3 ms·
I wonder if they are using key pinning and have mitigated SSLStrip and other SSL attacks. Also, they say that it wasn't vulnerable to attacks on braking and ste
by oomkiller 12y ago
I wonder if they are using key pinning and have mitigated SSLStrip and other SSL attacks. Also, they say that it wasn't vulnerable to attacks on braking and steering. If firmware updates are possible over the air, you could theoretically capture and disassemble one and modify it to suit your purposes.
The device the software runs on most likely sits on the CAN bus with everything else and could be used to feed false data in that could at least confuse other systems on the car. Similar attacks have been done before in experiments. Local (USB drive) system updates look to be cryptographically signed, but who knows about the OTA ones, and even then the key might be extractable.