Automakers Say You Don’t Really Own Your Car
eff.org
eff.org
Now we're talking about downloading iPhone apps that promise 10% more speed and the only technical challenge is aligning your car's USB plug with your phone. And then hitting the big green button labeled "GO FASTER!"
That doesn't sound like anything I've ever heard of. Many manufacturers require expensive subscriptions to access service manuals and programming software.[1] The average person (and even a lot of small-time mechanics) doesn't have access to those resources.
What do you think has changed / will change that will lead to an onslaught of dangerous amateur tuning by phone? The technology to do so has existed for years.
Now you need a computer, hard to find software, special cables, etc.
See all that data that is generated when people use the product? That could be mined, refined, and made into new products. All those computer screens in the car are suddenly new avenues to push advertisements. All those critical equipment are a avenue to sell repairs, where the producer has monopoly. And if nothing else, the computer inside the car can always be made into a platform.
Take a product, throw in some DRM, and voila, you can create revenue after sale. The DRM and the accompanying user agreement is the glue from which all that extra revenue can be made.
From a company perspective, I don't see how much of a choice they've got. A competitor can use that extra revenue to lower prices for which a consumer won't be able to assess when buying. Selling equal-looking products at higher prices normally spells doom, and regulations haven't even begun addressing the issue.
There are many modern cars where (for example) the "service in XXX miles" indicator for oil changes can't be reset except by the access-restricted and very expensive factory service tool.
Many independent shops already have to buy reverse-engineered tools to allow them to service these cars and continue to stay in business. It's clear that automakers are very interested in abusing copyright laws to force a monopoly on after-sales service.
You can buy an ODB2 reader for ~$20 on amazon. If you are working on any car newer than 1990, an ODB2 reader is a standard tool in your drawer.
The real problem is, to change the headlights on my car, you have to remove the front wheels and part of the wheel well. If anything these shenanigans help independent shops. If they built cars to last and be maintainable, there would be a lot fewer independent shops.
The example I supplied (Service Now mileage indicator, not Check Engine Light) was a very specific one with Porsche in mind. Most post-2004 Porsches have no procedure to reset that indicator without using an official PIWIS ($13000 + subscription, if you can even get one) or reversed Durametric ($250 + illegal if automakers claim their software can't be reversed).
Another example of anti-competitive dealer software is "coding." Replacing the headlight control module in a BMW, for example, requires it be "coded" to the car's control systems. Many DIYers and independent shops use straight-up pirated BMW diagnostic tools, because again, the "blessed" way to do so costs thousands of dollars.
All of this is categorically different from a private party renegotiating the well-established legal concept of ownership for the sake of private profit and ongoing exploitation.
If a car manufacturer shores up its profitability and that of its dealers by ensuring that everything right down to the oil change needs their licensed and authorised device, then many governments would label that "business innovation" and claim it's in the common good of the economy.
Automakers want to lock out consumers and unapproved mechanics from tinkering with vehicle software on the grounds that (1) they could purposefully or accidentally make the vehicle non-compliant with safety/emission standards, and (2) they could use the vehicle's computers to infringe copyright (presumably ripping streaming audio?), and (3) closed source = more difficult for malicious hacking of vehicles.
There are already laws in place to deter all of the outcomes of these actions. To deter the action that might lead to unlawful action... sigh.
When have laws ever stopped bad actors?
There are laws against breaking and entering, burglary and so on. Does that mean you don't lock your house or install an alarm system?
In some places (quick check here, California as one example) locksmiths are required to be licensed:
http://www.bsis.ca.gov/forms_pubs/locksmith_fact.shtml
Also noting that there is a physical limitation to the harm that can be done if locksmith tools are sold. Both geographic and how the tool (which in not digital and has friction in distribution) is able to spread.
Someone using locksmith tools will most certainly operate in one area. They can't work from the comfort of their bedroom and in most cases can't cover their tracks as easily as digital crime can be covered (and done from anywhere in the world).
We should punish the actual bad behavior, not things that enable bad behavior. Otherwise, we'd outlaw kitchen knives and driving cars because, hey, you never know what someone could use them for.
In San Francisco I saw someone start to cross an empty street at an intersection, who then saw a police car cross the street two blocks away. The pedestrian stepped back onto the pavement and waited for the lights to change.
This was one of the most trivial crimes possible - jaywalking on an empty street - and it was stopped by a law.
"They say you shouldn’t be allowed to modify the code in your car because you might defraud a used car purchaser by changing the mileage."
All you would need to do is checksum to know if the consumer had manipulated the code. Let car owners see the code running on their cars but void liability if the software has been altered.
Plus, the idea of a car needing a net connection to operate is a non-starter (excuse the pun).
Your turn.
I implement a RSA key for each car, signed before it leaves the factory. Each key is housed in memory that is heavily epoxied and very difficult to remove (in a place that you would have to remove the majority of the engine to reach). The cars ignition system requests validation from the on board key on every start (in fact it gets the actual <start car> command from the chip itself). If the key is not present, the car does not start and instead tells you to return it to the dealership.
Now you say, I can remove the key and then reverse engineer it. What if I put n keys? How many do I realistically have to add to make it so time and labor intensive for you to remove my little inexpensive keys that you just give up? Probably not that many. Oh and did I mention that all of them are in an array? Better be sure you didn't miss one or it will zero itself out giving you no hope of recovery. (The warranty specifically mentions this as something that will void it)
After all that, if you still want to attempt to modify it. Fine. I'll add 1% to the purchase price of the car and reimburse anyone who bought lemons from your little (illegal) scheme.
Requires no Web connectivity of my year 2000 Nissan Micra.
Alternately, the odometer could (and I'd argue should) be implemented in hardware, possibly as an ASIC (or maybe FPGA) plus dedicated EEPROM to store the counter, wired directly to the relevant sensors. Perhaps some data interface with the main computer, but it should be read-only. That would solve this issue right quick.
"Cars should have no anti-tamper mechanisms" != "Owners should be legally able to modify their car."
Even changing the mileage is not a crime, the crime occurs if you sell it and commit fraud by lying to the buyer.
Once again, not illegal to make the change, but probably fraud if you were to lie to your insurer about it.
If your cousin's friend changes the code for the ABS to "work better on gravel roads" and then you wreck, who's going to get sued? Not your cousin's friend - he's living in a van down by the river. The automaker is, because they're the ones with the money.
The whole justice system is broken if we have to take the stupidity of ridiculous cases in account to tame down technological progress.
As is stated elsewhere, it's easier to determine that a physical part failed, and that it was not automaker-issued than to do the same with (e.g.) modified firmware. It's not like people are above attempting to hide the fact that they modified the firmware in order to win a lawsuit.
Is the litigation risk any different with software rather than hardware?
It's hard for me to pick a side here. I want that freedom, but the auto makers have a compelling reason for wanting to stop it (getting sued, warranty issues, etc). I'm 60/40 on the automaker's side.
If you really want to play with engine management, there's always megasquirt.info and wb02.com, which are more hackable anyway.
Some OEMs opt for the low settings where tuning gets detected and logged while still allowing you to run new or modified code while others only allow the flashing of signed code.
Also, as far as i know from motronic mods, they mostly only change calibration data and not the code itself, but i may be wrong.
To be specific: car makers should not be liable for unsafe modifications made by third parties, even if they intentionally made the car easy to modify and did foresee that some people would make unsafe modifications. To subject the car maker to liability in the case of a modified car, the plaintiff should have to show by a preponderance of evidence that the modification did not cause the crash.
I can see this going the opposite way too. E.g. the automaker says that they are not liable because the customer modified the audio system, even though it was the ABS that failed.
I don't buy your argument.
For example, to plug in a laptop and do a checksum of the binaries would take seconds. To disassemble an engine to find a spec'd up cam would take hours.
This would only test that the software was a known set of instructions, it wouldn't help debug the flow of the code and the run-time state:
Software and the state and sequence of events are much harder to look at and conclusively say "yes, this was the culprit".
Disassembling an engine would seem to be on the same order of complexity as disassembling and reverse engineering firmware without source code (perhaps more so).
To answer my own question: because there are fewer court cases about home mods of automotive software, then there are about home mods of automotive mechanical systems. I think it's the lack of precedent that scares corporate lawyers when it comes to this stuff.
Maybe that should still be in Johnny's right to do, and it's up to the service center to detect what happened, but I can see why the automakers would really rather he couldn't do that.
wrong call in my books, but don't be surprised if it happens everyplace.
Some guy comes in with half a cornfield stuck to the undercarriage of their vehicle, who should pay for the suspension work? I deeply feel we should each be responsible for our own stupidity. If it is submitted as warranty, it becomes a cost to the manufacturer and I feel that is inherently dishonest. Additionally, increased costs _do_ get passed onto customers.
I get _why_ it happens, but it shouldn't.
Opening that interface or code turns that black box of deniability into potential evidence of shitty practices leading to failure in what should be safe, correct and easily tested modules.
Think global variables, 4k line functions, goto/jumps, completely ignoring industry standard practices like MISRA, etc.
It's horrifying.
A note about embedded programming on a microcontroller: global variables and goto can be used effectively and safely. Their presence or absence does not alone indicate code quality. Even a 4kloc function might be reasonable if the compiler couldn't be relied upon to inline functions into a time critical global update loop.
As much as I wanted to know about the mysterious "software upgrade" that the dealer claimed was available for my car (that was covered under warranty) - I understand why they keep consumers in the dark.
Do you really want some random guy messing with the base code of his car and accidentally get into a deadlock situation causing the brakes to not engage? Or for the vehicle's accelerator to keep increasing without being pressed?
Something else to keep in mind - people already have figured out how to remotely control a vehicle using bluetooth. [1]
I couldn't tell you what the solution is - whether it be build-your-own-car or forcing auto makers to release their source code - each will still have problems.
[1] - http://arstechnica.com/security/2015/02/senator-car-hacks-th...
So again I say, own is such an overloaded term. I wish people used it far less than they do.
>But you aren't allowed to make copies of that disc. And you absolutely can't makes copies and then sell the copies. You can't even use that disc whenever and whereever you want. For example you can't play that disc through stadium speakers at a sporting event. Nor can you use host a concert and play parts of that album. You can't do it to mix with other music and you can't even play it directly.
You can own a knife, but still not be allowed to stab people with it. That's materially different than owning a computer or car and not being able to look at the inside, modify it, or repair it.
But it has consequences depending on the law if you don't have a license to do it.
Some of the things you say, like making copies of my own disc is totally legal in countries like Spain. It is illegal to distribute them.
In fact, in a democracy if more than 50% per cent of the people consider that they could do something, they can do it, think on the Prohibition.
If those in power reject the majority, they could be kicked out.
If we're going to lump both of these together as you're doing, then "own" is the wrong word to use; you're "leasing" instead. In that sense, I'd agree with you that the word "own" is used incorrectly in a lot of contexts.
I think, we should use the word own if we want to protect ownership rights. If we start saying that "own is such an overloaded term, lets not use it anymore" this is the first step to giving up any ownership rights you may have had.
And you can transcode it too.
What they don't want is distribution.
I can see a huge benefit from having FOSS versions of car firmware in the future. It could be especially important if you don't agree with your manufacturers choice of ethics for automatic driving (See the AI Tunnel Problem).
http://robohub.org/an-ethical-dilemma-when-robot-cars-must-k...
Then, insurers wouldn't insure you on some software, which would mean that you'd be illegal to drive your car in many countries.
https://www.fsf.org/blogs/community/the-car-analogy
They're no longer analogies! They're the literal truth! This is very sadly funny. :-( :-/ :-)
Designing a test suite that catches all possible life-critical errors is near impossible. The cost of testing and certification will probably be quite high, well outside the reach of amateurs.
Just as we advise people not to write their own crypto (its easy to get wrong), I think the same will hold for safety critical software.
All that being said, I think it is very important that this software is open source.
However, the manufacturer is in no way obligated to make that easy or even possible.
The hardware & software have a symbiotic relationship. Each must function within certain developed parameters to ensure the other can function within its specified parameters. That's how Apple can use lighter-weight & cheaper hardware yet get greater performance: both hardware & software are tuned together for optimized performance. Android, like Windows, is suffering from having to support unknown hardware. You're demanding that, under police power of the state (note that: you're threatening to arrest people for this), Apple explicitly allow/support software which Apple has absolutely no control over yet will get grief for when it sucks.
Relevant to the original point: a car manufacturer doesn't want users patching in home-brew software which changes/breaks safety features. While such could be done with hardware, they're increasingly trying to do things to prevent those changes too (model-specific parts, hindering others from making & using inferior components).
A phone you buy on a 2 year contract is yours at the end of the contract. Then you get a new phone and give the old one to whoever in your family needs a new one, or just put it on ebay for fifty bux and change.
This argument is a bit silly, given how many laws can be broken and how much harm can be done by anyone behind the wheel of an automobile, regardless of how it has been modified.
* Ability to modify firmware of your own car.
* Ability to inspect and review code in the car.
The first one is dangerous, imagine someone who wanted to improve ABS but didn't do testings, and this led to a crash. Or, if we consider, more intelligent self driving cars, possibilities for abuse, etc, are enormous.
The second one is discussable. On one hand, we want to make cars as safe as possible, and there's no better way for this, than inspecting code. On the other hand, the company wants to protect their intellectual properties from competitors.
http://en.wikipedia.org/wiki/Motor_Vehicle_Owners%27_Right_t...
Cory Doctorow, http://boingboing.net/2012/01/10/lockdown.html
There's an aversion to transparency in a lot of software stuff because you can't prevent people from stealing your hard-earned work, but in giving your customers more accessibility you'll have an immediate edge in the car market, which, after all, is how you make money.
TL;DR == "tough"
Regulations can be bad, they can stifle innovation, enforce inequality, maintain awful power structures, etc. But, they can also save lives. In America there are a million things you can't do because they infringe on the safety of others.
At an abstract level, an automobile is 3,000 lbs. of metal holding 10 gallons of gasoline that carries human beings through public spaces at up to ~70mph. It travels through neighborhoods where children live and play at up to 25mph. It's a mixture of chemical, mechanical, computing and electrical systems that an engineer needs about 10 years of study to be able to handle after they get to engineering school. Even then they'll specialize.
Car enthusiasts simply don't have the skills to merit carte blanche access to mess around with cars that drive on public roads. In general, they probably don't even have the skills necessary to evaluate their skills which is what makes this so dangerous.
Tinkering with a mechanical system like your brakes is very different from tinkering with a computing system that through an electrical system is controlling the mechanical system that is your brakes. That's orders of magnitude of new complexity. Do you really think the average car-guy will understand the bugfix, written in optimized C or assembly, that accounts for how a certain transistor behaves above 200 degrees Fahrenheit?
To be clear, these laws aren't to protect anybody from their own stupidity, they protect the rest of us. If you do have the skills to tinker at this level then you're free to use them in race cars that aren't street-legal.
If they have a better tool than the DMCA to keep the average person from defeating safety features built in to their car, they should say it. But any system strong enough to ensure there's no dangerous code running in any cars on the road will be opposed by the EFF because it would be a whole new level of surveillance.
> EFF is fighting for vehicle owners’ rights to inspect the code that runs their vehicles and to repair and modify their vehicles, or have a mechanic of their choice do the work.
So I see "inspect" as read access, "repair and modify" as write access and I think what would we do if we had read-write access to our cars? Relly think about that one for a second.
I disagree with the "regulation will be enough" idea in the same way I understand the law regulates people from entering my house but I still lock my door.
Later in the article they go into why the DMCA is the wrong tool for the job and they're probably right, this shouldn't be done in the name of ending music piracy.
Why hasn't a problem manifested already, when I can build a drone, download software for it, and tweak it all I want? It's because very few people do that. And vanishingly few do it will ill intent.
I'm sure that 15 years form now there will be a true crime show about someone who programmed their car to run over their spouse. (It's always the spouse.) But that shouldn't be an excuse to stifle the thousands of beneficial results from hacking automotive systems that will come about from people satisfying their curiosity about what's on the CAN bus.
I guess my point is that, even being a FOSS advocate and pro-DIY, I don't see why car makers should be compelled to hand over their code, unless of course they're already using GPLed or similar OSS code.
Troubleshooting diagrams would be reasonable to ask for, or perhaps some documentation of the protocols used. But demanding that a company release their source code because you essentially feel entitled to it is pushing the buck if you ask me.
The analogy with car engines, I presume, is to make one kind of car engine, and to use the electronic control system to present a range of performances to the consumer market, without having to go to the expense of actually making different engines. Does this already happen, or is it yet to come?
It is a difficult thing to do though because high performance parts often come at the cost of price, fuel economy, reliability and usability. Using the performance variant turbocharger across a line of cars and setting the ECU to a lower boost would result in the lower spec ones having overly expensive parts that boost at the wrong rev range resulting in worse fuel economy and engine response.
Lets say that by a surreal act of good software engineering, you get rid of the hackers problem, what are the odds of getting rid of corruptible institutions?
Plus, I reckon there's probably a whole bunch of code in a Tesla.
I'm not saying it's not, I haven't even looked up a definition, but I do know I've written firmware update code before... I think the way the term gets used is probably a little blurry...
My car, for instance, is a bit old. It has some sort of ARM device in it running a proprietary GPS system. There is an update mechanism that can be triggered when you put a new DVD full of map data into the drive in the trunk. This updates the stuff that runs the ICE as well as the GPS. I would be very concerned if it had anything to do with engine-control I suppose.
Essentially nothing like that is used anymore. Almost every programmable part is reprogrammable in-system unless someone takes extraordinary measures to prevent it from happening. That means that there is no longer any real distinction between "firmware" and "software," and there is no such thing as "read-only software," as you put it earlier. There is only "software" and "locked software."
This thread is all about who should own the keys to the lock.
Automakers aren't trying to take ownership of my car away from me. This is linkbait... no, it's donationbait, and as long as the EFF keeps this up, they get nothing from me, and they should get nothing from you, either.
The EFF actively misrepresents and lies about issues to convince folks to give them money. It's just too blatant, and they represent themselves as technically savvy, so even if it's unintentional, I can't forgive them for those kinds of errors.
"The reach of copyright law has expanded so far that it now threatens people's ability to repair their own cars and protect them against malware. Yesterday, EFF launched a legal campaign to fend off that threat."
Can't even think that I have read any stories (so far) about malware having an impact on auto operation. Hard to believe that opening up the software won't result in something bad happening either.
See the following computer bugs that caused safety problems:
* http://www.bloomberg.com/news/articles/2014-07-10/honda-reca...
* http://abcnews.go.com/Blotter/toyota-pay-12b-hiding-deadly-u...
there are dozens of other stories.
If safety trumps all, we might as well ban people from changing their tires. If you don't use a torque wrench, you might find your wheel coming off on the freeway.
It sure would be nice if I could go in and put Google maps in there.
In the long term, tires, filters, and brake pads could become proprietary in the same way as Keurig's K-Cups are now, though I imagine with more complex DRM.
What will happen instead is, the car's software will be signed and even if you somehow get the sources, you won't be able to run a different version. Just like in tivo.
Getting back to technology, 20 years ago you were able to hack the car with a wrench. Now it's just plain impossible to know what's going on. Hopefully not for too long.
Anyway, you can already mess with modern cars tire pressure sensors, when driving near them. http://www.winlab.rutgers.edu/~gruteser/papers/xu_tpms10.pdf
Closed source and un-modifiable car firmware is like closed-source crypto and other systems - it's not the best. Because it doesn't really have to be better, so why bother. Open source / custom can be as bad or worse, or it can be much better.
I prefer a world where we have the freedom to have good stuff.
Seems you have broken this rule:
http://www.nytimes.com/2010/05/14/science/14hack.html?_r=1
The study referenced [PDF] http://www.autosec.org/pubs/cars-oakland2010.pdf
This was a simple search: "malware car software." Pretty sure disabling the brakes or selectively braking individual wheels on demand could have a deadly impact on auto operation.
First of all it would be EXTREMELY hard to nail down a car crash to malware currently because we have no tools/insight to do so. For all we know (put's on tinfoil hat) car hacking has been employed multiple times by state actors to kill off people who they disagree with. It's way too easy to write it off a the driver made a mistake and never have an investigation into the root cause.
However we HAVE seen that it's possible to hack into a car, there are multiple news articles showing people taking over control of cars remotely and killing the breaks, shutting off the engine, pushing down the accelerator, etc.
Also I don't buy the "Safety" argument it's way to easy to scream "Think of the children" to kill off an argument. Hobbyist hackers who want to hack their own cars have to still abide by the laws set out by the government just like a mechanic can't put a car on the road without breaks. I don't see the difference, yes maybe it will make it easier for bad hackers to disable your breaks but they could just cut the break line which would probably be easier (or should be if the automakers take security seriously at all which I would bet they don't).
Killing the brakes on a car would require mechanical interference/sabotage, not just software hacking.
I see no reason why the ability to brake in my Prius couldn't be disabled by sabotaging the ECU, same with steering and acceleration. There's not a traditional transmission either, so I can't just force it into neutral and roll up a hill to stop. There's technically a mechanical linkage in the break pedal to the disc brakes should the ECU fail, but ECU failure and ECU tampering are two separate concerns.
With that said, I'm not overly concerned about electronic attacks on my vehicle at the moment, someone would still need to forcibly enter the cabin, connect to the OBDII port and make modifications to the ECU firmware, not something some jerk could do while we are going down the freeway. I would certainly feel a lot safer if the code running on the ECU was available for the community at large to dissect and inspect, though.
http://www.cbsnews.com/news/car-hacked-on-60-minutes/
More info on Security Now episode 497 if you are interested in hearing the security devs being interviewed.
Aside from the exceptions snuxoll mentioned, I can think of two ways the brakes could be hijacked on a car with traditional hydraulic brakes in order to cause a crash.
The first is abusing the antilock brake system to render the brakes less effective. Instead of reducing braking power when the wheels lock, it could be programmed to reduce braking power as much as possible in the event of panic braking at high speed.
The second is to abuse the stability control system now mandated by law to be included on new cars in the US and many other jurisdictions to induce, rather than prevent/correct a skid. Stability control works by selectively applying the brakes on different wheels. Applying one front brake at a moderate level (not enough to lock the wheel and leave rubber on the road as evidence) would look just like an erroneous steering input to anyone investigating a crash as long as the tampering couldn't be detected electronically. For extra evil, use GPS or have an observer trigger it manually when the car reaches a location in which a sudden turn would result in an especially bad crash.
So you won't have any problem in <x> years if all PCs are coming with default configuration 'cause "safety trumps all' and "you don't need to tinker with the auto software". You don't need to change your shell. You don't even _need_ a shell anymore. The _company_ will provide you with everything you need. And of course, no choice for what OS you're going to install.
I imagine an answer would be "but my PC isn't going to run over a child". No, but an insecure OS can cause you to lose all your credit balance and many more (which I imagine you can guess being an hn member). All that just because "you don't need to tinker with the auto software".
I'm sorry, but people with views like yours keep the world behind.