Now your car is a cybersecurity risk, too
eetimes.com
eetimes.com
There's the fundamental problem right there. Over the air software updates means malware can always be installed.
One day, security engineers may remember (or reinvent) critical technology from the 1970s. This was when, to write to the ROMs, there was a physical electrical switch called "write enable".
Now, if the car's embedded systems have a physical write-enable switch, then malware won't survive a reboot.
Next, have the system reboot every time the car is started.
The reason you hear about security flaws in newer cars with OTA updates is because research on unpatchable cars is regularly silenced. Multiple friends of mine who thought it would be fun to look into bluetooth security in cars have had their work shut down by law enforcement and teams of lawyers, and told to back off.
I'd estimate that at least 90% of cars on the road without OTA updates are vulnerable to some sort of Bluetooth based attack that will never get fixed. Your "write enable" trick does more harm than good in these scenarios.
Steering wheels made of cardboard would be easier to manufacture, yet they'd fail safety inspection.
If car makers are actually hooking the bluetooth chip up to anything except the sound system, that's the problem. Although, assuming a class 2 device, it only has a 10 meter range. If an attacker is that close and wants to shut down your car, they can use a nail strip.
The real problem here is hooking up WWAN to control software.
These connections could be physically 'one-way' but in practice most modules are simply wired in parallel on a CAN bus and something like the radio would be set up to send data to the car's CAN bus (for diagnostic purposes at least).
The stereo is way too tightly coupled with the rest of the vehicle.
Not to mention that updates can obviously brick things. Imagine waking up one day and finding out that your car is bricked due to some update.
But car owners are not given a choice, and most systems are then gradually engineered to depend on online access to function.
The conspiracy theorists might say "so they can slowly degrade the performance, in the name of environmental protection"...
I bought a Honda once that was never brought in for a service recall and thus had an issue I had to pay the dealer to fix because it was outside of the recall window.
Tesla was able to push an OTA update to the Model 3 to improve performance after a CR article criticizing it's braking distance.
I think OTA or remote updates should be possible, and I think it should be something the owner of the vehicle has control over.
https://mall.industry.siemens.com/mall/en/us/Catalog/Product...
The more secure means would be to require the car be taken to a dealership -- but that's costly to the auto maker (they have to pay the dealers for updates they apply), and is deemed an inconvenience to the customer. They worry about the friction on the customer, and the cost.
With OTA updates, much of the security relies on using signed images. The SoCs in IVI systems are fused with the auto maker's key.
Unfortunately, it's somewhat unfair to always blame the non-engineering folks. Many times is other engineering domains that run counter to good security. In my experience, cost or schedule are the leading factors but sometimes engineers want to push for certain features that are not compatible with good safety or security practices.
I kept pleading that we don't have the marketing that Tesla has, our customers don't want to think about updates. Not to mention OTA costs money. Tesla can do it because they are sinking money and only have a few hundred thousand cars. My company sells millions of cars per year, OTA is significantly more expensive.
I'm not saying my company does OTA often, but the word Tesla cones up more often than it should.
I've done several OTAs on a Tesla. Most were about 1 month apart, and my longest update took 28 minutes. The average is closer to 15.
> Tesla can do it because they are sinking money and only have a few hundred thousand cars.
I won't get into whether they are sinking money, but they have about 1.6 million cars.
How does it work? Is it automatic during the night when the car is parked and you're asleep (that would be ideal) or does it updates when you start the car and would be ready to go (that would be a nightmare)? Maybe something in between.
When an update is triggered (manually or on a timer) you get a 2-minute countdown to restart and then it will install.
Interesting. My Model X always estimates 25 but it's usually closer to an hour.
Also make sure I can use my older thumbdrives to "downgrade" to a previous version.
That would be perfect. Thanks.
The thing is, thumb drives cost money, and mailing things cost money. Mass hack attacks rely on not costing the attacker any money.
That is the problem and that is the reason why every OEM will support OTA in the near future.
I honestly don't know what I'm going to do in the future, there's no chance I'm ever going to buy a modern "car", it's going to get tougher and tougher to keep a real vehicle running after enough decades have passed. Of course a non-modern car is infinitely easier for the average individual person to maintain and keep running so I'll be able to keep going for a long time.
For the same reason you never get malware USB sticks in the mail to stick into your computer. It costs money.
I'd be curious on the HN perspective. Are we less willing to accept this from software because it's taken as a given that when "it's just software" changes are easy? Does it imply that the software process (particularly requirements and testing) are not as robust as with hardware processes, leading to more frequent updates? Does it imply we are overly reliant on software to mitigate hardware issues because "it's easier"? (I'm thinking, in part, of the 737-Max issue for the last one).
Unfortunately, "the lawsuits get filed" is comfortably beyond the planning horizon of any entity out there right now, even though we're talking about lawsuits with the reasonable chance of driving the affected companies right out of business.
An automobile is the last thing on Earth I want suddenly working differently on Tuesday than it did on Monday.
Actually, scratch that: a plane is the last thing. An automobile is the second to last (because I'm not an amputee with a prosthesis).
Tesla "we remote SSH'd into as many vehicles as we still could to patch up a crash/bootloop that existed because our on-board JSON handler couldn't handle a certain json blob coming from our backend" Tesla?
Tesla "we'll call you as soon as you connect anything to the onboard ethernet port to tell you to stop doing that" Tesla?
Tesla "it was demonstrably possible to 0-day your way to the Autopilot ECU" Tesla?
I'm sorry, my comment might come off as more hostile than I mean it to, but it seems you and I have radically different impressions of Tesla. Knowing their quality control process and build quality, I wouldn't even want to stick with the first version as released.
Although I do definitely agree with you on one thing. I think OTA is a very scary prospect for cars. And let me be clear: for any car manufacturer. From the type of software I've seen car manufacturers produce I'm not sure any of them should be capable of instantly updating their whole fleet.
Then again I also don't want touch screens in my car, so what do I know?
In any case, if it can't be built without GSM tracking, I won't be getting one.
Or maybe only the military version will have it.
I guess the military/police version will cost multiples of the civilian version too, if I were Musk I'd know I'd want to suck on that "virtually unlimited government budget" tit.
It's possible I could compromise on wi-fi or bluetooth, because those need to be paired to communicate. Hard no to cellular of any kind, if for no other reason than it means that the car's location is being continuously tracked and logged for all time by the carriers and national military.
I hate it for the fact alone that it enables location tracking via cellular connectivity as I assume that the SIM is connected all the time.
I'm willing to bet there are militaries and state intel agencies in the EU that have obtained brand new passenger cars that don't have transceivers in them. The module is also probably fairly easy to physically rip out, too, without disabling the whole vehicle, if creative methods with more finesse don't pan out.
Does nobody at all in governments see what an existential danger it is to a free society for anyone in that society to have access to a database containing the complete transportation logs of every single member of the society? I can't be the only person who sees this is an existential threat to a small-l liberal democracy; there are people alive in the EU today who suffered under the USSR and DDR.
I'd be worried even if it were a benevolent person with these logs; I'm positively terrified knowing it is the phone company and their pals in military intelligence.
Maybe. But does anybody in the governments think that the free society withering away is the danger to the government? Perhaps during the Cold War they thought so, but nowadays...
It's a legal requirement to have it. Sure, I can rip out the head-lights too, but then I am not allowed to use the car any longer on public roads. If emergency call is part of the cars registration I am probably not allowed to disable it without voiding the registration.
As well, no one does this. If you do it, you stand out like a sore thumb.
It's internal to the vehicle, so I doubt it would stand out visually. The ALPR stuff and mobile towers aren't (yet) integrated.
I can't do that for a GSM radio built into my car if my car has to be on to drive from A to B.
This was 15 years ago: https://en.wikipedia.org/wiki/Data_Retention_Directive
Sure, it eventually got struck down by the courts, but EU politicians still thought this was a terrific idea. And it's not like things have changed much since then.
(I was looking for my "smart" TV, I ended up disconnecting the wireless card from the TV. Thankfully the error message isn't as annoying as other models.)
There's no real standard for cellular antennas as there is for many other types of radios (as far as I know, not that I would / can find in some brief looking). Most stuff I'm familiar is 50ohm or 75ohm. E.g., wifi antennas are generally 50ohm. If you made me pick a resistor to put on there without being able to test anything first, I'd pick a 50ohm/5W. But you might burn your electronics up.
So your two main unknowns are the impedance and wattage.
Solving for wattage is probably best just done with Google. The power output should be fairly standardized. Assume the transmitter's going to go into its highest power mode when it realizes it can't find anyone to talk to and then leave yourself some headroom on top of that. On a very brief look, most sources put LTE at about a half a watt, but other techs at up to 3-4W. For the price of resistors and assuming these will end up mounted somewhere without great airflow, I'd probably just throw two 5W resistors at it.
Solving for impedance is going to be a bit more challenging. If you're lucky, an off-the-shelf antenna _may_ be marked with the frequency ranges and impedance. Otherwise, measuring impedance generally requires some more specialized tools. You could pick up something like the NanoVNA2 to do the measurements yourself (they're not the best, but likely close enough for what you're doing and cheap relative to the other options), or try getting in touch with your local ham radio group and ask if anyone has an antenna analyzer to analyze a cellular antenna (impedance is at a given frequency, so they need an analyzer that covers up to at least around the 1GHz range, which are less common than one for HF which is only covering up to a few dozen MHz) and could analyze an antenna for you.
Then just hop on Digikey/Mouser/etc, grab some resistors and a SMA or whatever other connector would plug in in place of the antenna and get to soldering.
Disclaimer: Amateur radio guy, not RF engineer. It's been years since I actually used any of this information in any significant way. This could all be entirely wrong.
Last time I asked it was 1500 quid plus install from the dealer. I could probably get under a grand now.
If there existed a car with no entertainment system at all, and I just stuck a specially adjusted tablet in there, with industry standard connectors, everyone would be happy, and if anyone hacked my entertainment system they would not be close to the important stuff
Cars should be the mobile equivalent of a dumb TV screen. But no-one wants to make them.
It's cartel behavior. Producers just silently agree to not do stuff that would disadvantage them on the long term.
Everybody keeps going on about "yeah, but someone will undercut them, free market, bla bla", but it never happens in practice.
Outside of HN, people do want smart features, from what I can tell, and don't even consider that their TV is a privacy concern.
I don’t know anyone who uses the smart features in their TV, except my wifes parents who use the Netflix app in their Sony TV. Everyone else just use an AppleTV, ChromeCast or a box from their cabel/internet provider.
Because the current generation of TV buyers are used to the concept of purchasing separate hardware to deliver content. That is changing now.
I had a similar realization about streaming v piracy. 15 years ago everybody my age was pirating music and TV. It led to a lot of viruses and malware for some, but everybody more or less knew where to go to for that stuff, even as P2P networks were being shut down left and right.
Today, young people don't really do that. Spotify, YT and Netflix apparently fixed enough UX and content gap issues that torrents and stuff aren't considered necessary anymore.
The same will happen with TVs.
From the wal-mart website, it looks like the 55" Sceptre is dumb but the 65" is smart. When I bought my 65" tv earlier this year, I couldn't find a dumb tv that fit all of the specs I wanted so I compromised and got a vizio (simple, chromecast based smart tv) and just never connected it to wifi. It doesn't seem to nag me about the smart features or connecting it to the internet at all
I asked about this a while back on HN. I’ve heard enough people complain about smart TV’s even outside of the sort of tech privacy bubble that I wondered why no one tried to take a dumb-TV angle or how difficult it might be to do so.
Was basically told, that consumer hardware is mostly a commodity business and that margins are super thin so it’s not really a profitable idea. So the companies turn to smart TVs where they can make up the cost by things like advertising.
FWIW in a later discussion elsewhere, I was pointed to a handful of Dumb-TVs being sold at Walmart, etc. I don’t recall whether you have options for high resolution or large sizes though. Commercial displays also get brought up in this discussion, but if my experience with other commercial hardware is any indication, general consumers may have a hard time getting their hands in those.
How old are your peers? My house in college was full of "DIY TVs" but once I got my own place I was tired of squinting at a 24" display
My TV is 65". That's not a monitor, and a monitor isn't a replacement for that size, and the closest monitor is the 40-something inch HP Omen which costs over four times what my TV cost.
So I'm not sure what you're talking about
Not everyone can afford to not care. You probably make a lot of money :-)
https://www.amazon.com/Samsung-Double-49-Inch-Monitor-LC49RG...
49", curved, $1100.
An average Smart TV:
https://www.amazon.com/SAMSUNG-55-Inch-Crystal-TU-8000-Built...
65", straight, $550.
So, yes.
I’ve done it on both my and my wife’s cars. They now have standalone CarPlay units for music and maps and calls, yet zero integration into the car itself and it’s perfect.
I wasn’t a fan of the JVC one we had previously though. Not very responsive and the lag made it annoying to use. The Pioneers are fast and pretty much perfect in comparison.
For most common cars you can also use the steering controls adapter kit which lets all your factory steering wheel controls for volume and answering/making calls.
Please no. I don't want a giant screen or touch screens in any car of mine. I like my knobs and buttons that provide tactile and position feedback.
I too want only knobs and buttons for controls, and I think it can be done well, unfortnately I'm not in that field though. Oh well.
I got my hands on a VW Up! in part because they decided to not bother with an entertainment system: you have a better one with your phone. So you get a USB port, a phone holder and an app if you really want useless crap.
I did that to my older car so it could have wireless car play for my spouses phone (but mainly because the native entertainment system was awful).
The "extra super base" trim models that they make half a dozen of so they can advertise a low "starting at" MSRP are often devoid of radio/infotainment.
Or have a function that the engine can't start if the switch is on (because during an update the engine should be off, although obviously the onboard computers need to be on).
This might have been the report that made them pay attention: https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
Which of the features which are a cause for concern aren't:
a) used inflate prices
b) used to gather/sell data to make more profit
c) to save costs ?
(I know some things like rear cameras are legally mandated in some places)
Some of the cost savings are directly impacting safety and it needs to stop. For example, hiding often-used things behind menus. It needs to be called out as the greed it is.
I want a car without all these. I don't mind OBDII but all the rest has no real reason to be there let alone be integrated with the car itself.
Of course one could always drive a historic car... ;)
So, I would argue that "feature cars" are amazing value right now. Even early 2000s or early 2010s are exceptionally reliable (unless you buy a 7-series E65 BMW or some nonsense) and cost almost nothing to run. Much more sensible than paying $80k for a new Tesla, even though it's clearly better and a shiny new toy.
There's a huge middle ground between a 10 year old civic and an 80k tesla.
But they drive so smooth...
I don't like modern electronics in cars but the safety features make buying a modern car compelling.
It's a learning curve but instead of spending money on in garage (and get ripped off) over the years I invested it in tools and try to repair anything myself. Sometimes I'm back on the road within 24 hours sometimes it takes me a month. Meanwhile I made friends driving similar cars who can help out. Not an option for everybody (space & patience), but I know my car now better than most mechanics. It turned me into a massive engine nerd too and I also got all the diagnostic tools to look at and clear error codes over the OBD-II.
If a large 4x4 isn't your cup of tee then a Lotus Elise can result in similar fun. My latest project is a Caterham which I'm building from scratch and hope to have it on the road later this summer (https://www.caterhamcars.com/it)
Anything battery powered or electric for me would never be an option. People say it's "not so green" but my opinion differs. I think getting the latest model of X every 2-3 years is far more toxic to the environment.
AFAIK the pedestrian safety rating for them is why older models (after the Ford/Puma engine) was abysmal and they discontinued. If you hit a pedestrian or cyclist that's probably it. That has always been my main worry. But I think the safety for the driver/passenger is pretty good when using common sense and when not driving them like the stig. I hit a wild pig once in a forest in France and it was splattered across the front but not so much as a dent in the car.
They also come with roll-over cages on the US market which tells something about what can go wrong if you lose control. Never got one since I don't drive rallys. Still their handling (directness of the steering) is much better than a Wrangler (where the steering is horribly "spongy").
The owners are a massively understated source of differences in performance and perception of both manufacturers and specific models.
On a newer car, I'd probably install a toggle switch for that wire. (I'd love to hear from anyone who's actually tried that.)
Edit: Also, I always open the door with the physical key, and I don't even carry the button.
Allowing car companies to update the cars themselves is going to be a recipe for disaster.
Increasingly _what_ cyberattacks? Frequent?
Tesla doesn't exist because Elon et al. went into his backyard and made a car, it exists because Elon et al. convinced a bunch of other people to cooperate on making a car.
Same with Jeff Bezos et al., and Amazon. Steve Jobs et al. and Apple. Bill Gates et al. and Microsoft.
Just posting on social media doesn't make your pen mighty, reaching out to people and convincing them to work on something does. On the other hand, social media is not a terrible place to "test" ideas to try and get an idea whether or not you'll be able to rally people to the task at hand.
Surely you meant to write "Martin and Marc", not "Elon".
but how do you explain the value add of a built once used and validated everywhere binary? and a standardized security architecture and frozen version maintenance? to yocto embedded folks?
Full image update is a better engineering practice, that's why it is done this way.
yocto only has half baked support for a binary layers, let alone binary sdk layers, where you add more packages, for the target or the build host, and more layers come further down.
this is for you to use the binary packages to build your images. which you then deploy, as you suggest.
key thing: you use suse/ubuntu/redhat binary packages to build and create your add-ons which you then deploy, as image-on-the-fly (created on target during traditional Linux install/update), or as precooked image (qemu, container or, new: embedded flash image)
This is just my preference personally, I would require a physical switch that powers down all transceivers. This will be a requirement for me on all modern cars for ODB3 regardless. I also want the ability to review all data that will be uploaded in JSON. If I can not review this data, I will violate terms/AUP/laws and upload my own image. Even non EV's have remote updates and telemetry with ODB3. This is more common on cars manufactured after 2018. For now I am sticking with used older vehicles.
Cars getting hacked when running around you won’t be a risk you can ignore. Your town’s critical services car systems getting compromised won’t be something you turn a blind eye to either.
As usual, apart from engaging in local committees there is little we can do from the outside, but we’ll definitely be the ones paying the price at the end.
Not sure where anyone mentioned anything to do with Tesla?
> All modern cars are very safe.
Well yeah that was my point - cars that aren't as modern aren't as safe. They increase crash standards at places like NCAP every few years.
I've been driving for almost 15 years, and never had an accident, but in that time there are many occasions where someone else on the road has done something _incredibly_ stupid. All it would have taken in any of those scenarios is for me to be opening a window/changing the radio station/looking in the rear view mirror and I'd have hit them.
Everyone thinks that they 'know how to drive'.
Even if you do, the point is other people may not know how to drive and may crash into you.
The crash event being pileup does not changes anything.
And while multi car crashes happen less often, they involve more cars, so if don't affect you chance to not get into one.
Do others? You are but one in the massive herd
Disclaimer: My daily is from 1981
Number of people killed on the roads every year due to normal crashes: 1,350,000
If you're optimising to reduce risk of the former at the significant expense of increasing risk of the latter... I think you're a fool.
Number of cars that should have complex, proprietary, hackable software: 0
It's a regress
How do you know this? The beauty of a cyber attack is that it can be made elusive. And the number of people killed on the roads by failing software is certainly not 0.
https://www.news.com.au/finance/business/media/wikileaks-vau...
I.e. if there's one vulnerable car every million 0 is what you'd expect deaths to be, not an astounding result.
But I understand the sentiment.
maybe we can crush the still totally usable cars, paint them white and use them as filler for the melted ice caps?
I recently discovered the motorcycle airbag monthly subscriptions. I kind of see it as sign.
Is that a thing besides Tesla?