9 ms·
A Remote Attack on the Bosch Drivelog Connector Dongle
- Buge 9y agoI knew IOT devices generally have weak security, but I didn't anticipate them so easily being connected to physically dangerous objects like cars. I wonder how common this will become.
- alexei_kovelman 9y agoThis is actually more common than you'd think (and keep in mind that the Drivelog is relatively secure, even by non-IOT standards).
- lucaspiller 9y agoJust to clarify, the no-name Bluetooth OBD-II adapters a lot of people use come with a default PIN of 0000 or 1234 - that can't be changed - and the OBDII port is usually powered even with the vehicle switched off and locked. However, how much you can do really varies depending on the vehicle. I have a 2010 Prius and the OBD-II port is powered when locked and switched off, but the computer isn't active (so the port can't be used) unless the vehicle is switched on. Also the port itself is mainly read-only in my case, other than opening windows there isn't much I can do through it (I wanted to add remote-start, but it's not possible).
- avs733 9y agoJust to clarify...the ports ARE NOT read only. They are very much writeable. The devices you mention just give a readonly interface. The OBDII protocol itself is read only. OBDII requires a subset of parameters to be readable through an SAE (society of automotive engineers) developed protocol using the standard port. This occurs through reading of data that is regularly broadcast onto the CANBUS itself. In effect, OBDII runs on top of the CANBUS, with the connector in the cabin allowing access to OBDII via the CANBUS. However, the ports are much more capable and include direct connects to just about every system. CANBUS actually interconnects The CANBUS itself is typically a 'security through obscurity' approach where tuners are forced to reverse engineer CANBUS packets to access the networked exchange of information within the vehicle. In fact, 7 of the 16 pins in the connector are 'manufacturers discretion'. CANBUS gives access to it all, if you speak the language. OBDII is a 1pg sheet of translations. You can see the results of this through examples like that published in 2015 by Wired[0]. That was possible because the infotainment system and the engine, and transmission, and body control module, etc. are all connected to the same CANBUS...and information on the network is fully trusted once you know the language. [0]https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/ https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
- mtreis86 9y agohttps://hackaday.io/project/6288/logs https://hackaday.io/project/6288/logs Someone hacked VW Canbus to play video games on the dashboard of a polo.
- BoorishBears 9y agoI've owned cars where the ODBII port couldn't do (that) much more than the required subset of reads, and only a second port with access to the CAN network (that required disassembling part of the dash to access) was able to do things like what that link describes
- tyingq 9y ago>The OBDII protocol itself is read only I'd say "read mostly". Clearing the CEL with mode 4, for example, would cause your vehicle not to pass a state inspection until it went through a drive cycle...which can be quite a while. Mode 8 is more troublesome. It's not as standardized, so you have to know vehicle and model specifics. But you can actively manipulate real physical things in the car, canister vents opening/closing, etc. So, not as wild west as unconstrained CAN bus access, but not really read-only either.
- patcheudor 9y ago>So, not as wild west as unconstrained CAN bus access, but not really read-only either. I'd say mode eight makes it absolutely the wild west. In addition to clearing the CEL, I can use my CAN bus to program everything from the TPMS IDs for my wheels all the way to the pre-sets in my radio along with everything in-between including the amount of power steering and brake assist applied.
- tyingq 9y agoI'm not convinced all of those things are done via mode eight, but rather, by direct CAN bus access. I know, for example, some models of cars only expose a limited number of actuators over mode 8, mostly emissions stuff. Do you have a reference? In any case, "mode 8" is a subset of what unconstrained CAN bus access gives you. Edit: The best info I can find is in this whitepaper: http://www.autosec.org/pubs/cars-oakland2010.pdf http://www.autosec.org/pubs/cars-oakland2010.pdf You can see packet dumps on page 10. These aren't obd-ii packets. They are CAN bus "DeviceControl" packets. These are the ones they used to manipulate braking, etc. The context I'm trying to convey is that a dongle that exposes the OBD-II port wirelessly should probably expose only the "safe-ish" parts of OBD-II. No direct CAN bus access, no access to mode 8, mode 4, etc.
- yetihehe 9y agoMost of trucks in europe have gps systems which connect to CAN in order to measure driver efficiency and vehicle condition. They are also connected via cellphone network to internet (only sometimes through APN, mobile equivalent of VPN). All of them have security holes, typically much worse than this dongle, just no one cared to look at them yet.
- rahkiin 9y agoWouldnt it be possible to have the CAN chip only send data to the iot microprocessor? So not attaching the Tx but only Rx. As far as I understand CAN it is a bus everything is dropped on, without an actual request-response system. Now everything from the car could be read but nothing can be controlled.
- jasonkostempski 9y agoThis. One-way communication needs to make a comeback in a big way.
- paulmd 9y agoThis is fundamentally impossible in a CAN bus, and is stupid and functionality-limiting anyway. Everyone likes it when the radio turns off when the ignition does, these systems need to be able to talk to each other to get the functionality you expect. What you need is to move away from the non-authenticated bus paradigm entirely, to a network-based system where some devices may be assumed to be hostile (which is what you have, like it or not). This inherently involves authentication and privilege systems, so that the pedal controllers can prove to the brake controllers who they are, so that when the radio/head unit tries to interface with the brake controllers the brake controllers can go "woah, hey, you're not supposed to be touching the brakes". This at least would require escalation from a trivial system like the head unit to a more crucial system, which is a more typical model for exploits in computer OSs. This is a workable threat model. "Trust everyone all the time" is no longer, and hasn't been since we allowed external connectivity to automobile systems.
- 9y ago
- kylehotchkiss 9y agoI went out of my way to buy a vehicle with no GSM chip built in whatsoever (that's not easy in 2016). Car companies care as little about protecting their tech as they care about trying to fix USAs lovely car dealership system. I know this post is about a dongle, but you can remove a dongle from a car at least. You can't remove the GSM chip from most new cars that's uploading your location to heaven knows where and how many people have hacked their database this week.
- gumby 9y agoCan't you disconnect / destroy the antenna?
- microDude 9y agoActually, I was impressed how much security Bosch included in their device. For a IoT device I would give this a gold star. I am sure after this report was given to them, they patched their firmware.
- tyingq 9y agoI dunno...the dongle gives up it's certificate so that you can brute force it offline. It's an 8 digit numeric only pin. 100 million possible PINS, when you can do 100 million SHA-256 computations in 30 minutes on a typical laptop. That seems unwise. And it allows you to send and receive any CAN bus message you want, versus just some subset of OBDII. As far as I can tell, the features don't require anything other than querying OBDII for some very small subset of data. So if the dongle only passed those request packets, and dropped everything else, it would be miles more secure. Since it appears to be a simple passthrough device, I'm not sure there's enough horsepower in the dongle to fix that with firmware.
- azinman2 9y agoSeems to me that the main thing they could do that's cheap and easy is require a button press on the device to pair. Unfortunately that's not as simple as a firmware update.
- SwedishChemist 9y agoIs the Drivelog Connect even necessary? "Drivelog Connect allows your car to speak to you. Your car directly connects with your smartphone. All the information becomes available at your fingertips." Many of the features the app offers could be made available in the car's console/monitor. Like: - automotive diagnostics, display of real-time driving behavior(should you really be looking at your Smartphone while driving), Logbook for recording and storage routes... I don't really see benefit of this app.