3 ms·
It depends. If you hack the box, overwrite the CAN-ID (and therefore impersonating other devices in the car) by rewriting the boxes' CAN-Controller-Firmware you
by phelmig 13y ago
It depends. If you hack the box, overwrite the CAN-ID (and therefore impersonating other devices in the car) by rewriting the boxes' CAN-Controller-Firmware you can circumvent all ID based security. As long as CAN doesn't implement a private/public key auth it's possible to own the car by owning a box.
On the other hand one could try to separate the CAN-Controller from the box (entertainment system in this case) physically and only allow a serial connection to push/pull CAN messages. But from my understanding right now the entertainment system could overwrite the firmware of the CAN -Controller and inject malicious packages. AFAIR the the 30c3 talk pointed that out as well.
The different CAN busses are not (always) separated physically.
- hengheng 13y agoThe attacks you describe have not been demonstrated. A CAN-ID attack requires that you'd get access to the bus from a programmable device that isn't firewalled from the bus, which doesn't exist. Malicious packages are also filtered out. Packet filters are tested exhaustively (which is possible because CAN isn't too complex). There is a router between the busses, but that is tested exhaustively as well before production. (Again, relying on personal information by a VW engineer. I hope he had no reason to make up stuff.)