco 11y agoBut every microcontroller on the network doesn't have to listen to messages from the others. The real problem is that the designers of CANBUS never dreamed of a day when rogue nodes could show up on the network and start broadcasting messages they should not be broadcasting. Automotive embedded systems were closed loops and, aside from perhaps a diagnostic tool in the garage while parked, not susceptible to spoofing messages.
- tinco 11y agoI wouldn't even blame the designers of CAN-bus. The crazy thing is that GM/Chrysler allow media devices and general computers on the CAN-bus without a firewall. It's easy to say that the architecture is flawed, but that's no excuse at all. The CAN-bus allows control of the car, so non-control devices should not be allowed to send control messages on the CAN-bus. It's the same as blaming the insecure architecture of the internet when your password gets snooped, when you should have just used a secure tunnel.