Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

41–50 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#41
post #28

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

Indeed this is an odd disclosure and I am not familiar with past posts by them. Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.

https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...

Re: Malware infects Android-based automotive head unit firmware

#42

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit

Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

Re: Malware infects Android-based automotive head unit firmware

#43
post #41
post #28

Earlier quoted context omitted.

Indeed this is an odd disclosure and I am not familiar with past posts by them. Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.

https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...

[flagged]

Re: Malware infects Android-based automotive head unit firmware

#44
post #21

There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872

The car hacker's handbook [1] has a chapter on just using the infotainment system to access the CAN. Specifically mentions "attacking through the update system".

[1]https://opengarages.org/handbook/ebook/ (chapter 9)

Re: Malware infects Android-based automotive head unit firmware

#45

    Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month *
    * Cars without subscription causes acceleration to be restricted to 60mph.
After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.

Re: Malware infects Android-based automotive head unit firmware

#48

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

The way I understand it, the connection is negotiated via BT, but then wifi is used for the fat data pipe to run the display.

Re: Malware infects Android-based automotive head unit firmware

#49

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.

Re: Malware infects Android-based automotive head unit firmware

#50
post #29
post #19

Earlier quoted context omitted.

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.

I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.

If that was one of those ELM327 dongles, yes they have 12V and are known to drain your battery. They're only meant for short diagnostic runs.
Post reply on HN