4 ms·
> According to Tindell and Tabor's research, the attack, called CAN (controller area network) injection, works by sending fake messages that look as if they com
by dilippkumar 3y ago
> According to Tindell and Tabor's research, the attack, called CAN (controller area network) injection, works by sending fake messages that look as if they come from the car’s smart key receiver, the research continues. The underlying issue is that vehicles trust these messages without verifying them. Once the thieves have accessed the necessary cables by removing the headlights, they can use their device to send these messages, it adds.
I have to ask - does the automobile industry hire from a different pool of systems engineers than the usual pool I’m used to interacting with? It seems like everyone I know would say “obviously you should verify that the security mechanism first”.
Or is this a result of how the automobile industry is structured and what is outsourced to vendors/suppliers and what is done in house?
I’m not going to be buy that this isn’t solvable for a technical reason at this point. We have had a lot of experience dealing with PKI infrastructures and zero trust architectures in other parts of the industry.
- ahepp 3y agoIt seems to me that computer systems have always been a secondary concern on ICE cars. It’s possible the ECUs in question have been so cost optimized there’s not a lot of power left to do asymmetric (or possibly even symmetric, idk) crypto. Bus capacity is also a concern.
- HeyLaughingBoy 3y agoThe "problem" is really that the need for security became obvious in the web/networked world first. Think back to how insecure devices were 20 years ago. That security is slowly trickling down to other areas of the software industry. Even when you have individual engineers or teams who understand that it needs to be more secure, their procedures don't have that built in. And securing the car needs to be done at a system level, which means coordinating across suppliers & subcontractors, which requires management buy-in. Similar problem in the medical device industry, but at least we have FDA cybersecurity requirements to adhere to.