I hacked my car
programmingwithstyle.com
programmingwithstyle.com
https://datatracker.ietf.org/doc/draft-gutmann-testkeys/
From the point of view of m.d.s.policy the main idea is to require CAs to reject these keys in certificates for the Web PKI and encourage software to use these keys (rather than their own examples) in sample code. Basically when you build my-cool-website.example and copy paste the private key from an example into your certificate fetching code, the CA should say "Er, no, you need to actually choose your own private key, that's what the word private means" and this should happen when you copy-paste a high-rated Stack Overflow example, the provided sample code from the library you used etc. Ideally these would all be the same keys is the idea.
It would also make sense for tools to care about these example keys e.g. GitHub could flag code that's checked in and has keys which are not these examples since maybe you used real keys by mistake in your GitHub repo, meanwhile your build-for-production CI tools could reject keys which are on the list because that means you forgot to pick actual keys for the real build.
[0] https://www.reddit.com/r/cscareerquestions/comments/6ez8ag/a...
Then, secrets from production are hard to extract and typically rotated (semi-continuously). So it would be very strange if that somehow ended in up in a developers paste buffer to add to the docs.
I read the document hoping for an example Authorization: Bearer token auth, but was disappointed. Even more surprising was the lack of any ed25519 key; I would also have used this in my documentation.
Back in college our school had some limitations on the internal networks in our dorms. After doing my normal stuff (you know mega downloading,ftp, limewire etc) my net stopped working. Come to find out they had a bandwidth monitor and would just block you for some time if you used too much and had to contact tech support, even for simple things like window updates.
Anyways, somehow I found out I could tweak some net configs in the registry. So here I randomly change some dword value to change my Mac address. I finally got back online and just forgot about it.
A few days later I came back to my room after classes, my roommate told me the school officers raided the room trying to get on my PC. I went to the student dean's office and come to find out I took net access from I think the president and they tracked it to my PC ... Some luck I say lol .. Tech support said that there was no possible way I could change my Mac address after a bit back and forth I decided to just agree with him.
O yeah and they had like a 200-300 page printout of irc chatlogs ,there was more stuff but I'll end it there.
Needless to say my net access was blocked for a year even tho I had a work study job with the webdev department. It didn't stop me though, I ended up running a long cat5 cable from the dorm next door. Fun times.
It just depends on what the driver/hardware lets you do. Some drivers don't support changing it and some hardware/firmware may just be built in a way that doesn't make changing it (easily) possible. Not being able to change it may be more of a WiFi thing though. I've had the displeasure of dealing with one of those cards. Not sure if it was just the driver.
The Linux Kernel driver for Intel Ethernet supports changing the MAC address, so there's an example of what that may look like: https://elixir.bootlin.com/linux/v5.19/source/drivers/net/et...
That's already at the driver level though. There's a couple dozen other manufacturers with drivers in the Linux kernel, and their cards may work entirely differently.
If however your hardware allows you to have sufficiently low level access, your MAC address can be whatever you want it to be. After all, if your device says "this is my MAC address", then that is its MAC address as far as anyone talking to it is concerned.
If your card is a black box and is doing all the work internally (I think that'd be most cards?), then you're at the mercy of what it lets you do.
At the other end of the spectrum you'd have programmable NICs/"FGPA with an Ethernet port".
> This is an intuitive macOS status menu application written in Swift to help you spoof the MAC addresses of your Wi-Fi and Ethernet interfaces.
However, in the article they did not have control over the operating system. So how do you change the MAC address then? Well, you change the factory-configured MAC built into the device - which requires using the factory configuration tool!
In reality, the real rate-limit was my college budget and the price of hard drives, but it was all good fun.
Writing custom software looks like a really promising alternative though, especially if the vehicle's cellular connection can be used. Hell, if the IVI uses the CAN bus, perhaps there's a reverse-engineerable list of PIDs.
[0]: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
Anything that is not J1979 but purely manufacturer defined though, is a different story, and making that available is the main reason for the existance of the regulation.
(It is basically the same head unit, Kias/Hyundais share a lot of components.)
IMO Kia makes great cars but I don't trust them with Internet security. Android device permanently connected to the Internet with unfettered access to the CAN bus of my car....no thank you. And even if it was relatively secure today, I doubt it will get security updates for the 10+ years I expect to have the car, if at all.
I'm glad folks can now sign their own firmware to run on their own cars, but what else is vulnerable in these things?
The car is amazing otherwise, and I'm glad Kia does not seem to use the modem for any anti-features, so the car is totally fine with removing it.
As for people commenting about "nothing to hide" and paranoia, I guess that they never worked on the other side. Seeing how even very innocent-looking data can be (ab)used, I would definitely prefer less data to be gathered about everyone.
have they never heard of credit card fraud, identity theft, etc?
1: https://github.com/impfen/apps-inoeg/blob/main/tests/fixture...
There are many ways to do this, but one that often fits what I am doing is to use terraform’s TLS provider [0]. Terraform has become pretty ubiquitous for me. I am probably already using it to power other parts of my dev environment setup and teardown. Adding in a call to a little module that spits out a dynamic CA and certs signed by it is really easy.
[0] https://registry.terraform.io/providers/hashicorp/tls/latest...
https://snakeoil.cr.yp.to/submissions/Lolcipher%20Submission...
(To be fair I suspect the IVI isn't running unless power is turned on, which limits the number of real world threats, but it does potentially offer a new avenue for carjacking)
The big question, of course, is: Why haven't we had a security apocalypse? I imagine it must be because most software engineers are honest, and because the bad actors who have the skills and resources to pull it off (e.g., foreign government agencies) have a vested interest in maintaining the status quo.
So, non-technical managers everywhere go on with their lives thinking their software infrastructure has been "secured," without really knowing whether it's true. Consider that no executive or manager at Hyundai was aware until now that their vehicles have been using a previously published private key to update their software.
The most common ones I know of are:
* Out-of-bounds write issues allowing "signature was validated" flags to be overwritten in Flash memory, like https://github.com/jglim/UnsignedFlash
* State machine mistakes, like https://github.com/bri3d/VW_Flash/blob/master/docs/docs.md - allowing Flash to be written again after it was already written, without an erase first.
* File format parsing mistakes, like those in a number of VW AG head units: https://github.com/jilleb/mib2-toolbox/issues/122
* The use of RSA with E=3 and inadequate padding validation, like https://words.filippo.io/bleichenbacher-06-signature-forgery... .
* Failure to understand the system boundaries, like in the second part of https://github.com/bri3d/simos18_sboot where "secret" data can be recovered by halting the system during a checksum process.
* Hardware fault injection issues, as used in https://fahrplan.events.ccc.de/congress/2015/Fahrplan/system... .
Fundamentally this is of course, a very hard problem, since in the "protect against firmware modification" case, the attacker has physical access. But, compared to the state of the art in mobile devices and game consoles, automotive stuff is still way behind.
For those reasons, instead of trying to repack the software for the original ECU, I started to sniff the CAN traffic and analyzing the binaries contained in the software update packages found online. That allowed me to reimplement the communication with other ECUs on a Linux SBC.
Any company that believes its core business isn’t software will not pay for software developers.
They're incredibly hard to buy right now, I've been on the waiting list for months.
I'd heard they're almost impossible to get hold of. I'm actually in no rush so I was tempted to wait for the next iteration. I'm all about V2H/X and I'm hoping / wondering if the next version will have that fully enabled or not.
Anyway, take my comment as just a strong compliment for Hyundai. I'm so happy they're around as a strong alternative to the incumbant.
Good luck getting yours. I'd get one just based on its looks, let alone any of the other goodness.
But it's clear that software is important to cars nowadays. I don't think any mfr fails to grasp that at some level. So presumably some will succeed to some degree; why not Hyundai?
The OP said that Hyundai partnered with nVidia - although I grant that the keyboard making could still have been done by a crappy code factory.
To me self-driving car and all that amount of stuff is simply dangerous, what if someone hacks a million of self-driving cars? What damage can he do? A disaster, worse than hacking a nuclear power plant... and I said coding standard for this kind of vehicle is not minimally comparable to the one of nuclear power plants. We are talking about people that till yesterday did program the offline car radio software that now are programming software that can take the control of the vehicle.
If you know a manufacturer putting radio devices on the CAN bus, by all means name and shame. I'd be morbidly curious because of how obviously terrible an idea that is.
I suppose if you brick your own computer the dealership probably won't realize that you were the one responsible. Just don't say, "yeah I cracked your ivi but after I modified the system image the car wouldn't start anymore...." Still, you might want the full warranty before attempting this step...
I remember "carputers" were a somewhat common aftermarket mod in the early 2000s, mostly running a stripped-down 98 or XP on an SSD or memory card. The obvious difference being that you had full control of it from the start. Here's an example of someone doing so:
Makes me feel better about my own incompetencies. But also makes me scared for the future of safety in vehicles.
Wonder how true it is that you only get a couple of weeks in jail for stealing a car (in Milwaukee at least)...
So there's no "hack" really, just destroying the lock cylinder.
https://www.thedrive.com/news/how-thieves-are-stealing-hyund...
The "immobilizers" you're referring to are the bane of my existence from my perspective. Instead of getting cheap $5 copies of my keys made, I have to pay something like $120 to Ford to get copies made.
Working-class teenagers in Milwaukee do not use flatbed tow trucks to steal cars.
>The "immobilizers" you're referring to are the bane of my existence from my perspective. Instead of getting cheap $5 copies of my keys made, I have to pay something like $120 to Ford to get copies made.
Ask anyone in Milwaukee whose car hasn't been stolen whether they regret having an immobilizer.
But if as a society, the default has become that your car will be stolen then the society has collapsed. It's more like a bunch of competing warlords, with the most prominent one being the local government.
https://www.thedrive.com/news/how-thieves-are-stealing-hyund...
Hyundai Motor America:
Immobilizers became standard on all vehicles produced after November 1, 2021.
One day, you too will be old.
They could start fostering an app ecosystem for their cars.
And it would be an extra selling point for their cars (especially if there are apps that won't run in other cars).
And it might even turn into a new revenue stream by building an app store.
Toyota, for example, charges something like $150 for a single satnav maps update, although now CarPlay/Android Auto is a standard feature and has tanked that market.
Afaik Ford has similar program where you pay one time fee for ability to reprogram modules remotely.
Imo a good deal for consumers.
A lot of this is done entirely in security by obscurity so there might not even be any actual cryptography/authentication involved. It's purely a rent-seeking operation.
All the CAN protocol data being public means there's no need for expensive documentation, proprietary scan tools or trips to the dealership for key/module programming if it's all been reverse-engineered (a lot of programming and security-related things in cars are more down to obscurity than actual public-key-cryptographic authentication). Hell, it may even remove the need for expensive modules (over 1k bucks for what is essentially a slow microcontroller on a conformal-coated board running shitty firmware) if the docs allow third-parties to reimplement module functionality on the cheap. It would also blow up any future attempts at subscription-based heated seats or A/C if the published docs make bypassing it trivial.
I hope that one was intentional; I chuckled.
As for gaining access to the engineering, I’m interested that it was left in. We logged everything of course, but all of our engineering tools were removed during the build process. Essentially, our engineering mode was baked out.
Modern cars are literly just hyper-optimised consumer goods. Hyper optimised for warrenty periods and unskillly supply chains with no quality control or pride. modern cars are literly like going to a LAN party with a different personing bringing boxes that need to interact without failure. not happening. hackable to the hilt because pentesting cant be warrentied out.
He claims to have the fastest web server on the planet. It'll do about 160km/hour.
The car being new and under warranty is a major advantage in this case.
Add to it that most developers from Asia do not really expect or care about privacy and are super quick to drop any quality standards to meet deadlines. And the management that likewise does not value quality besides things that can be easily seen and typically does not tolerate any delays for anything that is not absolutely necessary.
I worked for a well known, huge Korean company. When I was there I learned they shipped a mass produced device with a telnet server with a simple default password. This wasn't done for any evil purpose -- the development team decided this would improve their ability to debug any production problems they might face. They were not trusting their own code and were looking for a quick and easy solution to deal with inevitable deluge of support tickets.
https://android.googlesource.com/platform/cts/+/3ece5ae7a51d...
We would probably all love to hand write encryption algorithms for data transfer, or beautiful animations on user interactions, or perfectly graceful fault handling, or 100% test coverage.
The reality is that kind of work takes far longer than most employers are willing to wait. I doubt heavily that it’s the engineers love of coding that is lacking, rather the employers patience.
Yikes. Funny that you mention this, because it’s precisely the kind of thing that one would expect from this sort of “talent”, and not from real engineers.
No. One does not hand-write encryption algorithms, unless they are Daniel Bernstein or similar.
-> You did a casual racism there, unless you can back up your claim with non-anecdotal evidence.
Asian cultures’ have similarly cavalier attitude towards privacy.
Noone said anything about races. Asia is a continent.
Thus the claim that the original comment was racist is false in my opinion.
Another argument against this claim would be the fact that Asian software engineers (here “Asian” is used in the racial sense) raised in Western countries with a strong culture of privacy, seem to be just as privacy conscious as their Caucasian counterparts.
Thank you for giving me the opportunity to correct myself.
That said, both the original post and several comments, including this comment's parent, are equally prejudicial: attributing qualities to large groups of people based on location or ethnicity and solely relying on anecdotal evidence as opposed to controlled and peer-reviewed study.
Case in point: are there any studies to back up the claim that 'Asian' folks raised in Western countries are more privacy conscious than their 'natively raised' counterparts?
It is useful term because all these groups come from different environment with a different history and all are distinct enough from other environments that it makes the name useful to describe certain things.
It does not mean that all asians or europeans are the same. Any thinking person understands that talking in general is useful to describe certain things but also understand there is much more subtlety and exceptions under every statement like that.
So we know that people from different backgrounds have different IQs, education or predisposition to different health issues. It is not racist, these are just statements of facts.
Racist is when you try to take these facts and paint them to discriminate or entice discrimination against people just for the fact they share same background.
So when I say that "asians typically care less for privacy" is a statement of fact. You have to contend with the fact that not all people around the world care about privacy the same way and the moment you do so you understand there are some identifiable groups of people that care less.
If I somehow did this to communicate that asians are somehow worth less as people because they care about privacy that would be racist. That would be coming as view of a person from a western country somehow telling that people who do not value same things as me are somehow worth less. Which is a stupid an narrow way of thinking about the world.
When I say "asians value privacy less" and you say "this is prejudice/racism against asians" what it really is is your racist brain. You are saying that your western values are better than values of people coming from some other region.
Part of being racist is being closed to the idea that other peoples have different values that aren't necessarily better or worse.
But I fail to see how my and your experience are relevant to the way OP expressed himself re: 'Asian' behaviour?
Having lived and worked in South Korea for 4 years, I can't confirm this to be true. My Korean colleages were no less diligent than the ones I now have in Germany, on average. It's true that pressure is high and projects are often run in an air of permanent crisis mode to keep the pressure up, though. If corners get cut the decision usually comes from above.
I do systems engineering on operating systems and HMI for consumer electronics. In Korea it was for smart TVs and industrial equipment control, in Germany for cars.
Also, while I have you: can you please not use HN primarily for political/ideological arguments? It looks like that's what your account has been doing, and it's not the intended use of the site.
https://news.ycombinator.com/newsguidelines.html
https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...
You started a hellish, tedious flamewar with this. That's exactly what we're trying to avoid here.
Please edit general putdowns, casual swipes, and flamebait out of your HN comments, and stick to what you can legitimately say from your own experience.
But this is my 22 years of experience in software development working for various companies from all over the world, including a number of companies in Asia.
I have experience working directly for about 30 companies and indirectly for about 50 companies.
I worked for a core security team for one of the largest phone makers from Korea. I don't want to name the company but when I say the actual privacy was not a huge concern this is actually my own experience working with them.
These are facts just like saying most Americans are overweight. You might not like it, but that does not change the fact.
Here, some more explanation about groups of people, facts, prejudice and racism: https://news.ycombinator.com/item?id=32480914
Flamebait with racial/ethnic/national generalization is just about the biggest provocation there is. It's bog-standard forum moderation to ask users not to do this. Please don't do it again.