Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the first place.
Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the first place.
I'm speaking as one of the authors of the Uptane standard for secure software updates in vehicles, and as a life-long proponent of user freedom and open access to the computers we buy. There are possible solutions here, but they are not easy.
I love "it's a complicated trade off" - it's way more interesting than whatever slogans end up defining "sides" in a debate
sure most of us reading this have the skills to write new code for their ECU, but realistically almost none of us would do that anyway unless we want to make a trade off that effects emissions.
Many mechanics will read and tell you the codes for free. Auto part stores will as well.
What use is preventing dangerous modifications, when unmodified devices contain critical safety bugs, and will continue to contain them. The ongoing effort by automakers is increasing the amount of safety bugs by connecting everything to the internet without proper security practices.
The only reason to require signed firmware/hardware as it stands is to decrease the repairability, harm the second hand market, and increase profits.
On the other hand, a Minority Report future where "your" car answers to a different master, or you don't have the right or ability to control your own medical implants and prosthetics, is terrifying. Given that we've lived for almost a century in a world where cars can be modified in unlicensed ways, I'll go with the devil we know.
But, that does require physical access to the car and hooking to the wires. Nobody complains that if you hook to the buses on a PC you can own it.
Now they have this security concept where every ECU on the car will have their own private key in their own secure enclave. You need that key to put authenticated data on bus and it can only be updated by the OEM's.
The authenticated bus infra will probably not protect against remote attacks ( since if you own the ECU SW you have the cert and you will still be able to publish signed messages) but will kill ability to change HW.
I really would not like to kill our ability to fix our vehicles but I feel this is the thing that is going to happen.
Not just a concept, on vehicles you buy today (from, for example, Ford and VW)
https://cdn.vector.com/cms/content/products/VectorCAST/Event...
In some ways. In other ways, things are worse now.
Yes
(I've reverse engineered the security system on an ABS controller for the top selling vehicle of a major auto manufacturer. It is atrocious. I'm pretty confident the whole reason it exists is so that they can claim they have one to use the DMCA to stop third party tools from interacting with it.)