3 ms·
> What justification do you have for asserting that the safety critical systems are actually separated/isolated? I don't need to justify anything, I am stating
by DoingIsLearning 6y ago
> What justification do you have for asserting that the safety critical systems are actually separated/isolated?
I don't need to justify anything, I am stating they are isolated in all the vehicles I am familiar with. [0] The example from the Jeep Cherokee is a pretty crude architecture defect, the only way that could happen is in vehicles with a single CAN bus, which really is something out of the 1990's.
As constructive criticism you really ought to read the "In Comments" section of the guidelines at the bottom of the frontpage.
[0] https://www.st.com/en/applications/body-and-convenience/automotive-gateway.html#overview https://www.st.com/en/applications/body-and-convenience/auto...
- Veserv 6y agoYou state in a different comment chain that bus segregation does not mean no communication, so I do not understand how that is consistent with your claim that they are isolated. The Jeep Cherokee also did not have only a single CAN bus as evidenced by the diagram on page 8 [1]. The problem was that the radio unit was on both CAN buses. I ask for justification of your statement because you counter-argued the previous comment that stated: “It really should be illegal to have network connected cars. Any software security engineer knows that.” by stating that the safety critical systems are segregated and thus “the network bus in which your 'compromised' infotainment system is able to operate is completely separate from Engine, ABS, AEB, ESP, Airbags etc.” which implies that solution achieves the desired security properties. I claim the desired security properties are: “safe enough to bet the lives of 471,000 people on them and take responsibility if they were wrong”. I think, and I think most people would agree, that is accurate assessment of the potential consequences of catastrophic failure. That is a consequence comparable to the detonation of a nuclear warhead in a city, so we should apply similar standards to the required level of security. Hardly any software engineer would make a claim that their software can be trusted with an amount of lives within 3 orders of magnitude of that number (note 3 orders of magnitude is 471 which is comparable to an airplane crash, so 3 orders of magnitude less is critical avionics level). Therefore, making a claim that implies that level of security has already been achieved is an extraordinary claim and should thus require equally extraordinary evidence to be believed. Even with such justification I would still caution anybody else reading it since it would not be a legally binding claim by a liable entity, so even assuming you are commenting honestly and to the best of your knowledge (which I assume you are), and even correctly describing the truth as it is today, there are no consequences for any liable entity if they betray your trust. It should always be up to the liable entity to justify themselves to the people to our satisfaction before deploying systems with such societal-level consequences. [1] http://illmatics.com/Remote%20Car%20Hacking.pdf http://illmatics.com/Remote%20Car%20Hacking.pdf
- wwy43 6y agoThis is wrong. The Cherokee hack existed because both CAN buses in question travel to the infotainment system. The vulnerability came into being by finding a path between them. It became remotely exploitable when they found a way to do the same thing over the onboard cellular modem. So no, your definitive crude architecture defect and reference to the 1990s is a misunderstanding of the actual problem. This is a common FCA design. CAN HI and CAN LO often go to the same device on different pins. My Jeep has an instrumentation bus as well and all three arrive in one box in multiple places within the vehicle. Friend with a Rubicon Wrangler discovered both engine buses connect to the electric motor to disconnect the sway bar. He discovered this when water got in it, shorted it out, caught the electric motor on fire while he was watching, and subsequently totaled the ECU and TIPM by transmitting electrical noise on both CAN ECU buses. You’ve assumed one bus goes to one thing to reach your conclusion. That is faulty logic, which is no shortage of ironic given the parts of your comment I’m mostly ignoring in this reply.
- redfern314 6y agoSomething doesn't parse for me in your second paragraph - CAN HI and CAN LO are 2 parts of the same bus (each bus has 2 wires per the differential spec) and so of course they go to the same device on different pins. Am I missing something about the Jeep architecture?
- wwy43 6y agoThey’re two separate buses, high rate and low rate, for different purposes throughout the engine and components. Not the literal high and low pins of each bus. High rate, low rate. Think cylinder timing communication speed versus, say, fuel usage. CAN operates at a fixed speed, and I understand high and low rate buses to be a common design (they’re two CAN standards, high is something like a megabit). My code reader has fetched “CAN HI” before and the code was contextually referring to the high-rate bus, not the physical wire. I’m not a deep Jeep tech, just dangerous electrically and with a spanner, so I may be wrong in how I’m spelling those and I’m following the lead of a trouble code. If you’re nice to a service dealer with a laptop you can get a quite lovely wiring diagram that explains it better.