3 ms·
From a security point of view this could become interesting. Regarding how terrible (IT-)security is in CAN Systems a jailbreaked Radio could lead to major anno
by phelmig 13y ago
From a security point of view this could become interesting. Regarding how terrible (IT-)security is in CAN Systems a jailbreaked Radio could lead to major annoyances.
Good Talk on this topic: http://media.ccc.de/browse/congress/2013/30C3_-_5360_-_en_-_saal_2_-_201312281600_-_script_your_car_-_felix_tmbinc_domke.html http://media.ccc.de/browse/congress/2013/30C3_-_5360_-_en_-_...
- hengheng 13y agoI have to disagree with you here, specifically concerning the Script Your Car talk at 30C3. (In which the speaker had lots of experience in embedded linux security and no experience in car electronics, so he decided to hack the linux-driven hands-free set in his Volkswagen car. He was able to send messages via CAN bus that appeared on the info display on the dash board.) First of all, the linux PC was firewalled with a CAN transceiver that dropped any malformed messages to account for bugs in the linux box. Secondly, all other CAN devices on that bus are designed to withstand any erroneous messages. Thirdly, this was just the infotainment bus. There are three separated busses in the car, the first of which has ABS, ESP and the motor controller talking to each other, the second has semi-important things like window lifters and probably AC on it while the third and least important is the infotainment one. The linux box was allowed to be configured so badly precisely because it couldn't harm anybody. I sat next to a Volkswagen engineer in that talk, and he wasn't particularly impressed with what the guy on stage achieved on the car side of things, but rather with how much he was able to learn so quickly, and how easily he opened up that random Nokia box. Keep in mind he owned the box, not the car. Volkswagen tests all of these busses and devices exhaustively. They do have to pass TÜV certification, but more to the point they don't want any expensive bugs to happen. You can be sure that IT security is taken very seriously on that front. (Also consider that once you are inside the car, you by and large own it already, so discussing further CAN bus attacks would be derailing. The attack vector here is through a firewalled device on an unimportant bus.)
- phelmig 13y agoIt depends. If you hack the box, overwrite the CAN-ID (and therefore impersonating other devices in the car) by rewriting the boxes' CAN-Controller-Firmware you can circumvent all ID based security. As long as CAN doesn't implement a private/public key auth it's possible to own the car by owning a box. On the other hand one could try to separate the CAN-Controller from the box (entertainment system in this case) physically and only allow a serial connection to push/pull CAN messages. But from my understanding right now the entertainment system could overwrite the firmware of the CAN -Controller and inject malicious packages. AFAIR the the 30c3 talk pointed that out as well. The different CAN busses are not (always) separated physically.
- hengheng 13y agoThe attacks you describe have not been demonstrated. A CAN-ID attack requires that you'd get access to the bus from a programmable device that isn't firewalled from the bus, which doesn't exist. Malicious packages are also filtered out. Packet filters are tested exhaustively (which is possible because CAN isn't too complex). There is a router between the busses, but that is tested exhaustively as well before production. (Again, relying on personal information by a VW engineer. I hope he had no reason to make up stuff.)