5 ms·
The response from the NHTSA highlights an interesting mismatch... > The NHTSA said a malicious actor "could utilize such open access to remotely command vehicl
by mfer 3y ago
The response from the NHTSA highlights an interesting mismatch...
> The NHTSA said a malicious actor "could utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently."
Yet, the Mass law is looking for...
> allow independent repair shops to access diagnostic data that newer cars can send directly to dealers and manufacturers to allow consumers to seek repairs outside dealerships.
It sounds like the same access to get data on the vehicles also allows control. For auto companies to comply with both laws could be possible but that it would require more fine grained access controls.
Or, am I missing something?
- cwmma 3y agoI'd guess that to get enough access to repair the vehicle you might have to be able to send certain commands to turn off alerts or update part information. Now that would probably only be a problem if the current set up for most car manufactures is a binary is dealer then be able to do anything setup.
- wongarsu 3y agoBut wouldn't that be trivially solved by only allowing such inputs via a physical interface (like say the physical OBD-II port) instead of Bluetooth or whatever they are using? Or if a physical socket is undesirable, at least a physical switch you have to use to allow such access?
- AnthonyMouse 3y agoYes. That's why everyone is calling it regulatory capture. Right now they have a system where automakers granted themselves a dangerous and unreasonable level of remote access to cars that aren't theirs. Now they're claiming that it would be dangerous and unreasonable for third parties to have that level of remote access to cars that aren't theirs. No kidding. But you could easily have a system where a remote access server has to be authorized by the owner, e.g. by having to press a button inside the car while the key is present. And could be revoked by the owner in the same way. Then the car could be repaired by anyone... who is inside the car and has the key. Which is not only completely reasonable, it's more reasonable than the thing they're doing now.
- nickff 3y agoThe buttons and keyswitch may be connected to the same CAN network which is the source of the vulnerability.
- AnthonyMouse 3y agoModern cars have electronic keys that can use cryptography. You can't forge a digital signature by hotwiring the car.
- thaeli 3y agoIsn't that pretty much what immobilizer bypass modules have done for years?
- AnthonyMouse 3y agoThose are for cars with physical keys. In cars where the key switch is only telling the computer "is key present: [y/n]" they put a message on the bus that answers yes and the car starts. But if you're going to use the need for security as a defense then you don't start by designing your car like that. Some car manufacturers have also attempted to use encryption and implemented it so poorly that it was easily cracked. There is no technical reason that a car key can't effectively be a yubikey. The computer issues a challenge to the key, answering the challenge requires a secret stored in the key, so you need the key. It works as long as the encryption isn't broken. And if "car can be remotely controlled" and the encryption is broken then that's a much bigger problem than anything your local mechanic is doing.
- neuralRiot 3y ago> The computer issues a challenge to the key, answering the challenge requires a secret stored in the key, so you need the key. This is how most modern “smart key” systems work.
- TylerE 3y agoThere are devices that plug into the obd2 and then allow remote access. I’ve heard of them being used by stalkers.
- deleted 3y ago[deleted]
- giantg2 3y agoIn my view, all they really need is to allow read-only data display through the OBD2, or via an authenticated web portal assuming the manufacturer has the data already. If you remove the wireless part of it (which the law doesn't say you mush access it wirelessly), then the remote operation is a non-issue. Really seems like a lot of fuss about stuff that has plenty of possible options. I might even call it FUD or a miscommunication it's so sloppy. Personally, I don't want a car sending data to anyone. I disconnected OnStar in the one vehicle that had it. Pretty simple to remove the bridge between the cell board and the rest of the electronics.