4 ms·
How long before cars are zero-day susceptible to remote wireless hacks that can endanger lives of the passengers? I have seen conspiracy theories about acceler
by binarymax 13y ago
How long before cars are zero-day susceptible to remote wireless hacks that can endanger lives of the passengers?
I have seen conspiracy theories about acceleration and brakes being tampered with, but those allude to the tampering while the car was stationary.
When a vehicle has so much code in it, control systems are fly-by-wire, and there is bluetooth and wifi access, it is not a stretch to imagine a malicious entity driving on the highway and taking over nearby vehicles.
- adisbladis 13y agoI would guess the control systems and entertainment/navigation systems are separated for that very reason.
- dominicgs 13y agoThey probably are completely separate, but the use of wireless protocols is not necessarily confined to the entertainment system. For example, wireless tyre pressure/temperature sensors are installed in many cars and can be read with SDR hardware[1]. It's not too much of a leap to assume that false readings could be injected. [1] http://sandiego.toorcon.net/2013/10/07/dude-wheres-my-car-reversing-tire-pressure-monitors-with-an-sdr/ http://sandiego.toorcon.net/2013/10/07/dude-wheres-my-car-re...
- mcculley 13y agoThey are not that separated. Some modern cars have the entertainment system take note of the speed of the engine and adjust the volume accordingly. Some flip the infotainment display to a backup camera when the transmission is indicated to be in reverse. This is in addition to some cars adjusting the side mirrors when in reverse. I remember reading of an exploit that took advantage of the fact that the security system was on the same network in a particular car and thieves were able to crack off a side mirror and inject an "unlock" command. Does anybody have a reference for that?
- spatulon 13y agoThey are typically connected, but (kind of) sandboxed. A small ECU acts as a bridge between the infotainment system and the CAN bus.
- tobithiel 13y agoThese things not always work very reliably. A guy from a supplier once held a security talk at our university. They basically filter out unwanted messages, but the manufacturer often don't configure them very restrictive, but use black list approaches.
- __alexs 13y agoMinus many days? http://grahamcluley.com/2013/07/car-hacking-video/ http://grahamcluley.com/2013/07/car-hacking-video/
- scott_karana 13y agoYeah, when I saw OpenSSH in the list, that was my first impression too. I wonder how many backdoor authorized keys they have installed? :(