Live data from Hacker News

I hacked my car

programmingwithstyle.com

21–30 of 142 posts

Re: I hacked my car

#21
>If I could figure out all of the security measures of the firmware updates, I could modify an existing system image with my own backdoors, giving me full access to the IVI.

I suppose if you brick your own computer the dealership probably won't realize that you were the one responsible. Just don't say, "yeah I cracked your ivi but after I modified the system image the car wouldn't start anymore...." Still, you might want the full warranty before attempting this step...

Re: I hacked my car

#22
I would be shocked if Hyundai wasn’t outsourcing most of its software development to the lowest bidder.

Any company that believes its core business isn’t software will not pay for software developers.

Re: I hacked my car

#23
The Mac address part stood out to me, has something changed over the year that made changing Mac addresses more complex?

Back in college our school had some limitations on the internal networks in our dorms. After doing my normal stuff (you know mega downloading,ftp, limewire etc) my net stopped working. Come to find out they had a bandwidth monitor and would just block you for some time if you used too much and had to contact tech support, even for simple things like window updates.

Anyways, somehow I found out I could tweak some net configs in the registry. So here I randomly change some dword value to change my Mac address. I finally got back online and just forgot about it.

A few days later I came back to my room after classes, my roommate told me the school officers raided the room trying to get on my PC. I went to the student dean's office and come to find out I took net access from I think the president and they tracked it to my PC ... Some luck I say lol .. Tech support said that there was no possible way I could change my Mac address after a bit back and forth I decided to just agree with him.

O yeah and they had like a 200-300 page printout of irc chatlogs ,there was more stuff but I'll end it there.

Needless to say my net access was blocked for a year even tho I had a work study job with the webdev department. It didn't stop me though, I ended up running a long cat5 cable from the dorm next door. Fun times.

Re: I hacked my car

#24

I would be shocked if Hyundai wasn’t outsourcing most of its software development to the lowest bidder. Any company that believes its core business isn’t software will not pay for software developers.

I’m not so sure. Hyundai/KIA are entering aggressively the EV market in the west. I have an Ioniq 5 and its software, although not bug-free is incredibly nice to use. The touch screen is very responsive too. I would be shocked if they are not taking software development seriously. The car is basically software on wheels.

Re: I hacked my car

#25

Don't expect much from a manufacturer who until recently didn't use immobilizers.

The "Kia Boys" in Milwaukee stole almost 10,000 cars last year, mostly Kia and Hyundai models lacking immobilizers. That's 1 car theft per 58 city residents, in a single year. This gonzo documentary on the phenomenon's worth watching: https://www.youtube.com/watch?v=fbTrLyqL_nw57

Thanks for the link - that's crazy. And awful.

Wonder how true it is that you only get a couple of weeks in jail for stealing a car (in Milwaukee at least)...

Re: I hacked my car

#26

That's why I try to never put any testing or development keys in repositories. From those keys sitting there it just takes one act of negligence for the keys to make it into a production environment. It's really frustrating that most people don't care about this at all. Even people forking my own projects would not listen when I told them to please just generate the keys dynamically (for which I included all necessar…

This. I always generate my keys or certs or whatever as part of my dev workflow scripts, configure the local environment to read these, and then gitignore the resulting files. This way it just works for the rest of team and the mechanisms are plainly visible in the repo.

There are many ways to do this, but one that often fits what I am doing is to use terraform’s TLS provider [0]. Terraform has become pretty ubiquitous for me. I am probably already using it to power other parts of my dev environment setup and teardown. Adding in a call to a little module that spits out a dynamic CA and certs signed by it is really easy.

[0] https://registry.terraform.io/providers/hashicorp/tls/latest...

Re: I hacked my car

#27
post #23

The Mac address part stood out to me, has something changed over the year that made changing Mac addresses more complex? Back in college our school had some limitations on the internal networks in our dorms. After doing my normal stuff (you know mega downloading,ftp, limewire etc) my net stopped working. Come to find out they had a bandwidth monitor and would just block you for some time if you used too much and had…

> has something changed over the year that made changing Mac addresses more complex?

It just depends on what the driver/hardware lets you do. Some drivers don't support changing it and some hardware/firmware may just be built in a way that doesn't make changing it (easily) possible. Not being able to change it may be more of a WiFi thing though. I've had the displeasure of dealing with one of those cards. Not sure if it was just the driver.

The Linux Kernel driver for Intel Ethernet supports changing the MAC address, so there's an example of what that may look like: https://elixir.bootlin.com/linux/v5.19/source/drivers/net/et...

That's already at the driver level though. There's a couple dozen other manufacturers with drivers in the Linux kernel, and their cards may work entirely differently.

If however your hardware allows you to have sufficiently low level access, your MAC address can be whatever you want it to be. After all, if your device says "this is my MAC address", then that is its MAC address as far as anyone talking to it is concerned.

If your card is a black box and is doing all the work internally (I think that'd be most cards?), then you're at the mercy of what it lets you do.

At the other end of the spectrum you'd have programmable NICs/"FGPA with an Ethernet port".

Re: I hacked my car

#28
post #23

The Mac address part stood out to me, has something changed over the year that made changing Mac addresses more complex? Back in college our school had some limitations on the internal networks in our dorms. After doing my normal stuff (you know mega downloading,ftp, limewire etc) my net stopped working. Come to find out they had a bandwidth monitor and would just block you for some time if you used too much and had…

Network cards have a factory-configured MAC address, which is the default one the adapter will use. As you figured out, the operating system is usually able to override this MAC address- but it has to redo this every time it initializes the adapter. It'll still have its original MAC on a different system.

However, in the article they did not have control over the operating system. So how do you change the MAC address then? Well, you change the factory-configured MAC built into the device - which requires using the factory configuration tool!

Re: I hacked my car

#29
post #20

I've heard of much worse security no-no's. The worst example I'm familar with is of a Fortune-500 corporate database with data for millions of private citizens exposed for years on the public web over plain old http (not even https), without any password or public/private key protection, such that anyone anywhere with the right URL or IP address could access it. The big question, of course, is: Why haven't we had a s…

Everyone already has a copy of everything, so what's one more copy?

Re: I hacked my car

#30

Don't expect much from a manufacturer who until recently didn't use immobilizers.

The "Kia Boys" in Milwaukee stole almost 10,000 cars last year, mostly Kia and Hyundai models lacking immobilizers. That's 1 car theft per 58 city residents, in a single year. This gonzo documentary on the phenomenon's worth watching: https://www.youtube.com/watch?v=fbTrLyqL_nw57

Insane. And the cars in question have no immobilizer, so the process is just finding a 2021 or older Kia/Hyundai of a certain model, one with a physical key instead of a pushbutton. Then you just rip apart the steering column and turn the ignition cylinder. I was confused because a USB cable was involved, but it's apparently only because it slides nicely over the mechanism to help you turn it, as opposed to having to use needlenose pliers or similar.

So there's no "hack" really, just destroying the lock cylinder.

https://www.thedrive.com/news/how-thieves-are-stealing-hyund...

Post reply on HN