I Hacked My Car Guides: Creating Custom Firmware
programmingwithstyle.com
programmingwithstyle.com
It turns out some fine Internet people have written C# (https://github.com/alexeyfadeev/erc-calculator) and Python (https://github.com/Berks/python_erc) packages to generate these codes. Was really cool to figure this out without having to pay some shady site in Bitcoins! The display is still in Japanese, but at least I can use Bluetooth and the rear camera! Hope that helps someone.
Some people are unlocking more maps in the navigation system by patching files which tell the infotainment application what options you purhased.
I would expect all controllers with safety critical functions are carefully firewalled so that you cannot do bad things via CAN.
https://github.com/commaai/openpilot/blob/master/selfdrive/c...
I don't know how powerful the chip in the car is but I can see someone building quite a competent open source navigation system through Qt and some car APIs, assuming you can get some kind of map storage solution working
The information you need isn't impossible to get: the manufactures make this available to third party scan tools, but they assume anyone wanting this information considers paying $100,000 a nominal cost and won't question it. In a previous job (I left in 2010) I had access to this information, but we still spent a lot of time reverse engineering things because the documents were too often wrong.
* DBC file is a proprietary format that describes the data over a CAN bus.: http://socialledge.com/sjsu/index.php/DBC_Format
* OpenDBC: democratize access to car decoder rings: https://github.com/commaai/opendbc
Depending on where you live, this might be illegal though.
I'd love to have a better insight into how exactly this happens. Not that it sounds like it would have been much of an issue even if properly generated keys and IVs were used.
At the other OEM's I have worked with, private key material lives on an HSM controlled by the OEM and all signing/encryption is done by the OEM for production builds.
If they are using example keys from NIST and private keys from published tutorials, then I would not be surprised if they are also using defaults for TLS - for example: allowing TLS 1.0, allowing TLS 1.1, allowing weak cipher suites, etc.
A random car from a 2nd hand car lot with a mystery custom firmware? Oh hellllllll no.
This only add value if you assume there are no bad actors. I'd bet $100 if this becomes common, 2nd hand car lots will sell access to install creepy tracking firmware on all cars that pass through their hands.
Just like any random car can have a $100 GPS tracker or spy microphone hidden which you won't locate without dismantling the entire car.
If someone wants to spy or be nefarious with a car I can think of many easier & cheaper ways than making custom firmware for the radio.
exfiltrates private information like contacts, SMS,etc..
sends premium rate SMS's/spam contacts
trackers
bitcoin miners
virus
adverts
etc...
They're great tools that are available for a tiny fraction of devices, usually only after jumping through hoops, thus failing to invalidate the claim
>> Not even most Android devices have facilitations for that.
(Emphasis mine)
Edit: my intention was there is no official way of doing it, and conveniently forgot to say so in my original comment. That was unfair on my side, sorry.
I don't speak about vendor's warranty, I'm speaking about road code.
As far as I know, many countries forbids meddling with breaks, lights, engine exhaust system and other systems related to road safety.
I understand, that infotaiment system is not the brakes, but still - many modern car allows to setup ABS and traction control modes via same interface, for example.
There are separate modules that do well-defined tasks and only a few of them would ever be relevant in an insurance/accident scenario (engine/transmission controller, power steering and maybe ABS).
What he's done here is equivalent to installing an aftermarket head unit, something people have been doing for decades. But even editing firmware (or rather the data tables in there - also called "maps") from more "spicy" controllers such as the engine management controller is routinely done by auto tuning shops and in practice the worst that happens is blowing up your engine by pushing it beyond its limits.
With that said, yes, if you happen to have a suitably common vehicle (e.g. Ford F150).
Zenec for example makes units that are able to display & control HVAC and parking radar on VAG Group (Volkswagen/Audi/Seat/Skoda) vehicles, pulling the data from the CAN bus.
In the authors case he’s reusing existing manufacturer-provided libraries that handle CAN message parsing but there’s no reason you couldn’t do it from scratch with enough effort.