Page 2 of 3 [ 43 posts ]  Go to page Previous  1, 2, 3  Next

sliqua-jcooter
Veteran
Veteran

User avatar

Joined: 25 Jan 2010
Age: 39
Gender: Male
Posts: 1,488
Location: Burke, Virginia, USA

31 Jul 2014, 11:24 pm

Kurgan wrote:
You'll need to gain access to the car first.


Telematics systems have already been hacked, and the CAN bus isn't particularly secured from access outside the car.

Quote:
If you're thinking of CAN bus hacking, then this enables you to controll stuff like the radio, whether or not the servo works, and so on. It still won't allow you to remotely control the car directly without any modifications.


I have personally seen someone attach a bluetooth dongle to the can bus via OBD-II port and drive a car around a parking lot with an iPhone.

There's also known and published attack vectors in car telematics systems that have the potential to provide low-level access to both CAN busses.

Put them together and you have a very bad day.


_________________
Nothing posted here should be construed as the opinion or position of my company, or an official position of WrongPlanet in any way, unless specifically mentioned.


Kurgan
Veteran
Veteran

User avatar

Joined: 6 Apr 2012
Age: 37
Gender: Male
Posts: 4,132
Location: Scandinavia

01 Aug 2014, 11:00 am

sliqua-jcooter wrote:
Telematics systems have already been hacked, and the CAN bus isn't particularly secured from access outside the car.


You need physical access to hack it in the first place (it's not designed to be operated wirelessly). You can use something like this if you do have physical acces, though:

http://www.theregister.co.uk/2014/02/06 ... its_yours/

Quote:
I have personally seen someone attach a bluetooth dongle to the can bus via OBD-II port and drive a car around a parking lot with an iPhone.


This depends on the car (i.e. it's impossible without drive and brake by wire). In most cases, steering, brake hydraulics and so on are mostly mechanical, and can't be controlled via the CAN bus. Immobilizers, keyless go, and so on are a lot more secure than they were 10-15 years ago (Mercedes-Benz introduced the CAN bus in 1992, and Porsche introduced a similar, proprietary system in the late 1980s). The fuel injection (which is mostly non-programmable on road cars) on a modern car won't work unless it recognises the correct security token, which you can't copy from the keys just like that.

Quote:
There's also known and published attack vectors in car telematics systems that have the potential to provide low-level access to both CAN busses.


True. I've yet to see anyone gain full access to a car and remotely control it over a significant distance, though.


_________________
“He who controls the spice controls the universe.”


ruveyn
Veteran
Veteran

User avatar

Joined: 21 Sep 2008
Age: 89
Gender: Male
Posts: 31,502
Location: New Jersey

01 Aug 2014, 8:36 pm

Brainfre3ze_93 wrote:
Or does the idea of automatic cars aka " smart cars " terrified anyone? Just the thought of not being the one driving a car, and with technology becoming more and more integrated with the newest models. The thought of some complete stranger with the know how, could hack into the cars' engine, brakes, etc... virtually disabling the car entirely, and not being able to do anything about it. I know some people who are excited about what the future could hold for us, but I can't help but feel terrified.

It is not just cars, but technology in general and our ever increasing reliance on technology. What if a solar flare from the sun hit the Earth, or the satellites orbiting it? it could cause the satellites to become damaged leading to a power outage. Which could lead to some serious "potential " problems I ask this as a hypothetical question because we have not gotten that far, but it still bothers me. :?


As long as there is a positive over ride which gives control back to the human it should work just fine.

ruveyn



auntblabby
Veteran
Veteran

User avatar

Joined: 12 Feb 2010
Gender: Male
Posts: 115,281
Location: the island of defective toy santas

01 Aug 2014, 11:42 pm

it will eventually become a public utility, with a meter box and everything.



eric76
Veteran
Veteran

User avatar

Joined: 31 Aug 2012
Gender: Male
Posts: 10,660
Location: In the heart of the dust bowl

02 Aug 2014, 1:03 am

AspieUtah wrote:
I agree completely. While some drivers of motor vehicles are downright scary, they also have a degree of the human-survival instinct that forces most of us to brake, slow down and steer away from collisions thereby minimizing the damage done to all parties involved. I can't say that about self-driving compterized motor vehicles which would probably maintain its 45 MPH drive through a farmers' market simply because Google Maps doesn't know that the street is sometimes NOT a street when the market is open to pedestrians.


That should be no concern at all. A smart car would have to be able to recognize any and all slow moving obstacles as well as the proper path down a roadway. If someone were to step out in front of a smart car, it wouldn't surprise me if the smart car did a better job of avoiding hitting them than would your typical driver. I know one woman currently in the hospital (and will be there quite a while longer) because she was likely texting and ran into a truck pulling out from a driveway. I think the driver of the truck was probably texting as well.



eric76
Veteran
Veteran

User avatar

Joined: 31 Aug 2012
Gender: Male
Posts: 10,660
Location: In the heart of the dust bowl

02 Aug 2014, 1:05 am

Kurgan wrote:
[quote="sliqua-jcooter"
Chances are good that your car already has most of the following:

Power (aka computer controlled or computer controllable) steering ("hey look, my car can parallel park itself!")
Anti-lock brakes (controlled by computer)
Fuel Injection w/ computer controlled throttle
Power door locks, windows, and ignition (remote start, and remote stop).


This is mandatory on all new cars, and it's been like that in premium cars since the 70s and 80s (abeit not OBD-II or EOBD).[/quote]

Cites, please.

Why would power door locks be mandatory? Or fuel injection? Or power steering?



Kurgan
Veteran
Veteran

User avatar

Joined: 6 Apr 2012
Age: 37
Gender: Male
Posts: 4,132
Location: Scandinavia

02 Aug 2014, 7:22 am

eric76 wrote:
Kurgan wrote:
[quote="sliqua-jcooter"
Chances are good that your car already has most of the following:

Power (aka computer controlled or computer controllable) steering ("hey look, my car can parallel park itself!")
Anti-lock brakes (controlled by computer)
Fuel Injection w/ computer controlled throttle
Power door locks, windows, and ignition (remote start, and remote stop).


This is mandatory on all new cars, and it's been like that in premium cars since the 70s and 80s (abeit not OBD-II or EOBD).


Cites, please.

Why would power door locks be mandatory? Or fuel injection? Or power steering?[/quote]

The CAN bus and the OBD-II/EOBD standard is mandatory. I never said power locks or similar stuff were.


_________________
“He who controls the spice controls the universe.”


sliqua-jcooter
Veteran
Veteran

User avatar

Joined: 25 Jan 2010
Age: 39
Gender: Male
Posts: 1,488
Location: Burke, Virginia, USA

02 Aug 2014, 10:27 am

Power steering is mandatory because of dot safety standards

Fuel injection is mandatory because of emissions standards.

Power locks I don't think are mandatory by federal guidelines, but I'm willing to bet some state out there made them mandatory for some reason. Probably California.


_________________
Nothing posted here should be construed as the opinion or position of my company, or an official position of WrongPlanet in any way, unless specifically mentioned.


sliqua-jcooter
Veteran
Veteran

User avatar

Joined: 25 Jan 2010
Age: 39
Gender: Male
Posts: 1,488
Location: Burke, Virginia, USA

02 Aug 2014, 10:35 am

Kurgan wrote:
True. I've yet to see anyone gain full access to a car and remotely control it over a significant distance, though.


You missed my point again, I'm not trying to say that our current cars are wheeled death traps waiting for some hacker to kill us for the lulz.

My point is that all the pieces are there for someone to remotely take over your car, right now. It's possible with today's technology. It hasn't happened, mostly because it's really hard to do, but an "Advanced Persistent Threat" could absolutely get it done.

Having said all that, to the OPs major concern, it's not likely to be a thing that happens with any regularity. I'm significantly more concerned with car firmware being buggy (Toyota anyone?), than a malicious actor. And if you are still concerned by a malicious person taking control of your car, then you better go back to buying cars made before 1997.


_________________
Nothing posted here should be construed as the opinion or position of my company, or an official position of WrongPlanet in any way, unless specifically mentioned.


eric76
Veteran
Veteran

User avatar

Joined: 31 Aug 2012
Gender: Male
Posts: 10,660
Location: In the heart of the dust bowl

02 Aug 2014, 11:28 am

sliqua-jcooter wrote:
Power steering is mandatory because of dot safety standards

Fuel injection is mandatory because of emissions standards.

Power locks I don't think are mandatory by federal guidelines, but I'm willing to bet some state out there made them mandatory for some reason. Probably California.
How could power steering be necessary for safety? I've heard of people having accidents because of power steering but never because of not having it.

I've driven a number of vehicles including trucks that had no power steering at all and never had any problem.

Can you find any documents that state that power steering is required in modern automobiles?

Note that it is possible to still find cars without power steering in some small car lines. For example, the base models of the Kio Rio still have manual steering. Apparently some models of the Lotus Elite do not have power steering and the Opel Speedster in production from 2000 to 2005 had no power steering.

As for fuel injection, I can see that a modern manufacturer may find it necessary to use fuel injection to meet emissions standards and fuel milate requirements, but I don't think that they are mandated by law. Supposedly many smaller engines for motorcycles still use carbuerators.



Kurgan
Veteran
Veteran

User avatar

Joined: 6 Apr 2012
Age: 37
Gender: Male
Posts: 4,132
Location: Scandinavia

02 Aug 2014, 12:56 pm

sliqua-jcooter wrote:
My point is that all the pieces are there for someone to remotely take over your car, right now. It's possible with today's technology. It hasn't happened, mostly because it's really hard to do, but an "Advanced Persistent Threat" could absolutely get it done.


Only one car as we speak is available with steer by wire (Infinity Q50, which is a car that serves as a guinea pig for Nissan's technology)--and most manual transmisions and clutches are still purely mechanical (only BMW and Mercedes-Benz uses shift by wire on all models). Regardless, almost all drive by wire systems feature a manual override, in case of hackers or software malfunctioning.

Even with full access to the onboard computer(s), you still won't be able to control much of the driving itself of a modern car.

Quote:
Having said all that, to the OPs major concern, it's not likely to be a thing that happens with any regularity. I'm significantly more concerned with car firmware being buggy (Toyota anyone?), than a malicious actor. And if you are still concerned by a malicious person taking control of your car, then you better go back to buying cars made before 1997.


Actually, few (if any) cars in the 1990s featured any drive by wire systems, and only executive cars featured a CAN bus in 1997. Toyota introduced throttle and brake by wire in 2007, but there's still a lot that can't be operated by any onboard computer.

The firmware and the operating system of a car is typically no more than 2-3 megabytes, and it's simplicity and the fact that it doesn't use any third party drivers means that it's significantly more stable than anything on a personal computer or a cell phone.


_________________
“He who controls the spice controls the universe.”


eric76
Veteran
Veteran

User avatar

Joined: 31 Aug 2012
Gender: Male
Posts: 10,660
Location: In the heart of the dust bowl

02 Aug 2014, 2:16 pm

Kurgan wrote:
sliqua-jcooter wrote:
My point is that all the pieces are there for someone to remotely take over your car, right now. It's possible with today's technology. It hasn't happened, mostly because it's really hard to do, but an "Advanced Persistent Threat" could absolutely get it done.


Only one car as we speak is available with steer by wire (Infinity Q50, which is a car that serves as a guinea pig for Nissan's technology)--and most manual transmisions and clutches are still purely mechanical (only BMW and Mercedes-Benz uses shift by wire on all models). Regardless, almost all drive by wire systems feature a manual override, in case of hackers or software malfunctioning.

Even with full access to the onboard computer(s), you still won't be able to control much of the driving itself of a modern car.

Quote:
Having said all that, to the OPs major concern, it's not likely to be a thing that happens with any regularity. I'm significantly more concerned with car firmware being buggy (Toyota anyone?), than a malicious actor. And if you are still concerned by a malicious person taking control of your car, then you better go back to buying cars made before 1997.


Actually, few (if any) cars in the 1990s featured any drive by wire systems, and only executive cars featured a CAN bus in 1997. Toyota introduced throttle and brake by wire in 2007, but there's still a lot that can't be operated by any onboard computer.

The firmware and the operating system of a car is typically no more than 2-3 megabytes, and it's simplicity and the fact that it doesn't use any third party drivers means that it's significantly more stable than anything on a personal computer or a cell phone.


Perhaps you should read http://illmatics.com/car_hacking.pdf:
Quote:
Adventured in Automotive Networks and Control Units
By Dr. Charlie Miller & Chris Valasek

...

Executive summary

Previous research has shown that it is possible for an attacker to get remote code execution on the electronic control units (ECU) in automotive vehicles via various
interfaces such as the Bluetooth interface and the telematics unit. This paper aims to
expand on the ideas of what such an attacker could do to influence the behavior of the
vehicle after that type of attack. In particular, we demonstrate how on two different
vehicles that in some circumstances we are able to control the steering, braking,
acceleration and display. We also propose a mechanism to detect these kinds of
attacks. In this paper we release all technical information needed to reproduce and
understand the issues involved including source code and a description of necessary
hardware.



Kurgan
Veteran
Veteran

User avatar

Joined: 6 Apr 2012
Age: 37
Gender: Male
Posts: 4,132
Location: Scandinavia

02 Aug 2014, 2:35 pm

I have already read it. The article is about remote code execution and not taking full control of the car. The bluetooth device needs to be physically plugged into the car, something that you can't do without being detected. The cars mentioned in the article have both brake by wire and throttle by wire since 2010 (probably earlier for the Toyota Prius).

Quote:
Limited steering - Ford
Besides just replaying CAN packets, it is also possible to overload the CAN network,
causing a denial of service on the CAN bus. Without too much difficulty, you can make
it to where no CAN messages can be delivered. In this state, different ECUs act
differently. In the Ford, the PSCM ECU completely shuts down. This causes it to no
longer provide assistance when steering. The wheel becomes difficult to move and will
not move more than around 45% no matter how hard you try. This means a vehicle
attacked in this way can no longer make sharp turns but can only make gradual turns,
see Figure 19.


I never said that you can't hack a car, but that simply hacking it won't give you full control over it. In the case of both the Ford Escape and the Toyota Prius, the steering wheel is physically connected to the steering rack. In a steer-by-wire system (which is needed to properly turn a car remotely), the steering wheel serves no purpose beyond telling the computer how to turn the wheels.


_________________
“He who controls the spice controls the universe.”


eric76
Veteran
Veteran

User avatar

Joined: 31 Aug 2012
Gender: Male
Posts: 10,660
Location: In the heart of the dust bowl

02 Aug 2014, 3:52 pm

Kurgan wrote:
I have already read it. The article is about remote code execution and not taking full control of the car. The bluetooth device needs to be physically plugged into the car, something that you can't do without being detected.


An attacker wouldn't need to take full control in order to do immense damage like causing a wreck.

As far as plugging a wireless device into the car without being detected, if you inspect the car for wireless devices you should find it, but how many people do you think will check their car every time they get in to see if there are any wireless devices plugged in? I've never inspected my car to see if it has any strange wireless devices plugged in. Have you?



Kurgan
Veteran
Veteran

User avatar

Joined: 6 Apr 2012
Age: 37
Gender: Male
Posts: 4,132
Location: Scandinavia

02 Aug 2014, 5:14 pm

eric76 wrote:
Kurgan wrote:
I have already read it. The article is about remote code execution and not taking full control of the car. The bluetooth device needs to be physically plugged into the car, something that you can't do without being detected.


An attacker wouldn't need to take full control in order to do immense damage like causing a wreck.

As far as plugging a wireless device into the car without being detected, if you inspect the car for wireless devices you should find it, but how many people do you think will check their car every time they get in to see if there are any wireless devices plugged in? I've never inspected my car to see if it has any strange wireless devices plugged in. Have you?


The OBD-II port is typically located on or below the dashboard. It's fairly easy to detect a bluetooth device the size of a cell phone hanging from it, and it's obviously easy to see if anyone has broken into the car in the first place.

You can indeed cause damage by hacking a car, which is why there's usually a failsafe (after the you-know-what problem with the Prius pedals).


_________________
“He who controls the spice controls the universe.”


eric76
Veteran
Veteran

User avatar

Joined: 31 Aug 2012
Gender: Male
Posts: 10,660
Location: In the heart of the dust bowl

02 Aug 2014, 6:25 pm

Kurgan wrote:
it's obviously easy to see if anyone has broken into the car in the first place.


You'd better inform the police about that.

From http://arstechnica.com/security/2013/06/after-burglaries-mystery-car-unlocking-device-has-police-stumped/:
Quote:
It's February, about an hour after midnight, and three men in oversized clothing and hats walk silently down a deserted residential street in Long Beach, California. Each one goes up to a car in the area, takes out a small electronic device, and pulls on the passenger side car handle. The first man tries a car in the street. It doesn't open, and he walks on. The other two men try an Acura SUV and an Acura sedan in one home's driveway. Both of the cars unlock, their overhead lamps going on. The two men rummage through the cars, taking what they find. They shut the car doors and walk off.
I guess if they steal things from inside the car, it wouldn't be too difficult to detect that they broke in. But if they didn't steal anything?

Here's a description of a known approach to break into cars from http://www.mnn.com/green-tech/transportation/stories/computerized-cars-are-easy-prey-for-high-tech-thieves:
Quote:
A three-man gang would first scan the Internet for descriptions of Audis, BMWs or Range Rovers that had recently been exported from Britain to the former British Mediterranean colony of Cyprus, prosecutors told Southwark Crown Court in south London.

The gang's designated car thief would hang around commercial parking lots in London and the neighboring county of Essex, waiting for vehicles of the same make and model to pull in.

As the lawful driver left the targeted vehicle, the thief would use a jamming device to block the locking signal transmitted from the driver's remote keyless system.

The driver would think the car had locked itself ? presumably the lights would flash normally ? but the vehicle was in fact still unlocked.

The thief would hop into the car ? but he wouldn't steal it right away.

Instead, he used a computerized diagnostic tool, common among auto mechanics and easily available online, to plug into the car's computer and read and save the codes associated with its high-tech key.

The thief attached a secret GPS tracker to the vehicle ? and then locked it and left it where it was.

Back at the base, the gang's ringleader used the stolen security codes to clone a new key, used the downloaded details of the exported cars to create a stolen identity for the vehicle.

Then the gang would use the GPS device to track the targeted car around London until an opportune time came to steal it using the cloned key.
Do you think that the owners of these cars knew that someone had broken in and made their own key?