3 ms·
Yea, this attack doesn't make any sense as a threat model worth defending. If the thief is willing and able to replace substantial amounts of the car's electro
by labcomputer 3y ago
Yea, this attack doesn't make any sense as a threat model worth defending. If the thief is willing and able to replace substantial amounts of the car's electronics:
1. They're already in the car. So how you authenticate the ECU and door modules to each other is really irrelevant. They bypassed that already.
2. They can just go ahead and replace the ECU and all the door modules with their own. So, again, how auth works doesn't matter.
3. At some point, you have to ask: Am I replacing the electronics in the car, or am I replacing swapping all the non-electrical parts from one car to another?