But to be honest people are taking their specification and dooms-day-ism to stupid extremes. Soon we'll be talking about "it is only as secure as the CPU, what if you find a CPU bug and bypass all security?!"
I would argue otherwise, plenty of signature schemes give you enough rope to hang yourself. The Playstation 3 example springs to mind!
Here's another page which is describing the steps: http://www.areacellphone.com/2009/12/motorola-droid-rooted-h...
Here is the commit with a bug fix: http://review.source.android.com/12807
and actual diff: https://android-review.googlesource.com/#/c/12807/1/verifier...
Of course.. there's some room for them to screw up, but I would argue that that's set off by the risk of having buggy vehicle control firmware killing people. Especially with a new vehicle like the Tesla.
I'd prefer it if my car didn't have any connection between a public network and it's control systems, but if it does I want it to be able to automatically install patches ;)
The car manufacturers who do OTA updates for their cars are sitting on time-bombs. The clock is ticking for them until people get killed this way (regardless of them using HTTPS or signed updates - which some manufacturers don't even use now).
http://www.theregister.co.uk/2014/07/21/chinese_uni_students...
Security is about degrees and nuances. These kind of black & white statements are unhelpful and unrealistic.
Have you /been/ on the internet, lately? ;)
"Climate control system" is an abstraction over belt driven moving parts.
Yeah, no. Auto mfr.'s want to reduce the display count to make cars cheaper to make and the interiors simpler to build. I've never ever spoken to or heard form anyone who 'wants' or even kinda likes having their climate controls on the same screen as their maps, pandora, etc. It's confusing, usually cluttered, and complicates things unnecessarily.
Customers want things, it's not their responsibility, it's the manufacturer's responsibility to not ship something unsafe
One problem is that there is no limitation in the CAN protocol to prevent a node from impersonating the master node. Another is the mutability of a node's firmware.
http://www.gpo.gov/fdsys/pkg/FR-2014-06-06/pdf/2014-13245.pd...