Malware infects Android-based automotive head unit firmware
securelist.com
securelist.com
I found all these details through examining the official firmware image and reverse engineering.
I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.
You say "compromised". I say "monetised".
:sigh:
Germany, for example. Utterly bizarre and baffling that a democracy protects its politicians this way. /s
Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
Directions weren't coming from my phone's speaker or the car, but testing audio in the Maps app did (from the car).
Still not sure what combination of connections it had managed to get itself into!
Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.
This sentence doesn't make much sense - Auto (and CarPlay) still work in wired mode over USB 2.0 if the head unit supports it. They never worked over Bluetooth.
(And they use less than 15Mbps so USB 2.0s 480MBps are more than enough)
Remember that not that long ago viruses spread through floppy disks.
Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
It had the benefit of an information center with physical buttons too, so I could navigate around my library without touch screen madness or voice commands constantly failing to understand band and song names.
I've been doing it for years, since it's so much more convenient than the alternatives: plug the stick into my car and I have my whole music library there and it Just Works.
We use an USB key full of audio books: Harry Potter saga and The Quest of Ewilan among others. The whole family is hooked.
The car UI is much more reliable (no phone to unlock by the copilot, no Bluetooth disconnect). The phone battery is spared for navigation purposes.
Sure beats the radio, which plays 2 songs and then 5 min of commercials/sweepers, and has the gall to run ads on the HD text transmission on FM designed for song information.
Article does not say that.
Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.
Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
The two big things here in my mind are:
1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out
2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
Just off the top of my head.
And doing that doesn't really interfere with also setting up and selling proxy endpoints
Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.
The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!
Otherwise any car sitting unused for a week or two would have a dead battery.
Most traction batteries are behind a relay or something and won't be available for full time use...
Car fridge is a thing.
They do not stay in low power for weeks. Car batteries are really not that big, and cranking an engine takes some amps. I had a Subaru crosstrek that was recalled because their cellular modem was drawing IIRC 10ma 24/7, which would kill the car if it sat 3 or 4 days.
At least I'm not aware of any car where they updated the radio in the car when the network got turned off. By contrast, I work for John Deere and just down the hall from me are people who made a ton of money when the 2G network got turned off because a lot of customers paid $1,000 upgrade to a newer radio. I think most people would agree that there is no future that their car radio does that is worth paying money to upgrade when the cell network turns off. At John Deere, we're lucky that we have found pictures that customers find valuable enough that they are willing to pay to upgrade the radio when it goes obsolete.
There's a good chance it will last longer than 3G. 5G was designed to coexist with 4G so a 5G base station can (optionally) use a 4G compatible beacon and use 4G for some timeslots and 5G for others. Even if 6G doesn't do the same, 4G can live until 5G is turned off. 2G and 3G needed a whole channel allocated, which was too much in the US anyway. I understand in some countries they turned off 3G but left one channel of 2G for industrial/embedded devices; maybe one channel per network or maybe one channel that all networks could roam to ... roaming seems more permissive outside the US, too.
Nothing could go wrong.
[1]https://opengarages.org/handbook/ebook/ (chapter 9)
I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.
There are numerous reasons the HU needs CAN, for example to get the steering wheel angle to be able to draw the guides over the backup camera feed. Or to switch to the backup camera feed when you put the car in reverse.
Ideally most cars should be relying heavily on data diodes to minimize the risk of a bad actor wreaking havoc. I know for sure some cars (there was a Jeep example as I recall) don't do that, but I kinda wonder which ones do. It seems like a pretty obvious attack vector worth protecting.
I brought up the backup camera as another reason the head unit has CAN, since in my car that's what's handling drawing the backup guide lines.
The aftermarket HU would have enough data to do so, but in my case it doesn't (although it does read CAN for buttons/iDrive). The original HU is still there and functioning, but the aftermarket Android is between the vehicle harness and the original HU with some passthrough and swapping of video cables.
I can hold down the Menu button on my iDrive and the Android HU switches the screen to show the original HU output and I can interact with it normally. And when I put the car into reverse it also switches so I can see the original backup camera feed, then switches back to Android after I drive forward again.
Of course I use none of the Android functionality at all, the whole ridiculous system is solely for CarPlay.
Few headunits will ask you to connect to the OBD2 port for practical reasons, but the miscilanous manufacturer specific connectors you hook up often include CAN bus connections.
OBD2 port is just 1 of multiple ports with access to the network, even your headlights can be on the bus
This is available on standard OBD-II. Maybe, it is accessible over CAN?
I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).
Also, feel like John Gruber is going to have a field day with this one
Android Auto is the Google equivalent of CarPlay and runs on your phone.
It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.
Unfortunately Android Auto already existed. So it’s confusing.
I have such a car and I am so disappointed that I regularly tell people I would not buy another one and I would not recommend you buy a GM because they do that trip.
- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls
- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps
- Keyless entry basically a shit show of faraday pouches
- OBD port allowing thieves to clone a full key in seconds
- Even cars in decent neighbourhoods have to use steering locks
Sorry but this is a fucking joke and the automotive industry is cancer.
At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.
All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
Simple. It hasn't.
Many feedback loops in modern car is software based and interconnected with each other.
Kits that works half as good without software would be very expensive to make.
Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month *
* Cars without subscription causes acceleration to be restricted to 60mph.
After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don't need to be general purpose computing devices either. I shouldn't have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).
The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
Somehow I doubt it. They're ripe for ransomware attack.