This seems like a little bit of FUD. This isn't any different from hooking up a device to the brakes that receives a mobile signal and stops them from working mechanically.
I agree, it'd be nice to know how much easier it is (if at all) to mount an tie in a computer to their car. They do make a good point:
"But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow's cars, they see some serious areas for concern."
http://www.limitless.co.nz/ sells the cable + software for re-flashing a variety of ECU's. I think he makes the cables by hand (he also started offering a nifty GPS + flashing unit as well). It's impressive work. It's quite easy to play with (and also quite easy to physically damage your car if you don't know what you are doing).
Having physical access to the car would make it impossible to stop: It's relatively easy to replace the ECU in a vehicle, which would be essentially impossible to notice (in my cars case, it's tucked in behind the glove box). Then you could have much wider levels of control over the vehicle than an ECU would generally provide, by using your own custom hardware.
I find it highly unlikely that the ECU would be networked (so to speak) with the car entertainment system (wireless/internet etc).
Hopefully, the wireless and Internet-enabled systems will be completely isolated from the CAN-bus.
At first I hoped it would be air-gap isolated, but after I thought about it for a bit I realized that's not possible. In particular, one obvious application for the Internet is playing network MP3s to your car radio, which is also pretty intimately tied into the CAN-bus in modern designs. So while there may not be an "official" path from Internet->CAN-bus, it's one buffer overflow in the car radio away from working, probably. And what are the flerking odds that the car radio is implemented in anything other than (spit) C, which in the hands of embedded engineers who haven't had to think about security for decades pretty much guarantees buffer overflows will abound?
And of course if we're going to implement remote condition monitoring in the style of OnStar, there may very well be direct Internet<->CAN-bus interconnects built right in.
I'm sort of regretting having taken the time out to think about this. Now I'm scared.
Speaking from a little bit of experience in this area...these networks are often not isolated. It depends on the vehicle and network architecture, but there are valid business reasons for getting at the entire network through Wi-Fi.
Buffer exploits in C aren't the issue. The issue is cracking the weak encryption scheme, and figuring out the unpublished sequence of CAN bits to send that do things like lock/unlock doors or change the powertrain calibrations. OEMs try to hold this info close to the vest for obvious reasons, but there is a large subculture out there reverse engineering it.
This is exactly what the real problem is. Comments about cutting break cables being easier don't get this.
Many cars are not air-gapping these two networks and a failure in any of the components that bridge the two can lead to remote attacks of this type. I would not buy a car that has Internet-anything in it.
It depends on the car's ECU, and your technical skill-set. For a car like a Mitsubishi Evolution, there is a largish community re-flashing: http://forums.evolutionm.net/ecuflash-179/ is a nice place to learn and understand the craft.
I think if crash investigators lack the ability to dump the ECU rom and have it compared to an original, they are somewhat incompetent.
Sure, but only if they think of it. I doubt "hacked ECU" is at the top of the list when they start investigating causes.
On the other hand, I guess once they figure out you crashed without braking (no skid marks) but were still conscious when you did so (you've probably tried swerving to avoid an accident) they'll pretty quickly narrow it down to complete brake failure, which I guess has a much smaller list of possible causes, especially if the brakes look physically okay.
But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow's cars, they see some serious areas for concern.
Yes, it is a bit absurd to be concerned about somebody planting a laptop in your car then gaining control. They could just cut the brake lines without even having to get into the car. The point is that cars in the future will have wireless connections and be able to send diagnostic reports over this connection. That will create some level of connection between the vehicle's sensors and a network outside of the car. In fact, it's almost certain that some vehicle systems will be controlled by inputs from an external connection. Can you imagine every airbag in southern California simultaneously deploying?
The auto industry has never really had to consider this type of network security in their software. I think it's in everyone's best interest if they start thinking about it.
It's called OnStar: remote disable, and more, all at the click of a command key. I've been waiting to see news of a car-theft ring using OnStar to steal cars.
When I sit in my car I can also apply the brakes, turn the heater on / off, switch to maximum volume, open the windows, heck I can even drive it into a tree !!
All new cars have diagnostic ports using open protocols. http://www.obdii.com/ has some of the details. They use the CAN bus so it would be fairly easy to attach a small microcontroller with CAN support and an 802.11 or GSM module to give you remote access.
I'm not sure how well documented the control protocols are (stopping car, turning off brakes, etc.) but it is apparent from this article that they can be discovered.
The control protocols are not well documented at all, starting in 1996, all cars are required to have OBD ports.
The manufacturers don't want people to know the control protocols for various reasons (security, manufacturers make money selling repair materials and codes to repair shops, licensing codes to third parties etc.)
But it is possible to discover the control protocols, a friend and I worked on it for his Toyota Yaris I think by monitoring all the outputs from the OBD and changing a status (locking a door) and watching what bits change. We got a lot of equipment and help from a professor at school. We used a GPS and ended up making a little app that monitored where the car went, its speed, and various car statuses on google maps. There's a lot of info out on the Toyota Prius if you feel like getting started.
Brakes are mechanical systems. Can anyone figure out how the computer could even begin to disable them? I guess one could imagine the ABS module could be used to cut out the brakes permanently instead of pulsing them. (Maybe this is another reason people should learn to brake properly instead of relying on dumbing-down systems... ;-)
I'm not sure. But I think that one thing worse than disabling them might be to wait until the car reaches freeway speed and suddenly apply full brakes to, say, the front left wheel.
Just about anything with ABS or traction control has a digital override of the drivers intent. That was the big fact people seemed to overlook during the Toyota-acceleration fiasco.
I wasn't nearly as concerned about the actual problem as I was about the computer deciding a brake instruction from the user should be ignored. Modified, certainly. But ignored?
I don't remember hearing this, mainstream media was so focused on floor mats and sticky accelerators and what not. Are you saying that while the car was accelerating the computer overrode the driver braking and failed to apply any brakes? Source?
I'd need to dig in order to find it, but it is, indeed, possible to make the brakes act MUCH different than the driver intended, once you have patched the ECU firmware. I'm not 100% certain you can completely shut off the brakes (as in, driver puts two feet on the pedal and it sinks to the floor without engaging any brake pads at all) however it may be possible to disable ABS or possibly to bias all braking to only the left wheels, for example.
I yield to no man in the gravity and intensity of my fanboyish appreciation of Stefan Savage, but... people have been hacking engine ECUs (for benefits) for decades. Meanwhile, if I want to kill someone, I'm just going to cut lines inside the car. You know, like they did in Hitchcock movies?
Cutting the brake lines leaves physical evidence of sabotage. Messing with the computers is a lot harder to spot. Do police even check for this sort of thing? Would they know how to?
You may not be up on the latest car designs, but attaching the ECU to the Internet is indeed a problem. Preemptive response: no a firewall is not the correct answer to this problem.
My carbureted 1970's chevy pickup is looking better and better /s
This is obviously a hit piece. The mechanical systems of a car are more hackable than the computer (bleeder valves anyone?). We might as well be concerned about people bending railroad tracks.
I'll agree at some point there will be a huge news generating security issue that will wake up manufacturers, but people are so paranoid about cars/computers that I doubt it will be a continuing problem.
33 comments
[ 6.0 ms ] story [ 94.1 ms ] thread"But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow's cars, they see some serious areas for concern."
Having physical access to the car would make it impossible to stop: It's relatively easy to replace the ECU in a vehicle, which would be essentially impossible to notice (in my cars case, it's tucked in behind the glove box). Then you could have much wider levels of control over the vehicle than an ECU would generally provide, by using your own custom hardware.
I find it highly unlikely that the ECU would be networked (so to speak) with the car entertainment system (wireless/internet etc).
At first I hoped it would be air-gap isolated, but after I thought about it for a bit I realized that's not possible. In particular, one obvious application for the Internet is playing network MP3s to your car radio, which is also pretty intimately tied into the CAN-bus in modern designs. So while there may not be an "official" path from Internet->CAN-bus, it's one buffer overflow in the car radio away from working, probably. And what are the flerking odds that the car radio is implemented in anything other than (spit) C, which in the hands of embedded engineers who haven't had to think about security for decades pretty much guarantees buffer overflows will abound?
And of course if we're going to implement remote condition monitoring in the style of OnStar, there may very well be direct Internet<->CAN-bus interconnects built right in.
I'm sort of regretting having taken the time out to think about this. Now I'm scared.
Buffer exploits in C aren't the issue. The issue is cracking the weak encryption scheme, and figuring out the unpublished sequence of CAN bits to send that do things like lock/unlock doors or change the powertrain calibrations. OEMs try to hold this info close to the vest for obvious reasons, but there is a large subculture out there reverse engineering it.
Many cars are not air-gapping these two networks and a failure in any of the components that bridge the two can lead to remote attacks of this type. I would not buy a car that has Internet-anything in it.
Still, it's a pretty difficult and high-failure-probability way of killing somebody.
I think if crash investigators lack the ability to dump the ECU rom and have it compared to an original, they are somewhat incompetent.
On the other hand, I guess once they figure out you crashed without braking (no skid marks) but were still conscious when you did so (you've probably tried swerving to avoid an accident) they'll pretty quickly narrow it down to complete brake failure, which I guess has a much smaller list of possible causes, especially if the brakes look physically okay.
If the objective is just to kill brakes/turn off the engine, there are easier techniques.
I remember reading about a $200 handheld EMP weapon that achieve this (can't find the link right now).
I think the technique in the article could control the car from any location via cell modem.
But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow's cars, they see some serious areas for concern.
Yes, it is a bit absurd to be concerned about somebody planting a laptop in your car then gaining control. They could just cut the brake lines without even having to get into the car. The point is that cars in the future will have wireless connections and be able to send diagnostic reports over this connection. That will create some level of connection between the vehicle's sensors and a network outside of the car. In fact, it's almost certain that some vehicle systems will be controlled by inputs from an external connection. Can you imagine every airbag in southern California simultaneously deploying?
The auto industry has never really had to consider this type of network security in their software. I think it's in everyone's best interest if they start thinking about it.
THAT would be an interesting test.
I'm not sure how well documented the control protocols are (stopping car, turning off brakes, etc.) but it is apparent from this article that they can be discovered.
The manufacturers don't want people to know the control protocols for various reasons (security, manufacturers make money selling repair materials and codes to repair shops, licensing codes to third parties etc.)
But it is possible to discover the control protocols, a friend and I worked on it for his Toyota Yaris I think by monitoring all the outputs from the OBD and changing a status (locking a door) and watching what bits change. We got a lot of equipment and help from a professor at school. We used a GPS and ended up making a little app that monitored where the car went, its speed, and various car statuses on google maps. There's a lot of info out on the Toyota Prius if you feel like getting started.
I wasn't nearly as concerned about the actual problem as I was about the computer deciding a brake instruction from the user should be ignored. Modified, certainly. But ignored?
It boggles the mind.
This is obviously a hit piece. The mechanical systems of a car are more hackable than the computer (bleeder valves anyone?). We might as well be concerned about people bending railroad tracks.
I'll agree at some point there will be a huge news generating security issue that will wake up manufacturers, but people are so paranoid about cars/computers that I doubt it will be a continuing problem.