8 ms·
Toyota runs a car-hacking event to boost security (2024)
- LPisGood 1y agoThe CAN bus, the network interface vehicle components use to communicate was, at least as of a few years ago, the source of basically infinite vulnerabilities. Add in over the air updates or worse, updated bluetooth or radio firmware and you find things like stopping a vehicle remotely at highway speeds[1] [1] https://fractionalciso.com/the-groundbreaking-2015-jeep-hack-changed-automotive-cybersecurity/ https://fractionalciso.com/the-groundbreaking-2015-jeep-hack...
- AlotOfReading 1y agoThe people behind that stunt were immediately hired by GM.
- deleted 1y ago[deleted]
- burnt-resistor 1y agoIIRC, many TPMS systems run as CAN over IP, basically giving unsecured network access to a car if it thinks it's talking to a TPMS. Granted that some/most these sensors typically have to be "paired" with a car using a scantool (sometimes), but IIRC, some are self-pairing creating a vulnerability where the legit sensor could be replaced with a hostile one. Also the possibilities of spoofing, sniffing, and/or packet injection seem real too.
- privatelypublic 1y agoI know the receivers are often in a vulnerable position. But, on my 2008 era car- the code I've seen for SDR decoding is a broadcast MAC, pressure and a temp value.
- SV_BubbleTime 1y ago>IIRC, many TPMS systems run as CAN over IP, I’ve been in this industry for 20-some years not a single system I’ve ever seen operates like that. CAN over IP does not exist invehicles. IP over CAN doesn’t exist at all. UDS over IP does, but this is automotive Ethernet and an entirely different discussion.
- pipeline_peak 1y agoI love when companies openly embrace their security vulnerabilities rather than hide behind them, cough Kia
- monegator 1y agoA good starter would have been running the keyfob data on a different CAN line than the one going into the headlights... you know, the one you can reach with your hand from the outside. Then we could also talk about encryption, but at least making it a tad more difficult to have physical access. Not that toyota is the only one. If you ever notice a car that has a reinforced grill protecting the front RADAR, or the rear lights... now you know why.
- DecentShoes 1y agoThat's great, but the writing is still on the wall if Toyota doesn't get serious about electric cars. With their current trajectory Toyota is headed at 1000mph directly towards being the next Blackberry, Kodak, Nokia or Blockbuster. I say this as someone who owned a Prius for 10 years and loved it, and have also driven their hydrogen car. The BZ4X is badly named overpriced garbage, not enough and not good enough. The clock is ticking and they have to act yesterday to avert disaster and they're sitting their twiddling their thumbs. Currently Tesla is the iPhone to Toyota's Nokia and they're going to have to work very hard very soon to turn that around or their company will die.
- dzhiurgis 1y agoWhy make electric cars when you can bribe politicians to tax EVs and promote hybrids?
- cenamus 1y agoAre you talking about Toyota or every german automaker ;)
- nixass 1y agoOr even US government? (by removing incentives)
- bigstrat2003 1y agoRemoving incentives is not "taxing EVs", it's leveling the playing field. If EVs can't compete without the competition being tilted in their favor, they aren't up to scratch yet.
- dzhiurgis 1y agoIf EV costs more you pay more sales tax / gst / vat. Also most places now tax EV registration with extra fee or per mile so you add fair share towards roads making hybrid TCO lower.
- DrNosferatu 1y agoPwn2own?
- feraldidactic 1y agoHack-a-Toyotathon.
- 01HNNWZ0MV43FF 1y agoThe big security issue is that cars should not phone home, Toyota please patch
- BrandoElFollito 1y agoMy brother had his car (a sleek AUDI) stolen in front of his house. He left the key in the entry hall, and someone extended the range. Are current electronics (the consumer ones) good enough at scale to limit the time the round-trip car-key-car takes?
- addaon 1y agoUWB, used by CCC keys (iOS and Android; UWB might be optional for Android?) definitely is — TOF distance precision in the inches.
- octagons 1y agoFYI - the inclusion of UWB (specifically the FiRa consortium secure ranging standard) was not part of the CCC Digital Key specification until v4.0.0, which only left its draft state very recently, at least in terms of automotive security standards.
- hsbauauvhabzb 1y agoI think a fundamental problem is that keys aren’t security forward compatible - break the keys and you’ve broken an entire generation (or more) of cars. The only solutions I can see are software based keying and a mobile app or legally enforced security guarantees. But the car manufacturers don’t give a fuck if your 3 years and one day old car gets stolen. You move to the next competitor, only for the same to happen in just over three years time. Repeat. Repeat. Repeat.
- mlrtime 1y ago>The only solutions I can see are software based keying and a mobile app or legally enforced security guarantees. Wouldn't this require the phone to be trusted and not run unsigned software?
- BrandoElFollito 1y agoThe software part is a solved problem - this is how the web is secured. There would be an exchange of keys with the car, and done. This does not solve the problem of the timing (but the sibling comment explained that this one has a solution)
- sublimefire 1y agoCar companies would benefit from hiring thieves in the dark web. There were always toolkits on sale as well. So they could just investigate what is being done to steal the cars and patch it. I suppose a good bounty program would help as well as the tech savvy thieves would have a choice to get a bug bounty instead of ganging up with other criminals. Sort of divide and conquer.
- alephnerd 1y agoAutomotive Pentesting has been an industry for years [0][1][2] [0] - https://www.praetorian.com/services/automotive-penetration-testing/ https://www.praetorian.com/services/automotive-penetration-t... [1] - https://plaxidityx.com/ https://plaxidityx.com/ [2] - https://autocrypt.io/ https://autocrypt.io/
- Theodores 1y agoThe legacy automakers have been cramming ever more ECUs into their cars, at a considerable cost expense. Tesla did something different with the big screen and one 'big computer' rather than a bevvy of ECUs. This appears to be the design pattern going forward, as evidenced by VW's investment in Rivian, where they also go for the 'big computer' approach. It seems to me that the security of Tesla cars is pretty good, compared to that of the legacy automakers. You can't hotwire a Tesla. Securing one computer is relatively easy when compared to the challenge of securing a veritable forest of hardware, as made by numerous suppliers. Regarding the way that general attacks on car security systems happen, something has gone wrong with how all of it has been implemented. RFID works fine in many other applications, but they are doing it 'back to front' with automotive and it is just too easy to hack. I am not even sure it has been for features people really want. Remotely opening the car before you get in it has convenience value but we got in trouble with that.
- ocdtrekkie 1y agoYou can't hotwire a Tesla, but the manufacturer can, and can stop you from driving it too. I am not sure on the whole I prefer that option.
- lotsofpulp 1y agoAll the other new car seem like they are coming with integrated modems also, so I presume they have the same capability of stopping you from driving the car too.
- numpad0 1y agoWasn't Tesla basically a Toyota until recently? The big dash computer was just a car equivalent of Nest thermostat, at least when I looked at it, it could have been an Arduino with a key cylinder and the car would work fine.
- Buttons840 1y agoThere's 2 things when it comes to security: Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. Also, companies are not responsible (liable) for their own poor security. If they do something like leak the private data of half the nation--shrug--what can you do? How convenient for companies. It's literally a matter of national security; our national security is made worse by this status-quo, but at least companies aren't bothered by unwanted security researchers. We need to pick a lane. If companies want to be solely responsible for their own security, then they should also be solely reliable for any damages done by their own poor security. Or, we can recognize that security is really hard and make it a team effort and setup laws to protect security researchers, and then special "events" wouldn't be needed for security research; anyone could test the security systems at any time, and especially people would be able to test the security of devices they own.
- andrewmcwatters 1y ago> Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. Not a single sentence here is correct.
- bigfudge 1y agoI think you need to expand here. My understanding is that there is a lot of law you can fall foul of pen testing and sharing vulns on products of companies you don't work for.
- jfyi 1y agoIt's phrased weirdly, but the op is describing an idealized status quo as would be seen from a corporate standpoint. It was meant to contradict itself and thus: >We need to pick a lane. I imagine op would likely agree it isn't actually that monotoned and this was done for rhetorical purposes.
- chasd00 1y agoTangent but I have a 2016 Toyota 4Runner. Great car and fits my family and needs perfectly. The key fob broke so I needed to get a replacement, I got a blank and had a locksmith cut and program the blank. He must have not done it right because it worked and then I got stranded cause it must have lost its pair to the car or something. Nothing wrong with the vehicle, the engine wouldn’t start because of the key. I do road trips through the desert SW and other remote places, if I have the key I need the car to start no matter what. I really don’t want my keys to require a battery either. I wish there was a way to bypass the rfid/BLE or whatever it is.
- vigilans 1y agoDid you get a genuine key? I never had one fail on me. The immobilizer is the single best piece of technology for preventing car theft. If you create a backdoor for bypassing it, you'll end up like Hyundai/Kia which decided to sell cars without the immobilizer in recent years and which have turned into a joke in the minds of potential customers. It does not require a battery in most cases and is separate from the keeloq system that controls your car's doors.
- SV_BubbleTime 1y agoThe Stellantis systems I’ve worked on have a nice feature that there is a battery for the proximity use, that you can keep the key in your pocket and press the button to run the car, as long as the key is within the four or five proximity sensors you are fine. When that battery dies, you can press the directly to the start button and it uses a “receiver powered transmitter” RFID close proximity to start and run the vehicle. Most people don’t know this, so when that battery dies they panic and suffer.
- giobox 1y agoThis technique of pressing the dead key to the starter button works for quite a lot of brands, not just Stellantis vehicles. Always worth trying if you are in a "keyless" car with a dead key fob battery. In my experience virtually everything made in last 15 years will either support this RFID backup or have a spare physical key hidden inside the keyless fob. Lots of them will even let you press the dead key against some part of the exterior to unlock the doors too.
- OutputRiff 1y agoOr we could make Toyotas tunable like many other brands. I would love to tune my Tundra like I could tune my GTI. The mid 2010s after market super charged Tundras were so cool!
- sviruz 1y agoThe laptop in the second picture looks very nice. Thinkpad? Anyone knows what model this is?
- wslh 1y agoX1 Carbon? [1][2] [1] https://arstechnica.com/gadgets/2022/08/review-latest-lenovo-thinkpad-x1-carbon-is-a-good-performer-with-iffy-battery-life/ https://arstechnica.com/gadgets/2022/08/review-latest-lenovo... [2] https://www.synaptics.com/company/news/selene-lenovo-power-button https://www.synaptics.com/company/news/selene-lenovo-power-b...
- sviruz 1y agoThank you!