Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

31–40 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#31
post #21

There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872

An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?

Re: Malware infects Android-based automotive head unit firmware

#32
post #16

For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ? I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently). Also, feel like John Gruber is going to…

Android Automotive is the infotainment system’s OS and runs fully without a phone. Android Auto is the Google equivalent of CarPlay and runs on your phone. It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.

So I can use android auto on an android automotive head unit - got it but also this seems needlessly confusing naming structure. Apple TV comparison is apt lol

Re: Malware infects Android-based automotive head unit firmware

#33
Can't be safer than the non-entertainment system from WV Up! that's just a built-in head mount for your phone. Grab one with a large screen and it's the safest thing you can get. Android still has an auto mode for this where it controls the car's audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it's safer too

Re: Malware infects Android-based automotive head unit firmware

#34
post #21

There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872

An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?

Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app.

I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.

Re: Malware infects Android-based automotive head unit firmware

#35
post #21

There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872

An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?

Can't vouch for all car architectures, but in most cases the head unit is QM and safety domains are usually segmented from each other. So even if the head unit talks CAN (it needs to get car data somehow) it will only communicate with the rest of the car through a gateway that will not allow it to take any dangerous actions.

Re: Malware infects Android-based automotive head unit firmware

#36
"How has the automotive industry adapted to decades of computing best practices?"

- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls

- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps

- Keyless entry basically a shit show of faraday pouches

- OBD port allowing thieves to clone a full key in seconds

- Even cars in decent neighbourhoods have to use steering locks

Sorry but this is a fucking joke and the automotive industry is cancer.

At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.

All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.

Re: Malware infects Android-based automotive head unit firmware

#38
post #21

There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872

Manufacturers should be sued to absolute oblivion for doing what any developer would tell you is a security hole.

Re: Malware infects Android-based automotive head unit firmware

#39
post #19
post #14

Earlier quoted context omitted.

It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit. The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to…

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.

They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.
Post reply on HN