Live data from Hacker News

Automakers try to scuttle Massachusetts ‘right to repair’ law

techdirt.com

31–40 of 137 posts

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#31
post #22

Earlier quoted context omitted.

It's an open secret in the industry that the CAN bus is not authenticated. If you connect, you can read the data on the bus and inject the data on bus. But, that does require physical access to the car and hooking to the wires. Nobody complains that if you hook to the buses on a PC you can own it. Now they have this security concept where every ECU on the car will have their own private key in their own secure enclav…

I hate computers. Seems like lately they're only used to make our lives worse.

Since the Industrial Revolution, and only made worse with the Information Revolution, technology has advanced much quicker than the ability for laws and customs to adapt.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#32

Earlier quoted context omitted.

From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…

It's an open secret in the industry that the CAN bus is not authenticated. If you connect, you can read the data on the bus and inject the data on bus. But, that does require physical access to the car and hooking to the wires. Nobody complains that if you hook to the buses on a PC you can own it. Now they have this security concept where every ECU on the car will have their own private key in their own secure enclav…

The devices on CAN bus can use embedded certificates to securely communicate with each other. Basically VPN over CAN.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#33
post #10

Earlier quoted context omitted.

From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…

It's not about security by obscurity. A better analogy would be the fight over "tivoization". In safety-critical and highly-regulated systems like automotive and health care, there's a meaningful regulatory interest in ensuring that the devices as sold and authorized to be on the road (or in patients' hospital rooms) don't get modified in dangerous ways. That means that the software and firmware running on each of th…

> the devices as sold and authorized to be on the road (or in patients' hospital rooms) don't get modified in dangerous ways

What use is preventing dangerous modifications, when unmodified devices contain critical safety bugs, and will continue to contain them. The ongoing effort by automakers is increasing the amount of safety bugs by connecting everything to the internet without proper security practices.

The only reason to require signed firmware/hardware as it stands is to decrease the repairability, harm the second hand market, and increase profits.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#34
post #19

> For now, Massachusetts’ law is tied up by lobbying and legal fisticuffs. It’s depressing that the will of the people that passed this ballot measure can get pre-empted like this. Before it passes? Sure. But afterward you’re just disenfranchising the voters.

Direct democracy is a threat to order, the unwashed masses know nothing, they're protecting us.

I think the saddest part is there probably isn't an auto manufacturer that isn't a participant in the lobbying campaign against bills like this. I can't even vote with my wallet in this situation.

At this point I'm hoping I'll be able to buy an electric kit car that can satisfy my minimal needs in the near future so I don't have to deal with modern vehicles and their shithead manufacturers.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#35
post #10

Earlier quoted context omitted.

From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…

It's not about security by obscurity. A better analogy would be the fight over "tivoization". In safety-critical and highly-regulated systems like automotive and health care, there's a meaningful regulatory interest in ensuring that the devices as sold and authorized to be on the road (or in patients' hospital rooms) don't get modified in dangerous ways. That means that the software and firmware running on each of th…

dont include dangerous features that have nothing to do with the function of the vehicle. telemetrics, and remote manipulation of software during drive time are not required for safe operation.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#36

Earlier quoted context omitted.

Because people want things like remote start, remote climate control, etc. that they can control from phone apps.

Do they though? I mean if it's there sure people will mess with it but I don't recall any public outcry for either center dash ADHD factories or keyless anything.

In my experience, people like the following remote features:

* Where's my car? Press the button, get a honk.

* Lock the doors. If they're powered, close themi first.

* Unlock the doors. If they're powered, open them afterward.

* Warm up the car, it's cold outside.

* Cool down the car, it's hot outside.

So that's five buttons on a remote, maximum. None of them require connection to infotainment systems.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#37

Insurance companies should get behind Right to Repair. We've so far waited three months and have an $11,0000 price tag to the insurance company on a minor collision that bent our car's front fascia and broke a sensor -- no frame or metal damage. I would have happily repaired on my own if possible just to avoid being without the car for so long. If only I could get those parts and have a decent service manual.

I think insurance companies are also salivating at having access to detailed driving data so they have more reasons to deny claims and raise rates. I'm not sure they want to jeopardize that by getting on automakers' bad side.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#38

Here's a hot take: legislate an airgap between operation control and infotainment/convenience horseshit.

Nice in theory but almost impossible in practice, unless you start installing two copies of many things, one for safety-critical purposes and one for infotainment purposes.

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#39

Current cybersecurity standards enforced in the automotive industry will probably completely kill the possibility of after-market car parts and the usage of used parts in cars. I say this as someone working in this field that has asked a couple of people doing work in this exact direction. I point blank asked them if this will happen, and they just shrugged their shoulders and said... yeah, kinda'.

From the article: "federal regulators claim that malevolent third parties could "utilize such open access to remotely command vehicles to operate dangerously, including attacking multiple vehicles concurrently." Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity? If so, that's the real problem. The vulnerabilities described should not be there in the…

> Which really means auto makers built a terribly insecure system and hope to hide the fact behind security as obscurity?

Yes

(I've reverse engineered the security system on an ABS controller for the top selling vehicle of a major auto manufacturer. It is atrocious. I'm pretty confident the whole reason it exists is so that they can claim they have one to use the DMCA to stop third party tools from interacting with it.)

Re: Automakers try to scuttle Massachusetts ‘right to repair’ law

#40
post #7

Here's a hot take: legislate an airgap between operation control and infotainment/convenience horseshit.

Exactly. The infotainment bullshit should be in zero way connected to the actual operation of the vehicle. There is zero reason why the laggy, nonsensical software that controls my radio should control my engine. Someone correct me if I am wrong, please.

No, your radio has to be able to talk to the engine controller. How else can you get the engine to backfire in time with the beat?
Post reply on HN