Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

51–60 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#51

"How has the automotive industry adapted to decades of computing best practices?" - Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls - Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps - Keyless entry basically a shit show of faraday pouches - OBD port a…

You had me until you started giving Tesla the thumbs-up, despite your caveat.

Re: Malware infects Android-based automotive head unit firmware

#52
post #19
post #14

Earlier quoted context omitted.

It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit. The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to…

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.

Some of these Android units also double as DVRs and dashcam recorders (parking mode!) as well so may be hooked onto the normal +12v rail.

Re: Malware infects Android-based automotive head unit firmware

#54

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

I thought the latest Bluetooth protocols were basically designed to hand off to an ad-hoc Wi-Fi connection between the two devices after the initial handshake. (Might be an oversimplification of the real protocol)

Re: Malware infects Android-based automotive head unit firmware

#56
post #43
post #41

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...

[flagged]

Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?

Re: Malware infects Android-based automotive head unit firmware

#57
post #43

Earlier quoted context omitted.

[flagged]

Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?

FSB? Oh you mean Russian “Federal Security Service” ?

Re: Malware infects Android-based automotive head unit firmware

#58

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

Wireless AA and CarPlay use a hotspot your car emits that your phone connects to and transfers the image/inputs/audio that way

Re: Malware infects Android-based automotive head unit firmware

#59

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

It cannot self-propagate to any Android-based head unit

Remember that not that long ago viruses spread through floppy disks.

Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.

Re: Malware infects Android-based automotive head unit firmware

#60

Earlier quoted context omitted.

An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?

Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app. I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.

That’s wild, I’ve never run across a head unit that had me connect OBD2. I think I would just ignore that bit of the install instructions.
Post reply on HN