Hacked Jeep USB update criticised
bbc.co.uk
bbc.co.uk
So? Never thought I would hear a "Security Expert" argue for, and not against security through obscurity. Perhaps this is not the best source for critique.
The more important concern is the phishing issue.
That would still be a problem if the updates were only distributed to repair shops, however (you'd need someone on the inside, but given the number of people involved, that probably wouldn't be too hard).
If they had done this right, they would have sent the USB with a validation step and widely advertised this step, so that all users would be aware of the need to do it, maybe even branding a simple software package to verify the contents as something like "UConnect SafeCheck".
Hopefully, they at least have a secure way to download it online (but given actions up to now, I'm not optimistic).
Edit: Owners can download it via https (albeit with SHA-1), but I'd be surprised if there's a way to validate the integrity of the downloaded file. Also, they're advertising that link without the SSL (and indeed, it allows non-SSL connections).
In other words, the USB key can't use stronger crypto than vehicle and that crypto is poorly implemented [again, based on my understanding of the original hack].
Wasn't sure if it was signed or if there was much security or not so I wasn't brave enough to change anything for fear of borking my car.
But I would have loved to figure out how to enable the nav system that's already built into my car but disabled (Jeep charges $XXXX for the privilege)
If hackers goes into hardware, maybe should we also start working on Scam letters filters?
You might want to stick with those years considering industries that have little knowledge or care about security are endangering your very life at highway speeds.
It's going to take them another half decade to care about these things and they will probably just solve it by lobbying politicians to waive liability instead.
Industries at the scale of the automobile industry are always making actuarial bets on fatality rates. Software or hardware or mechanical or digital is irrelevant, e.g. GM cheapening ignition switches without changing part numbers. Anyway, brakes have been digitally controlled for many many years. Avoiding that means no traction and stability control systems and the ordinary hazards [e.g. hydroplaning] that those mitigate are orders of magnitude more likely than my car getting hacked.