Earlier quoted context omitted.
It's an open secret in the industry that the CAN bus is not authenticated. If you connect, you can read the data on the bus and inject the data on bus. But, that does require physical access to the car and hooking to the wires. Nobody complains that if you hook to the buses on a PC you can own it. Now they have this security concept where every ECU on the car will have their own private key in their own secure enclav…
I hate computers. Seems like lately they're only used to make our lives worse.
Automakers try to scuttle Massachusetts ‘right to repair’ law
31–40 of 137 posts
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#32Earlier quoted context omitted.
From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…
It's an open secret in the industry that the CAN bus is not authenticated. If you connect, you can read the data on the bus and inject the data on bus. But, that does require physical access to the car and hooking to the wires. Nobody complains that if you hook to the buses on a PC you can own it. Now they have this security concept where every ECU on the car will have their own private key in their own secure enclav…
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#33Earlier quoted context omitted.
From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…
It's not about security by obscurity. A better analogy would be the fight over "tivoization". In safety-critical and highly-regulated systems like automotive and health care, there's a meaningful regulatory interest in ensuring that the devices as sold and authorized to be on the road (or in patients' hospital rooms) don't get modified in dangerous ways. That means that the software and firmware running on each of th…
What use is preventing dangerous modifications, when unmodified devices contain critical safety bugs, and will continue to contain them. The ongoing effort by automakers is increasing the amount of safety bugs by connecting everything to the internet without proper security practices.
The only reason to require signed firmware/hardware as it stands is to decrease the repairability, harm the second hand market, and increase profits.
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#34> For now, Massachusetts’ law is tied up by lobbying and legal fisticuffs. It’s depressing that the will of the people that passed this ballot measure can get pre-empted like this. Before it passes? Sure. But afterward you’re just disenfranchising the voters.
I think the saddest part is there probably isn't an auto manufacturer that isn't a participant in the lobbying campaign against bills like this. I can't even vote with my wallet in this situation.
At this point I'm hoping I'll be able to buy an electric kit car that can satisfy my minimal needs in the near future so I don't have to deal with modern vehicles and their shithead manufacturers.
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#35Earlier quoted context omitted.
From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…
It's not about security by obscurity. A better analogy would be the fight over "tivoization". In safety-critical and highly-regulated systems like automotive and health care, there's a meaningful regulatory interest in ensuring that the devices as sold and authorized to be on the road (or in patients' hospital rooms) don't get modified in dangerous ways. That means that the software and firmware running on each of th…
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#36Earlier quoted context omitted.
Because people want things like remote start, remote climate control, etc. that they can control from phone apps.
Do they though? I mean if it's there sure people will mess with it but I don't recall any public outcry for either center dash ADHD factories or keyless anything.
* Where's my car? Press the button, get a honk.
* Lock the doors. If they're powered, close themi first.
* Unlock the doors. If they're powered, open them afterward.
* Warm up the car, it's cold outside.
* Cool down the car, it's hot outside.
So that's five buttons on a remote, maximum. None of them require connection to infotainment systems.
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#37Insurance companies should get behind Right to Repair. We've so far waited three months and have an $11,0000 price tag to the insurance company on a minor collision that bent our car's front fascia and broke a sensor -- no frame or metal damage. I would have happily repaired on my own if possible just to avoid being without the car for so long. If only I could get those parts and have a decent service manual.
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#38Here's a hot take: legislate an airgap between operation control and infotainment/convenience horseshit.
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#39Current cybersecurity standards enforced in the automotive industry will probably completely kill the possibility of after-market car parts and the usage of used parts in cars. I say this as someone working in this field that has asked a couple of people doing work in this exact direction. I point blank asked them if this will happen, and they just shrugged their shoulders and said... yeah, kinda'.
From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…
Yes
(I've reverse engineered the security system on an ABS controller for the top selling vehicle of a major auto manufacturer. It is atrocious. I'm pretty confident the whole reason it exists is so that they can claim they have one to use the DMCA to stop third party tools from interacting with it.)
Re: Automakers try to scuttle Massachusetts ‘right to repair’ law
#40Here's a hot take: legislate an airgap between operation control and infotainment/convenience horseshit.
Exactly. The infotainment bullshit should be in zero way connected to the actual operation of the vehicle. There is zero reason why the laggy, nonsensical software that controls my radio should control my engine. Someone correct me if I am wrong, please.