The Crisis of Connected Cars: When Vulnerabilities Affect the CAN Standard
blog.trendmicro.com
blog.trendmicro.com
our attack can be enabled with any remotely exploitable
vulnerability that allows the attacker to reprogram the
firmware of an ECU (e.g., the infotainment system).
I will be honest, it seems very unprofessional if vehicle safety engineers have allowed complex, network-connected entertainment systems to have write access to the same CAN bus that the brakes and throttle are on.After all, if a hacker can remotely reprogram anything on that CAN bus, for sure they can remotely trigger a fatal crash.
They are joined with a proxy/firewall that provides separation and limits the functionality available between the two.
I'm guessing this attack would only work in this case if the attacker could physically access the OBD port to gain entry to the safety critical bus.
It is just like most computer vulnerabilities, the ones requiring physical access have in my opinion an almost null impact in practice (if such a physical access is made difficult or impossible), whilst anyhting "remote" is really preoccupying.
One of the suggested mitigations of putting the OBD-II connector inside a hardware locked case (presumably with a mechanic lock with key, IMHO safer than an electronic one with a password) goes in this direction, no physical access, less risk.
As long as we give owners the key. Reminds me of farmers who can't service their own tractors [1].
[1] https://www.theguardian.com/environment/2017/mar/06/nebraska...
If you have physical access to the CAN bus you can also make it inoperable by shorting the two wires together... not sure the takeaway is supposed to be with this.
Edit: typos
I suppose, though, manufacturers could at least focus on isolating the OBD-II port from most of the CAN bus, and putting the unfirewalled CAN bus connectors in a place that's harder to get to. There seems to be a lot of variation there now. Some cars isolate at least some functions, others have the OBD-II port completely connected to everything.
See this for example: https://www.autoblog.com/2015/01/21/2-million-progressive-sn...
OBD-II messages are a subset of CAN bus messages, identified by bits in the header, so it should be simple to filter/firewall down to just what's needed for that physical port.
Sure, I am upset that it's not more secure, as I am about the same thing with SCADA and (shudder) MODBUS, but I recognize where how the problems emerged: these busses are, by current standards, old.