Live data from Hacker News

Honda Civics and the Evil Valet

juniperspring.org

41–50 of 105 posts

Re: Honda Civics and the Evil Valet

#41
post #19
post #2

To update 10th-gen Honda Civics, Honda ships updates on specially-formatted USB drives. They're essentially Android 4.2.2rc1-era recovery packages with some Honda-added version checks (which can be spoofed). The packages are signed with the publicly-known AOSP test key, so with physical access to the front USB port you can sign and flash your own package for arbitrary code execution on the headunit. This doesn't requ…

> AOSP Android Open Source Project for those outside the bubble!

[flagged]

Re: Honda Civics and the Evil Valet

#44
post #22

Earlier quoted context omitted.

It's not good that they allow anyone that happens to be in your car briefly root access. It'd be live having an always-on laptop in your office with a open shell on it. They should have provided some mechanism for the real owner to approve updates if the updates aren't all trusted by default.

Who cares? The valet could do any number of other attacks, like stealing the car, sabotage, adding a tracker, whatever. Threat modeling is important, otherwise security can harm one's own goals. Sometimes you have to briefly trust another person. I'd rather have an open shell inside a locked room when the alternative is no access at all.

You would notice if someone stole your car though.

Re: Honda Civics and the Evil Valet

#45

Most (if not all) cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics. What makes this even worse is the sensors they have onboard these days; the microphones, cameras, GNSS receivers, wifi and BT radios make them into mobile surveillance platforms. In March 2026, a bunch of controls were added to the Australian Government Information Security Manual[0] basi…

Isn't NC the absolute lowest in the sensitivity system?

Re: Honda Civics and the Evil Valet

#46

In one thread people fighting the ever decreasing amount of hw ownership of most devices in our lives and when we have one that is more open, the crowds come to attack that too. The theat model with tech has always been that if an attacker has physical access to the device and time then it's game over.

Because it's not open for modification by the general public? (emphasis general, not just technically minded people) Manufacturers need to pick a lane - either fully open, and then people who need it can harden their own stuff (and at least be aware of the tradeoff), or fully closed and secure. This in-between where cars are invasive privacy nightmares that spy on you at all driving hours, and are insecure nightmares…

they can set it up to be secure by default and allow bootloader unlock like most android phones. if theres some form of owner authentication before you unlock evil maid attacks are impossible. you also need the ability to do a clean system reset and lock it again as many times as you want (no e-fuse, sorry samsung knox) so its safe to buy a used car even if the previous owner installed some spyware. all of that is tech that exists today.

Re: Honda Civics and the Evil Valet

#47

If I'm reading the room, the sentiment is Honda is incompetent and their cars are security holes on wheels. But if the opposite happened, they would be technofascists locking us out of our own cars, a 30 post sub-thread "this is why I drive a 1999 Ford Ranger" would ensue, and someone would be investigating it as a possible GPL violation. Do I have this right? It's also a good assumption most people airing such compl…

No, this is a false dichotomy. It's not either "open to anyone" or "secure from anyone". There are various ways to ensure that only the owner can unlock the software, eg requiring a waiting period before unlocking.

Re: Honda Civics and the Evil Valet

#48

In one thread people fighting the ever decreasing amount of hw ownership of most devices in our lives and when we have one that is more open, the crowds come to attack that too. The theat model with tech has always been that if an attacker has physical access to the device and time then it's game over.

We can definitely see that on windows with the recent bitlocker exploit. I wonder if any new cases will be solved, or people imprisoned because of hardware in storage that can now be unlocked.

It's definitely better to not keep data locally if it's going to be seized, because of varying laws that can coerce unlocking, but in the U.S., it should be safe to refuse to give up passwords.

On the technical side, Google and Apple have changed the game with numerous improvements to physical security and GrapheneOS takes it even further building on their foundation reducing attack surface and adding good features. Particularly with Auto reboot[1] becoming widely adopted, your conclusion can be modified on phones.

[2]:

>This (https://osservatorionessuno.org/blog/2026/05/demystifying-ph...) is an article by an Italian non-profit that provides an introductive technical overview to forensic phone unlocking exploit kits used by governments and law enforcement, most notably Cellebrite.

>This post provides an overview on how disk encryption works on Android, common attack vectors used by forensic tools to brute force or extract a device, their countermeasures against popular security features like automatic reboot in iOS and how you can protect yourself against such tools, including several mentions about GrapheneOS.

[1] https://grapheneos.org/features#auto-reboot

[2] https://discuss.grapheneos.org/d/35728-demystifying-phone-un...

Re: Honda Civics and the Evil Valet

#49
I wish other car makers were as reasonable as Honda here.

No "evil valet" with half a brain cell would waste time hacking the head unit if they have physical access to the car. They would simply hide a spying device somewhere in the car.

Not to mention that people with Civics are never targets of three letter agencies.

Re: Honda Civics and the Evil Valet

#50
post #45

Most (if not all) cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics. What makes this even worse is the sensors they have onboard these days; the microphones, cameras, GNSS receivers, wifi and BT radios make them into mobile surveillance platforms. In March 2026, a bunch of controls were added to the Australian Government Information Security Manual[0] basi…

Isn't NC the absolute lowest in the sensitivity system?

The point is that they want all government employees/politicians/contractors etc to understand the risks of on-vehicle electronics.
Post reply on HN