Live data from Hacker News

Honda Civics and the Evil Valet

juniperspring.org

31–40 of 105 posts

Re: Honda Civics and the Evil Valet

#31

If I'm reading the room, the sentiment is Honda is incompetent and their cars are security holes on wheels. But if the opposite happened, they would be technofascists locking us out of our own cars, a 30 post sub-thread "this is why I drive a 1999 Ford Ranger" would ensue, and someone would be investigating it as a possible GPL violation. Do I have this right? It's also a good assumption most people airing such compl…

[deleted]

Re: Honda Civics and the Evil Valet

#34
Most (if not all) cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics. What makes this even worse is the sensors they have onboard these days; the microphones, cameras, GNSS receivers, wifi and BT radios make them into mobile surveillance platforms.

In March 2026, a bunch of controls were added to the Australian Government Information Security Manual[0] basically instructing people to not connect government devices to the infotainment systems of any vehicles, or to view or discuss anything sensitive in the presence of one.

> Security Control: 2099; Revision: 0; Updated: Mar-26; Marking: NC, OS, P, S, TS Mobile devices are not connected to the infotainment systems of connected vehicles.

> Security Control: 2100; Revision: 0; Updated: Mar-26; Marking: NC, OS, P, S, TS Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.

> Security Control: 2101; Revision: 0; Updated: Mar-26; Marking: NC, OS, P, S, TS Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.

[0] https://www.cyber.gov.au/business-government/asds-cyber-secu...

Re: Honda Civics and the Evil Valet

#35
post #22

IMHO this is a good sign(!?) that they didn't even think about locking down their systems against the owner.

It's not good that they allow anyone that happens to be in your car briefly root access. It'd be live having an always-on laptop in your office with a open shell on it. They should have provided some mechanism for the real owner to approve updates if the updates aren't all trusted by default.

Who cares? The valet could do any number of other attacks, like stealing the car, sabotage, adding a tracker, whatever. Threat modeling is important, otherwise security can harm one's own goals. Sometimes you have to briefly trust another person. I'd rather have an open shell inside a locked room when the alternative is no access at all.

Re: Honda Civics and the Evil Valet

#36
post #26
post #15

Wonder how good the rest of the security is. The head unit is likely hooked up to a CAN gateway, can it call into telematics. Maybe find some novel way to abuse carplay/aa to call home.

If you have physical access to a car and want to phone home, may I recommend leaving a gps tracking device under the floormat. It works on more brands of cars too than just one gen of honda civics, and probably quicker to install.

Ah but that is expensive and introduces risk of being caught doing clandestine. It is much more convenient to just use the one already installed and accepted.

In fact, put away all this physical access nonsense and just buy it from the data broker.

Re: Honda Civics and the Evil Valet

#38
In one thread people fighting the ever decreasing amount of hw ownership of most devices in our lives and when we have one that is more open, the crowds come to attack that too.

The theat model with tech has always been that if an attacker has physical access to the device and time then it's game over.

Re: Honda Civics and the Evil Valet

#39

In one thread people fighting the ever decreasing amount of hw ownership of most devices in our lives and when we have one that is more open, the crowds come to attack that too. The theat model with tech has always been that if an attacker has physical access to the device and time then it's game over.

Because it's not open for modification by the general public? (emphasis general, not just technically minded people)

Manufacturers need to pick a lane - either fully open, and then people who need it can harden their own stuff (and at least be aware of the tradeoff), or fully closed and secure.

This in-between where cars are invasive privacy nightmares that spy on you at all driving hours, and are insecure nightmares that will give up that data to anyone remotely invested, is the worst case scenario, obviously.

Re: Honda Civics and the Evil Valet

#40
post #2

To update 10th-gen Honda Civics, Honda ships updates on specially-formatted USB drives. They're essentially Android 4.2.2rc1-era recovery packages with some Honda-added version checks (which can be spoofed). The packages are signed with the publicly-known AOSP test key, so with physical access to the front USB port you can sign and flash your own package for arbitrary code execution on the headunit. This doesn't requ…

A number of other cars' infotainment systems are also based on ASOP. I remember downloading updates for my Hyundai which were also essentially Android images

based on aosp was not the notable part
Post reply on HN