3 ms·
Unfortunately, the article you cite is similar to OP's article. In this paper we intentionally and explicitly skirt the question of a “threat model.” Inst
by Finster 14y ago
Unfortunately, the article you cite is similar to OP's article.
In this paper we intentionally and explicitly skirt the question
of a “threat model.” Instead, we focus primarily on what an attacker
could do to a car if she was able to maliciously communicate on the
car’s internal network. That said, this does beg the question of how
she might be able to gain such access.
While we leave a full analysis of the modern automobile’s attack
surface to future research, we briefly describe here the two “kinds”
of vectors by which one might gain access to a car’s internal networks.
So, no, they didn't ACTUALLY dial a car's 3G modem. That is merely a theorized attack vector. There is no proof of concept here.
- tptacek 14y agoThe comparison here oversimplifies. Avionics engineers are on this thread saying there's no physical/logical connectivity between RF and flight control systems. But that's not true of cars; we know cars do have at least some RF controls, and we're far less certain of the connectivity between CAN devices in a car than the avionics people are of the connectivity between ACARS and flight control.
- gcr 14y agoNo, they really did demonstrate these vulnerabilities on real cars, it's not a theoretical analysis. Here's a link to their full research talk: http://www.youtube.com/watch?v=bHfOziIwXic http://www.youtube.com/watch?v=bHfOziIwXic I've been to both the UW and UCSD security labs and have seen their videos. It's real. This is ongoing work and honestly I cited the first article I could find.
- dguido 14y agoHere is a video of a similar attack being performed on a real car by another researcher who discovered the same vulnerabilities/attack vector in parallel to the academic team (1m30s): https://www.youtube.com/watch?v=bNDv00SGb6w https://www.youtube.com/watch?v=bNDv00SGb6w NOT theoretical.