7 ms·
Doesn't Tesla send over-the-air updates for critical systems to its cars? From my understanding, that means there is a way for a similar attack with a fake-firm
by netrus 11y ago
Doesn't Tesla send over-the-air updates for critical systems to its cars? From my understanding, that means there is a way for a similar attack with a fake-firmware. Am I wrong?
- vvanders 11y agoPretty sure Tesla signs their OTA updates.
- timdiggerm 11y agoNot that that's perfectly secure
- cwyers 11y agoYeah, it's only as secure as Tesla's ability to secure its private key.
- mikeash 11y agoAnd their ability to verify the signature on the car. Even if the private key is totally secure, you could either find a weakness in the signature verification, or find an exploit that lets you bypass it entirely.
- UnoriginalGuy 11y agoThat's an extremely rare vector for exploitation. I can think of one specific case where a vendor completely forgot to check the result of a signature check, but aside from that signature checking is well understood and rarely goes wrong. But to be honest people are taking their specification and dooms-day-ism to stupid extremes. Soon we'll be talking about "it is only as secure as the CPU, what if you find a CPU bug and bypass all security?!"
- ZoFreX 11y ago> signature checking is well understood and rarely goes wrong I would argue otherwise, plenty of signature schemes give you enough rope to hang yourself. The Playstation 3 example springs to mind!
- pigeons 11y agoSignature verification for android applications has been a tough one: http://www.saurik.com/id/19 http://www.saurik.com/id/19
- takeda 11y agoThere's plenty room for bugs in mechanism like that. For example Motorola Droid (back in 2010) was locked and only accepted signed updates. There was a bug where you could bypass it by using authentic update and appending your payload at the end of that file.
- thesteamboat 11y agoInteresting, can you point me to a news article or link? Shouldn't that have been rejected as an improperly signed file as (update+payload) should have a different signature than (update)? I'm want to know whether I'm misinterpreting something, misunderstanding something, or the signatures were misimplemented.
- kuschku 11y agoOnly the header was signed – that was the issue. It was made to save computational power on the device.
- takeda 11y agoThe original forum where it was posted doesn't exist anymore and there doesn't seem to be archived copy. Here's another page which is describing the steps: http://www.areacellphone.com/2009/12/motorola-droid-rooted-howto-root-droid/ http://www.areacellphone.com/2009/12/motorola-droid-rooted-h... Here is the commit with a bug fix: http://review.source.android.com/12807 http://review.source.android.com/12807 and actual diff: https://android-review.googlesource.com/#/c/12807/1/verifier.c https://android-review.googlesource.com/#/c/12807/1/verifier...
- tinco 11y agoYes, but I don't think skimmas is fully right. Updating firmware over the internet is not a terrible idea. Public key decryption is well established technology and simple enough for even big corporations to get right. Of course.. there's some room for them to screw up, but I would argue that that's set off by the risk of having buggy vehicle control firmware killing people. Especially with a new vehicle like the Tesla.
- higherpurpose 11y agoThere's also such thing as "key stealing". I imagine it would be quite a valuable target.
- UnoriginalGuy 11y agoWhen you're signing a binary blob, protecting the private key is actually pretty easy since it can be air-gapped/offline. Or heck you can buy appliances where they'll perform specific functions using the private key but won't expose it themselves without physical intervention.
- tinco 11y agoIf I were a mega-corporation protecting a firmware private key, your name would have to be Tom Cruise to get it. Though unfortunately responsible corporations seem to be as rare as real-life Tom Cruise characters, so I guess it's a valid concern you have.
- djrogers 11y agoThe ability to send OTA updates is a much better option than having to physically touch every single vehicle with a recall... I'd prefer it if my car didn't have any connection between a public network and it's control systems, but if it does I want it to be able to automatically install patches ;)
- higherpurpose 11y agoIndeed, and I remember the vast majority of the people getting super excited at the possibility of "getting an OTA update that can improve your acceleration by 0.1s" - without realizing what exactly that means in terms of security. In particular, that others could also control your engine and car the same way through updates. The car manufacturers who do OTA updates for their cars are sitting on time-bombs. The clock is ticking for them until people get killed this way (regardless of them using HTTPS or signed updates - which some manufacturers don't even use now).
- ohsnap 11y agoyet it's an order of magnitude easier to just go buy the parts to a real 'time bomb' than to crack an OTA update. Security is relative after all, and evil geniuses have much better ways to kill you.
- rasz_pl 11y agolike open(not unlock, open) doors while you drive? http://www.theregister.co.uk/2014/07/21/chinese_uni_students_pop_tesla_model_s/ http://www.theregister.co.uk/2014/07/21/chinese_uni_students...