5 ms·
From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, i
by technofiend 3y ago
From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently."
Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the first place.
- RealityVoid 3y agoIt's an open secret in the industry that the CAN bus is not authenticated. If you connect, you can read the data on the bus and inject the data on bus. But, that does require physical access to the car and hooking to the wires. Nobody complains that if you hook to the buses on a PC you can own it. Now they have this security concept where every ECU on the car will have their own private key in their own secure enclave. You need that key to put authenticated data on bus and it can only be updated by the OEM's. The authenticated bus infra will probably not protect against remote attacks ( since if you own the ECU SW you have the cert and you will still be able to publish signed messages) but will kill ability to change HW. I really would not like to kill our ability to fix our vehicles but I feel this is the thing that is going to happen.
- harambae 3y ago> Now they have this security concept where every ECU on the car will have their own private key Not just a concept, on vehicles you buy today (from, for example, Ford and VW) https://cdn.vector.com/cms/content/products/VectorCAST/Events/Symposiums/4_Securing_Communications_-_Things_I_Wish_Someone_Had_Told_Me.pdf https://cdn.vector.com/cms/content/products/VectorCAST/Event...
- hooverd 3y agoI hate computers. Seems like lately they're only used to make our lives worse.
- gottorf 3y agoSince the Industrial Revolution, and only made worse with the Information Revolution, technology has advanced much quicker than the ability for laws and customs to adapt.
- bluGill 3y agoIt sometimes seems that way, but when you look at how people lived without computers things were worse. Cars in the 1930s were not fuel efficient, polluted a lot, and you have to do things like file the points every couple months. I remember when you called buildings not people - the phone was attached to the wall, and what just a voice device, it didn't hold Wikipedia or current maps to everywhere. However we forget how bad the past really want.
- JohnFen 3y ago> when you look at how people lived without computers things were worse In some ways. In other ways, things are worse now.
- bethly 3y agoI’m curious what maximization function you are considering
- hooverd 3y agoFor a fleeting moment they seemed like something about actually increase freedom, but now...
- mycall 3y agoThe devices on CAN bus can use embedded certificates to securely communicate with each other. Basically VPN over CAN.
- tkfu 3y agoIt's not about security by obscurity. A better analogy would be the fight over "tivoization". In safety-critical and highly-regulated systems like automotive and health care, there's a meaningful regulatory interest in ensuring that the devices as sold and authorized to be on the road (or in patients' hospital rooms) don't get modified in dangerous ways. That means that the software and firmware running on each of the dozens of ECUs in a vehicle is part of the (regulated) functional safety spec of the system. There are real, meaningful technical challenges to overcome if you want to meet both the goal of ensuring that dangerous and malicious software can't run in safety-critical domains, and the goal of allowing users to modify their vehicles as they see fit. I'm speaking as one of the authors of the Uptane standard for secure software updates in vehicles, and as a life-long proponent of user freedom and open access to the computers we buy. There are possible solutions here, but they are not easy.
- lifeisstillgood 3y agoCould you expand, or point to a good primer on the issues? I love "it's a complicated trade off" - it's way more interesting than whatever slogans end up defining "sides" in a debate
- bluGill 3y agoWhenever I dig into this I discover that what people complaining really want to do is modify their cars so it no longer meets emissions standards (you can get more power and/or better fuel mileage by doing this). Nobody is replacing ECUs with one of their own design that otherwise meets emissions. Sensors and parts are easy to replace (sometimes at high cost), and mostly radially available. The OEMs already tell mechanics what all the diagnostics codes mean. sure most of us reading this have the skills to write new code for their ECU, but realistically almost none of us would do that anyway unless we want to make a trade off that effects emissions.
- BenjiWiebe 3y agoOEMs only tell authorized mechanics what the codes mean. Most cars have the basic standardized OBD-II codes, and an additional much-more-useful set of codes/diagnostics that are proprietary.
- genter 3y ago> Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? Yes (I've reverse engineered the security system on an ABS controller for the top selling vehicle of a major auto manufacturer. It is atrocious. I'm pretty confident the whole reason it exists is so that they can claim they have one to use the DMCA to stop third party tools from interacting with it.)