7 ms·
Honda Civics and the Evil Valet
Previously: Show HN: Honda Civic Infotainment Reverse-Engineering - https://news.ycombinator.com/item?id=36052753 https://news.ycombinator.com/item?id=36052753 - May 2023 (43 comments)
- librick 4mo agoTo update 10th-gen Honda Civics, Honda ships updates on specially-formatted USB drives. They're essentially Android 4.2.2rc1-era recovery packages with some Honda-added version checks (which can be spoofed). The packages are signed with the publicly-known AOSP test key, so with physical access to the front USB port you can sign and flash your own package for arbitrary code execution on the headunit. This doesn't require root/su. I've run it end-to-end on my own 2021 Civic and separately confirmed an official EU update file carries the AOSP test-key signature. Tooling and writeup in the post.
- Alive-in-2025 4mo agoThanks so much for your analysis. This kind of investigation and exposure of lazy work is the reason I love hacker news.
- vel0city 4mo agoA number of other cars' infotainment systems are also based on ASOP. I remember downloading updates for my Hyundai which were also essentially Android images
- hparadiz 4mo agoThe head units themselves are very dated and simply could not run recent versions of Android. I have a 2020 and I'm always eyeing up the after market units which are all better in every way.
- Tribesman3875 4mo agoits not about them being dated, or fast. Its the fact that the head unit will work in 10 years vs the aftermarket one probably dying in 2.
- hparadiz 4mo agoI don't think I've ever seen a head unit die. After market or otherwise. It's usually all those pesky moving parts in the front that go first.
- Brian_K_White 4mo agobased on aosp was not the notable part
- DANmode 4mo ago> AOSP Android Open Source Project for those outside the bubble!
- agrijakhetarpal 4mo ago[flagged]
- arcanemachiner 4mo agoSphere of knowledge/awareness, i.e. non-Android-nerds
- brysonreece 4mo ago[flagged]
- inigyou 4mo agoBaby don't hurt me
- Kapura 4mo agobeautifully done.
- The_SamminAter 4mo agoHey, how did you obtain the update file? I’ve been trying to probe an Acura head unit from the same year, it’s also on Android 4.x, but have ran into a roadblock when it comes to obtaining an update file.
- DANmode 4mo agoEvilValet, sick
- rootsudo 4mo agoYeah jealous he even got to name an attack surface. Damn.
- t1234s 4mo agoCould you use this to get a version of lineage OS running on it?
- baby_souffle 4mo agoYes, but it'll still be using their kernel so not all functionality from lineage might work.
- runjake 4mo agoYou could, but if this unit is anything like it is in my CR-V, and its most likely the same, it's an ancient slow OMAP processor and 4GB of RAM (IIRC). Edit: Looks like a Tegra 3 in this one, but my bet is meager RAM.
- hankbond 4mo agoSeeing more and more projects eschew code docs with the idea that "well architected code can be queried by LLMs" and stick to more functional runbook style docs. It really is unlikely that at any given point all of the docs of a project are up to date with the code. I'm generally aligned with this, but it is predicated on the whole "well architected" code part.
- jmalicki 4mo agoI'd rather see unit tests as documentation. The test can show intended use, show interesting corner cases, and I know it is up to date because it is constantly running and passing. I think that is a huge underrated benefit of adding a lot more testing. If I think a developer is going to ask a question of how something works, or about a corner case, isn't that deserving of a test, so they can just see proof of the answer to their question immediately rather than trying to re-derive it?
- EPWN3D 4mo agoLLMs are great at writing unit tests.
- hankbond 4mo agoYou know what, you are right on the money with that. I think if you expand to include functional/smoke/e2e tests, that covers pretty much everything documentation is supposed to be. Just by running them you can measure if they are in or out of sync with the code (well, if they were written correctly).
- nucleardog 4mo agoI think unit tests are documentation in the same way that a Dockerfile is... it's not. The tests don't paint the bigger picture, explain why, etc. That said, if you pitched me something like a Jupyter notebook style doc where tests validating the claims of the documentation were inline, I'd totally buy into that.
- bri3d 4mo agoHyundai head units at one point used an RSA key you got by googling “RSA key” (no joke: https://programmingwithstyle.com/posts/howihackedmycar/ https://programmingwithstyle.com/posts/howihackedmycar/ ), an honestly even more amazing mistake since it required effort rather than just a default.
- deleted 4mo ago[deleted]
- Lammy 4mo agoThis is a good thing because it means I can sign something that will work if I own that hardware
- BobbyTables2 4mo agoI’ve heard product managers proudly proclaim their firmware was signed using the corporate internal signing service (good). Of course, the question explicitly being asked (related to internal mandate) was if the firmware was signed — not if the firmware update process actually checked the signature (it certainly did not).
- mschulkind 4mo agoI'm surprised someone named BobbyTables2 wouldn't go straight for the proper way to check email PGP signatures...
- Koffiepoeder 4mo agoI once came across a similar "solution". The signing algorithm was directly executed from the update package. How would we otherwise be able to update the signature algorithm? Worst part was that it was correct at some point. It was an introduced regression because of a signature change due to " post-quantum safe" signatures now being required by the security team.
- consp 4mo agoBy the time post quantum matters for things like firmware packages the thing they've build, even if done well, will have been broken anyway in some other form. But rules are rules, thy must obey and introduce more logical errors and bug in the process.
- hnav 4mo agoWonder how good the rest of the security is. The head unit is likely hooked up to a CAN gateway, can it call into telematics. Maybe find some novel way to abuse carplay/aa to call home.
- TheDong 4mo agoIf you have physical access to a car and want to phone home, may I recommend leaving a gps tracking device under the floormat. It works on more brands of cars too than just one gen of honda civics, and probably quicker to install.
- willis936 4mo agoAh but that is expensive and introduces risk of being caught doing clandestine. It is much more convenient to just use the one already installed and accepted. In fact, put away all this physical access nonsense and just buy it from the data broker.
- userbinator 4mo agoIMHO this is a good sign(!?) that they didn't even think about locking down their systems against the owner.
- varenc 4mo agoIt's not good that they allow anyone that happens to be in your car briefly root access. It'd be live having an always-on laptop in your office with a open shell on it. They should have provided some mechanism for the real owner to approve updates if the updates aren't all trusted by default.
- simulator5g 4mo agoWho cares? The valet could do any number of other attacks, like stealing the car, sabotage, adding a tracker, whatever. Threat modeling is important, otherwise security can harm one's own goals. Sometimes you have to briefly trust another person. I'd rather have an open shell inside a locked room when the alternative is no access at all.
- nandomrumber 4mo agoYou would notice if someone stole your car though.
- brookst 4mo agoHow do you validate “the real owner” if having the keys isn’t enough? That sufficient to steal the car. You could do a PIN/password, but if it is never used during operation, nobody will know it. Ask anyone who’s had a head unit that needed a PIN after losing power.
- varenc 4mo agoMere possession is also enough for someone to steal your laptop, but that still shouldn't allow them to trivially install a secret persistent backdoor, or break your disk encryption. Agree that a PIN/Password would have usability problems with a car. Since no car manufacturer intentionally permits you to install software you want, there's no standard mechanism. But if this was standard I think an owner-set PIN would be very reasonable.
- naturalmovement 4mo agoIf I'm reading the room, the sentiment is Honda is incompetent and their cars are security holes on wheels. But if the opposite happened, they would be technofascists locking us out of our own cars, a 30 post sub-thread "this is why I drive a 1999 Ford Ranger" would ensue, and someone would be investigating it as a possible GPL violation. Do I have this right? It's also a good assumption most people airing such complaints have never eaten in a restaurant fancy enough to have valet parking, let alone evil valets. That said, are evil valets known to tote around USB drives, or would they more likely use your navigation system to drive back to your empty house and clean it out while you're eating?
- TheDong 4mo agoI think the evil valet risk isn't real, but this could be part of a chain-of-attack in some scenarios, mainly rental cars. Like, sure, if you're just going to use it to spy on the user, you could also rent a rental car and leave a recording device under the floormat, or hidden behind the head unit, or whatever. But if you have an Apple Carplay exploit, where someone tethering their phone to the car can be compromised, renting a car and flashing a malicious OS to exploit the phones of people who come after you could maybe be a real attack. It's kinda hard to get people to otherwise connect to a malicious infotainment system with carplay, so if you have an exploit that requires that, this could be part of it... Except actually, no, if you have a carplay exploit, just rent the car, and rewire the USB port to go through a flipper zero or whatever and don't bother reflashing the car's software, that's just as easy. ... So yeah, I guess I agree with you, even in the rental car scenario, where this seems like it would be worst, your attacker might as well just hide something in the car instead of flashing the software.
- Nition 4mo agoYeah ultimately society really relies on the fact that most people aren't actively trying to be evil.
- naturalmovement 4mo agoHaving rented a car and seeing 80 variations of "Ben's iPhone" in the Bluetooth pairing list leads me to believe 99.99% of society isn't worried about this. Another thing to consider is Honda may have signed these packages with a wink and a nudge, because it may be required, regulatory or Android or otherwise, but they're also not interested in building closed devices. Instead of thanking them we're complaining.
- justaman123 4mo ago[dead]
- 1-6 4mo agoHonda knows how to build great cars but they haven't up-skilled their software knowledge.
- speedgoose 4mo agoThe Honda-e had one of the best aquarium simulation software, 90s style. It was sold from 2020 but still.
- dang 4mo agoPreviously: Show HN: Honda Civic Infotainment Reverse-Engineering - https://news.ycombinator.com/item?id=36052753 https://news.ycombinator.com/item?id=36052753 - May 2023 (43 comments)
- bigfatkitten 4mo agoMost (if not all) cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics. What makes this even worse is the sensors they have onboard these days; the microphones, cameras, GNSS receivers, wifi and BT radios make them into mobile surveillance platforms. In March 2026, a bunch of controls were added to the Australian Government Information Security Manual[0] basically instructing people to not connect government devices to the infotainment systems of any vehicles, or to view or discuss anything sensitive in the presence of one. > Security Control: 2099; Revision: 0; Updated: Mar-26; Marking: NC, OS, P, S, TS Mobile devices are not connected to the infotainment systems of connected vehicles. > Security Control: 2100; Revision: 0; Updated: Mar-26; Marking: NC, OS, P, S, TS Sensitive or classified data is not viewed on mobile devices within or near connected vehicles. > Security Control: 2101; Revision: 0; Updated: Mar-26; Marking: NC, OS, P, S, TS Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles. [0] https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism https://www.cyber.gov.au/business-government/asds-cyber-secu...
- shakna 4mo agoIsn't NC the absolute lowest in the sensitivity system?
- rswail 4mo agoThe point is that they want all government employees/politicians/contractors etc to understand the risks of on-vehicle electronics.
- bigfatkitten 4mo agoAnd they’ll still get very senior, and supposedly intelligent people saying “it’s just a car”.
- bigfatkitten 4mo agoIt means “not classified”.
- 4mo ago
- xandrius 4mo agoIn one thread people fighting the ever decreasing amount of hw ownership of most devices in our lives and when we have one that is more open, the crowds come to attack that too. The theat model with tech has always been that if an attacker has physical access to the device and time then it's game over.
- Aerolfos 4mo agoBecause it's not open for modification by the general public? (emphasis general, not just technically minded people) Manufacturers need to pick a lane - either fully open, and then people who need it can harden their own stuff (and at least be aware of the tradeoff), or fully closed and secure. This in-between where cars are invasive privacy nightmares that spy on you at all driving hours, and are insecure nightmares that will give up that data to anyone remotely invested, is the worst case scenario, obviously.
- tancop 4mo agothey can set it up to be secure by default and allow bootloader unlock like most android phones. if theres some form of owner authentication before you unlock evil maid attacks are impossible. you also need the ability to do a clean system reset and lock it again as many times as you want (no e-fuse, sorry samsung knox) so its safe to buy a used car even if the previous owner installed some spyware. all of that is tech that exists today.
- krater23 4mo agoHow could the owner authenticate? With the car key? How could you do a clean system reset after someone had access to all installed software/data including the cryptographic keys? The information is gone, maybe the recovery partition is changed. How could you securely recover?
- krater23 4mo agoOkay, what is fully open? Do you really think the head unit developer would hand you over a huge developer documentation about every bit in the software? I'm freelancer and helped to develop some head units. I have a surprize for you: This documentation mostly doesn't exsists. Most of the time there are some chip datasheets and requirement documents, depending on the customer(car manufacturer) they are good or bad and then are some partly outdated wiki pages written down for some important special things. You learn all other stuff out of the code or from your colleagues. Wait two years and the most knowledge is gone, except of the things that are used for the next head unit.
- deleted 4mo ago[deleted]
- hahamaster 4mo agoI wish other car makers were as reasonable as Honda here. No "evil valet" with half a brain cell would waste time hacking the head unit if they have physical access to the car. They would simply hide a spying device somewhere in the car. Not to mention that people with Civics are never targets of three letter agencies.
- saaaaaam 4mo agoNot sure if you’re being sarcastic/satirical or not. If you are, fine. But if you’re not - why would someone driving a civic not be a target of an intelligence agency? It’s one of the most common cars about there, so if you want to fade into the background it’s a perfect car. Also, lots of otherwise “normal” people - scientists, engineers, journalists, lawyers - likely drive Honda civics. A spying device hidden in the car may be found. Something installed directly within the car’s firmware is somewhat less likely to be found.
- drew870mitchell 4mo agoWhenever we get to talking about three letter agencies, i wish people spent more time thinking about their threat model. Is the TLA surveilling me because they're broadly interested in everybody? OK then, the return on investment isn't there to pull an evil maid attack on public randos. If the TLA is interested in you because of who you specifically are, the average individual can't begin to plug all the possible holes in their lives. As a Honda owner (but the kind the company probably doesn't really really love since i'm still driving a 2006) i actually think it's better for the long haul that their cars are hackable given physical possession.
- saaaaaam 4mo agoI wasn’t making any comment on whether cars should be hackable or not, simply that saying “people with Civics are never targets of three letter agencies” is a little silly.
- rangestransform 4mo agoEveryone should have security robust against nation-state actors by default in the most popular consumer products, so that people who need it can hide in the masses. I hope LLM-assisted “offensive security research” makes insecure software fully unusable so that companies finally take security seriously.
- greatgib 4mo agoThe framing of this article sucks. It is rather cool that you can hack your own car that easily. Framing it like "the evil valet" gives incentive and excuse to the manufacturer to lock down everything. While a real 3 letter agency evil valet will not car anyway. There is an endless list of things that it can do anyway, like put microphone in 100 places, change the electronic, get the key from the manufacturer, add man in the middle devices,...
- krater23 4mo agofull ack
- getpokedagain 4mo agoOn the other hand rom-ing your civic sounds easy
- lifeisstillgood 4mo ago>>> you could get stuck in a recovery loop and softbrick your device. Your car …
- veza 4mo agoThe irony in this is that it's hard to imagine a Civic owner going to a luxury hotel with a valet. Maybe a Type R owner with a stretch...
- morpheuskafka 4mo agoDowntown hotels often don’t have a choice, even if it’s just a Courtyard Inn etc. I har to park my 23 Civic LX at a hotel in DC before for work trip. It was like $80 a day plus tips but I could reimburse it all. Funny thing is the hotel itself was capped at $250ish.
- cowsandmilk 4mo agoI’ve had my civic coupe valeted at hotels and wasn’t doing staying anywhere special. Business trip where I drove the 100 miles to Baltimore and stayed at the hotel my company put me up in. Also, I’ve had medical appointments places where they valeted your car for free. I feel like having your car valeted was something special when I was a kid, but now it doesn’t really take something special.
- thedougd 4mo agoMechanics, car wash, anyone who can unlock the vehicle while it’s parked.
- 0x1d7 4mo agoType R is one of their most expensive vehicles after the typical dealer markup.
- krater23 4mo agoIt's difficult for car manufacturer theese days. You do proper security with secure boot etc. and the reverse engineering homebrew community complains about no way to install own software. You use the public known test key that everyone can do homebrew stuff when he wants, the reverse engineering homebrew community calls it a security risk. In my opinion this auther don't know what he wants.
- jgalt212 4mo agoI think Porsche (and related brands) also have this or a somewhat similar vulnerability. Owners use it to add Android Auto to a car that formerly only supported Apple Carplay.
- bri3d 4mo agoThat's VW AG "MIB" - a lot of these units had fixed per-infotainment-model root passwords and a shell service exposed over SSH or Telnet, so one could dump the flash memory directly from the board and crack the password hashes, then use some exposed network interface (on some, WiFi, on others, a USB Ethernet device would work) to get a shell. Eventually a better vulnerability was discovered where the signature validator didn't work properly: The vulnerability used there is explained here: https://github.com/jilleb/mib2-toolbox/issues/122 https://github.com/jilleb/mib2-toolbox/issues/122 . It's a "classic" mistake in signature validation (iirc the Windows software licensing service had a similar vuln at some point) but is a lot less trivial than this one; basically, the signature validator would stop validating once validation succeeded, so it was possible to take a valid update manifest and just tack more instructions onto the end of it and it would happily run them (the validation would return True, and then the command-runner would happily iterate through everything it got). There's also a vulnerability on the lower tier models that revolves around a logic error and a signed update which would copy unsigned files into a directory due to some issue with the path validation that I can't completely recall at this point, as used in https://github.com/olli991/mib-std2-pq-zr-toolbox https://github.com/olli991/mib-std2-pq-zr-toolbox . Anyway, these were a lot more exciting from a vuln research standpoint than this one (the MIB head units are also _fascinating_; they are not standard Tegra Android devices but a morass of rare and exotic DSP hardware driven by QNX and a giant enterprise IBM Java applicatoin).
- xgulfie 4mo agoRelying on users to use an LLM to generate their own docs presupposes that the users have a Claude subscription or whatever. That sucks imo
- swordlucky666 4mo ago[flagged]
- mrbuttons454 4mo agoThis is great information, thank you for posting! I think there is a line between security, and keeping a device useful in the long term. I think the threat of people installing listening malware on the car via an evil-maid type attack is low. However, when these cars are 10+ years old, and are in the hands of those willing to tinker, I think the ability to open up the software and customize will be a great thing. Hopefully communities form around creating modifications they find useful, and prolongs the life of the devices. Seems much better than the end-users ripping out the factory head unit to install the Aliexpress "Android Tablet" style units, which likely have much worse security and engineering than the Honda units they'd be replacing.
- Kapura 4mo agoMaybe turning cars into gigantic computers on wheels was a bad thing? more study required.
- drnick1 4mo agoOne more reason to remove the cellular modem from the car, so that even a compromised vehicle cannot exfiltrate information or be otherwise remotely controlled. This is something that every modern car owner should do immediately when taking possession of the car.
- iugtmkbdfil834 4mo agoI keep hoping that one of those hacks will eventually be available for Ford Lightning. There is a reason why Civics were a target for hacking ( relative low cost of failure ). But we go back to the old question of: Why do I have to rely on hacks ( like with cellphones, tvs and so on )? Why am can't it be ready for heavy customization ootb ( and before you tell me that people do dangerous stuff on the roads -- have you driven around lately )?