NHTSA tells automakers not to comply with Massachusetts right-to-repair law
autoblog.com
autoblog.com
If this is accurate:
1. Manufacturers have created systems wherein they can murder their customers remotely. (I expect this to be true, at least to a degree, for Tesla, but other manufacturers should know better than to introduce something as insane as OTA brake control.)
2. What the fucking FUCK is NHTSA doing allowing manufacturers to create systems for remote steering, braking, and acceleration?
https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
So the manufacturer cannot use their own software to manage authn/authz to their cars?
What would stop the unaffiliated entity from giving anyone access to anyone's car? They wouldn't even have a financial stake in making sure they implement proper authn/authz and internal access controls to stop employees/contractors from accessing this information improperly.
https://web.archive.org/web/20230510205950/https://malegisla...
The NHTSA complaint: https://s3.documentcloud.org/documents/23846284/nhtsa-letter... (bump from a comment further down by Simulacra )
If the automaker themselves ran the software for this, they have a financial stake to make sure it's done right, since "hyundais being remotely controlled due to bad hyundai 2fa" is not a good headline. But with a third party, it'll have to be a de-facto monopoly over access to a manufacturer's cars, so once they have the contract and are years after the initial rollout, they might cut costs and leave the authorization/authentication system to rot, or have support agents incorrectly "recovering" user accounts for themselves or being phished into doing so.
If criminals are able to figure out and exploit a relatively simple compromise, what other exploitable secrets are auto manufacturers hiding using obscurity that right to repair would expose to the public?
Any US residents know if the NHTSA is captured by corporate interests, or are they relatively free of corruption?
[1]https://www.thedrive.com/news/shadetree-hackers-are-stealing...
We accept that computer security has limits when the attacker has physical access to a machine. Why should this be different with a vehicle? In this example, attackers need to physically rip apart a vehicle to trigger a vulnerability.
It's not as though the headlight wiring harness is any more accessible than core components like the engine control unit.
That's a bad example. If a computer can be taken over by a USB device, we would say there is a security vulnerability in its USB stack. Firewire is widely criticized for having a protocol based around DMA that naive implementations of are vulnerable in this way.
Once you can start plugging random devices into random ports, there's bound to be a vulnerability somewhere. And how much is it really worth it to manufactures and customers to pen-test requests sent from a fuel pump?
Cyber security doesn't need to be perfect, it just needs to be more difficult than the the brute force solution - in this case, throwing the car on a flatbed tow truck.
Like ethernet, this points towards the paradigm for analyzing security of such buses. For example in an office environment, a link trunking a bunch of VLANs is going to be in server rooms or enclosed in conduit/walls/etc, whereas the ports in individual offices are going to be locked down to specific VLANs, perhaps only to specific MAC addresses, etc.
In other words, yes there are always vulnerabilities to certain types of physical access. But that does not mean that all physical access implies game over. For instance a computer should be secure against attacks attempted from the USB bus, then you might have a case tamper switch that kills the rig, preventing easy access to the PCIe bus which is much more privileged.
Translated to a car, this probably means that non-security-critical devices close to the periphery (like headlights) should be on a separate bus to things like door locks, keyfob receivers, etc. AFAIK my car already has two separate CAN buses, bridged by the gauge cluster. The distinction has to do with hard realtime messages from critical systems (engine, steering, ABS, etc), and less critical messages of turning lights on/off etc. We can imagine one or two more buses with distinctions based on security.
For the more serious attacks mentioned, the automakers are essentially saying that they build extremely vulnerable systems and are afraid to disclose that fact.
I suspect we're in violent agreement though, that the correct outcome is to fix the vulnerabilities AND to document the repair methods.
It’s the “evil maid” problem, and it’s extremely difficult to protect against, such that you pay huge premiums to get equipment hardened against these types of attacks.
Question about the U.S. legal system:
If that's true, and if NHTSA's position is based on rule rather than law, then can NHTSA be (successfully) sued because the rule is capricious?
IIRC courts have set a really low bar for the rationality of administrative rule-making, but I may not know what I'm talking about.
This is almost certainly what the Massachusetts AG will next do.
- Jim Farley
NTSB OTOH...take their responsibilities more (or at all) serious.
But Tesla is clear in their methodology;
“To ensure our statistics are conservative, we count any crash in which Autopilot was deactivated within 5 seconds before impact”
Those stats used to be criticized on the basis that AutoPilot was driving predominantly highway miles and it’s safety record was being compared to overall driving crash statistics which have much more non-highway driving.
Now Tesla breaks out AutoPilot and FSD statistics and shows that FSD driving, noting that those miles are predominantly non-highway, still has 5x fewer crashes per million miles than average.
As you can see, the goalposts moved however. Now the “standard” for convincing stats includes controlling for road surfaces, weather patterns, and phase of the moon.
https://twitter.com/WholeMarsBlog/status/1650601088981307392...
Much as you'd like to imply there is goalpost shifting, these are quite valid concerns, and not facetious.
Road surfaces: poor paint, marking, potholes, heavy use of crack filler - all things which will cause FSD to disengage as it can't determine where the road actually is.
Weather: FSD will disengage in sufficiently heavy rain/show/fog/hail. It will also be compromised by bright sunlight and road reflections hitting the "vision only" camera system.
> Now Tesla breaks out AutoPilot and FSD statistics and shows that FSD driving, noting that those miles are predominantly non-highway, still has 5x fewer crashes per million miles than average.
All of those factors above happen on all types of roads.
By absolutely no coincidence, many of these factors result in increased collisions. FSD gets turned off in these conditions, so "conveniently" it doesn't suffer the collision adjustment as a result. Human drivers have no such ability, and nor do NHTSA statistics say "Well, these crashes happened but they weren't under optimal and level playing field conditions so, well, they don't count".
Rephrased: to be actually comparable and worthy of anything beyond Tesla "marketing", crash stats should be looking at "similar constraints" between FSD and humans, i.e. if FSD can't or won't engage on a given stretch of road, or in given weather conditions, then the human crashes that happened on that same stretch of road or weather conditions shouldn't count for comparison, because you have no way of saying whether FSD would have driven better, because _it wouldn't even engage_.
Breaking it down to "highway vs non-highway" is certainly _easier_ but reductive to the point of near-meaninglessness.
If the FSD stack crashes, or if it is completely unable to track its position on the road, you will get a forced disengagement - a loud alarm with a big flashing red “Take Control Now” alert.
That doesn’t happen if the lines get hard to see. That doesn’t happen if snow starts to fall. That doesn’t happen if the sun is at a bad angle. Forced disengagements of FSD are very rare.
The human driver of course can engage or disengage FSD at any time. The system will want a clear view of the lanes at the moment in time that FSD is first engaged, after which it will stay on until the driver decides to turn it off. You can engage FSD at night, in the rain/snow, etc.
But I can see how you might assume there are dangerous conditions that humans are compelled to drive where it’s unlikely FSD would be used. And let’s even presume without evidence that is true.
However the premise is flawed.
The vast majority of traffic accidents are not due to driving conditions, but rather are due to driver conditions. Drivers in accidents are usually either drunk, fatigued, or distracted. Drivers in accidents are likely to be inexperienced, or overly aggressive.
This is why the gap is so large (5x safer is an absolutely massive gap). Not because humans can’t be better drivers, but mostly because humans choose not to be better drivers because, frankly, humans make lots of really bad choices.
This raises a question for me: Why the actual fuck are safety-critical systems able to receive commands from anywhere other than the driver's controls or diagnostic port? Perhaps I am old-scool, naive, ignorant, etc, but given what "safety-critical" means, that strikes me as egregiously unacceptable.
I can sympathize with the idea of convenient remote diagnostic and repair, but in my opinion, this is a case where the saftey risk not just to the driver and passengers, but anyone else nearby, outweighs the convenience of logging into Ford's/BMW/Honda's website, click button, car works again.
And here are the HN comments: https://news.ycombinator.com/item?id=36332086
> "Vehicle manufacturers appear to recognize that vehicles with the open remote access telematics required by the Data Access Law would contain a safety defect," NHTSA said in its letter to General Motors, Tesla, Ford, Toyota, Rivian, Volkswagen and others.
I guess they’re just taking it at the manufacturers’ word that there’s just no way to implement this feature securely.
”We've tried nothing and we are all out of ideas!”
an insurance contract could work with highly granular , per-risk billing based on usage data, maybe even pushing a change in performance if your driving is too risky for too long.
what would be good is to assure such mods were benign, and be able to tweak steering, and breaking, based on current performance, and location, be it steep winding mountain pass, or desert straightways. this should have some local override to a safe default.
I think it is more that manufacturers say, and NHTSA agrees, that there is no way to securely comply with the state law quick enough to do so by the time the law goes into effect. At least that's what I recall from another article on this.
If this is based on law, the NHTSA doesn't have a choice. It has to enforce federal law, and federal law trumps state law. If it is based on a rule, the NHTSA has discretion and something screwy is going on.
https://s3.documentcloud.org/documents/23846284/nhtsa-letter...
The letter only calls out one very specific part of the law around allowing open-access to send commands, which the letter states is an unacceptable security risk and would qualify as a "manufacturer defect", which manufacturers cannot knowingly include in their cars by federal law.
> The open remote access to vehicle telematics effectively required by this law specifically entails “the ability to send commands.” Open access to vehicle manufacturers’ telematics offerings with the ability to remotely send commands allows for manipulation of systems on a vehicle, including safety-critical functions such as steering, acceleration, or braking, as well as equipment required by Federal Motor Vehicle Safety Standards (FMVSS) such as air bags and electronic stability control. A malicious actor here or abroad could utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently. Vehicle crashes, injuries, or deaths are foreseeable outcomes of such a situation.
Hopefully, the response to the letter by manufacturers is to say "Okay, we won't include that clear and obvious security flaw, but we will comply with the rest of the Massachusetts law and allow free access to other telematics such that they're available AND secure."
I wouldn't put money on that being their response though.
If the vehicle's owner wants to modify their car's code, or pay someone else to do it, there are many legitimate reasons to do that and it's no different than the mechanical modifications that people have been doing since cars were invented.
That's ridiculous. The person who is liable for the murder is the murder, not the car company. It's a transparent excuse because they want to force people to have their car repaired at the dealership. Nobody's buying it.
"Remotely" is just how the code gets installed. But installing updates for any of those features over the air is perfectly fine when authorized by the owner of the vehicle.
Moreover, this rule is about remote access, not what someone can do who has direct physical access.
If the dealer hadn't mentioned that, I'd never have known. I don't even know if the person we bought it from knew about it since he was the second owner.
It looks like this is at the NHTSA's discretion.
Then, even with federal preemption, the auto manufacturers would be forced to comply.
“ Subaru and another automaker, Kia, have been especially aggressive in resisting the law. While other companies are counting on a long-running federal lawsuit to overturn the statute, Kia and Subaru opted to shut off the features in their vehicles that are covered by the law.”
> The NHTSA said a malicious actor "could utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently."
Yet, the Mass law is looking for...
> allow independent repair shops to access diagnostic data that newer cars can send directly to dealers and manufacturers to allow consumers to seek repairs outside dealerships.
It sounds like the same access to get data on the vehicles also allows control. For auto companies to comply with both laws could be possible but that it would require more fine grained access controls.
Or, am I missing something?
Really seems like a lot of fuss about stuff that has plenty of possible options. I might even call it FUD or a miscommunication it's so sloppy.
Personally, I don't want a car sending data to anyone. I disconnected OnStar in the one vehicle that had it. Pretty simple to remove the bridge between the cell board and the rest of the electronics.
Right now they have a system where automakers granted themselves a dangerous and unreasonable level of remote access to cars that aren't theirs. Now they're claiming that it would be dangerous and unreasonable for third parties to have that level of remote access to cars that aren't theirs.
No kidding.
But you could easily have a system where a remote access server has to be authorized by the owner, e.g. by having to press a button inside the car while the key is present. And could be revoked by the owner in the same way. Then the car could be repaired by anyone... who is inside the car and has the key. Which is not only completely reasonable, it's more reasonable than the thing they're doing now.
Some car manufacturers have also attempted to use encryption and implemented it so poorly that it was easily cracked.
There is no technical reason that a car key can't effectively be a yubikey. The computer issues a challenge to the key, answering the challenge requires a secret stored in the key, so you need the key. It works as long as the encryption isn't broken.
And if "car can be remotely controlled" and the encryption is broken then that's a much bigger problem than anything your local mechanic is doing.
This is how most modern “smart key” systems work.
For it to work, I'm guessing that additional states would need to join Massachusetts.
Unfortunately, as we've seen with New York, that would probably be opposed by significant back-room sleaze.
You know, all that data they were hoping to make money on.
I'm not familiar with Massachusetts politics. It's a game of chicken between Boston and the NHTSA (or Congress), not the automakers--they have to comply with the law.
At which point people are going to notice, and ask why, and when they learn the answer is that the NHTSA is captured by automakers, maybe the NHTSA would like to avoid this hit to their reputation more than the commonwealth of Massachusetts would like to avoid looking like it's standing up to Big Auto.
Massachussetts would be banning the registration of new cars. Manufacturers wouldn't have a choice because they can't comply with the Massachussetts law. Maybe consumers who don't want to register their cars will still buy, I don't know.
It's a high-stakes gamble at pressuring the NHTSA. There are likely better ways to do that than shutting down the state's car business.
You know perfectly well that hardly anybody is going to do that.
> There are likely better ways to do that than shutting down the state's car business.
Like what? You have to do something that gets people to notice enough to put pressure on the captured regulators.
Which is why I said "Massachussetts would be banning the registration of new cars."
> Like what?
In the short term, their AG can sue under the Administrative Procedure Act. SCOTUS is re-working Chevron, and this case might thread the needle.
In the medium term, they could angle for DoT intervention. This would probably require coordination between their Senators and other like-minded states'. In the long term, the Congress must pass legislation that, if not granting a right to repair, at least explicitly enables it.
In summary, someone has to commit to making this one of the half dozen or so things one gets to do in office. I'm unconvinced Massachussetts voters would reward that.
Get the state's Congressional delegation to introduce a law that would explicitly protect state right to repair laws, taking it out of the regulators hands, moving the debate about cybersecurity claims vs right-to-repair to a different and more visible venue.
Obviously, the State gov can't compel that, but if the right-to-repair rule is sufficiently popular with the state electorate, it should be easy to convince the State's representatives in Congress to push on the matter.
Something can be popular (in the sense that a significant majority are in favor) without having enough interest or organization behind it to cause federal representatives to care. Moreover, Massachusetts is about 2% of the federal legislature. Even if their citizens and representatives care about it a lot, they may not have the votes to do anything at the federal level.
Whereas if they refuse to be cowed, it costs the automakers something. Maybe they'd like to be able to sell cars more than they'd like to be able to lock third party mechanics out of them, and stop pressuring federal regulators to keep doing what causes them to be prohibited from it.
Not if manufacturers are federally prohibited from complying with the requirements of your registration conditions; there won’t be anything qualified for you to register.
I would, but the US Supreme Court in Gonzalez v. Raich, 545 U.S. 1 (2005) already did; the current state of nonenforcement of federal prohibition agaimst state-authorized use isn't from a Constitutional limit due to the interstate commerce clause, but from a federal law adopted by Congress, specifically, an appropriations rider adopted in each spending bill since 2014 prohibiting DoJ from spending funds to enforce federal marijuana laws against certain acts whetr authorized by state law.
That is a pretty convoluted process to do not enforce a law.
This might be factually correct, but it's not how it works in practice.
The federal government exists at the behest of the states, not the other way around. When states start banding together in direct protest of the federal government, there's two paths forward: one escalates violence and leads to a civil war, the other peaceful strips the federal government of illegitimate power.
This is why the DEA cannot enforce their brain dead cannabis laws in California, and why the ATF cannot enforce their brain dead gun laws in Texas.
That is very fundamentally not true--it is the reason the US Constitution exists at all in the first place. In the US, it is neither the case that states exist at the behest of the federal government (that would be true in a unitary state, which most US states are, incidentally), nor that the federal government exists at the behest of the states (that would be true in a confederation, as the US was pre-1787). Instead, the US is a federal state, which means that the federal government and the constituent states have their own existences and loci of independent powers, and are in some sense co-equal.
And every time states decided they were going to disagree with the federal government by force, it is not the states who won that argument.
A rag-tag group of untrained goat herders and farmers kicked out the largest military force in the history of the world using basic fighting equipment. This is all despite their invaders having tanks, helicopters, jets, satellite imagery, night vision, body armor, and 10:1 ratio of boots on the ground.
The overwhelming majority of experienced combat veterans have been out of the US military for almost a decade and side themselves more with their state of residence than the federal government. There is an entire generation of Americans that have more combat experience than anyone currently in the armed forces.
Why exactly do you think the federal government is going to do anything again? The deck is stacked against them. It's much better if the federal government peacefully relinquished power and gave it back to the states.
The argument seems to be that anyone that disobeys the US federal government should be killed because it happened 150 years ago, therefore it will happen again the same way today.
https://www.nhtsa.gov/sites/nhtsa.gov/files/documents/nhtsa_...
That frankly shows this was not unexpected. And there was responsible transparent discussion between relevant parties.
The NHTSA was doing their job.
Maybe the MA senators and representatives were lobbing them a softball, explicitly calling out cybersecurity instead of leaving review topics up to NHTSA, in hopes of this happening. But that is obviously paranoid and an avenue of discussion that is difficult to talk about. So, I'll just let that go.
Isn't that the exact opposite of how things actually work?
CA has stricter environmental regulations. Numerous states have stricter minimum wage laws. Labor laws. Etc.
(And yes, these can get challenged in court. In fact, the MA right to repair bill is being challenged presently.)
But these are the same bad-faith arguments (FUD around remote vehicle takeover, which is not required by the MA bill) the voters of MA heard during the election season that this bill was (overwhelmingly) passed during. MA voters do not expect auto-makers to not uphold their federal obligations: MA voters expect them to uphold both.
If they’re in conflict, they cannot. State laws being stricter than federal ones don’t conflict.
A lot depends on how the federal law is written. Federal law can be written to completely preempt state law in some given area or it can be written to only preempt state law in the specific things in that area that the federal law actually provides rules on.
For wages federal law sets a minimum wage but does not prohibit states from setting their own higher minimum wage.
For many environmental laws federal law is written to completely preempt state law. States in those areas cannot set stricter standards. For some of those, such as car emissions, the federal law completely preempts (which would stop California from having stricter regulations) but the EPA is authorized to issue waivers to allow states to be more strict. There is such a waiver for California that allows them to set their own stricter standards and allows other states to choose to follow the California standard.
The Trump administration revoked California's waiver. (And then when several car companies announced they were going to continue to meet California's standard even if no longer required to do so the Trump administration threatened to sue them for antitrust).
The Biden administration restore California's waiver.
This is legally incorrect. There are challenges to agency authority, which might change the status quo. But even in their most ambitious forms, the NHTSA pre-dates Chevron by two decades.
In any case, that's an aside in terms of what can and cannot be federal law. Federal law trumping state law was always intended.