Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

71–80 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#71

Earlier quoted context omitted.

An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?

Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app. I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.

> speedometer/rpm

This is available on standard OBD-II. Maybe, it is accessible over CAN?

Re: Malware infects Android-based automotive head unit firmware

#72

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

This makes me think whether the whole chain is an intelligence side business — sell cheap electronics for profit and at the same time own them too.

Re: Malware infects Android-based automotive head unit firmware

#73
post #57

Earlier quoted context omitted.

Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?

FSB? Oh you mean Russian “Federal Security Service” ?

As it says in the first line of the WP article: "Federal Security Service (FSB)"

Re: Malware infects Android-based automotive head unit firmware

#74
post #39
post #19

Earlier quoted context omitted.

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.

They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.

You would hope that the ignition switch really cuts the power to the head unit when it is switched to off.

Re: Malware infects Android-based automotive head unit firmware

#75

"How has the automotive industry adapted to decades of computing best practices?" - Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls - Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps - Keyless entry basically a shit show of faraday pouches - OBD port a…

> "How has the automotive industry adapted to decades of computing best practices?"

Simple. It hasn't.

Re: Malware infects Android-based automotive head unit firmware

#76
post #43
post #41

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...

[flagged]

The article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.)

> “sources said”

Yes, that's how Wikipedia works. https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_vie...

Re: Malware infects Android-based automotive head unit firmware

#77

Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month * * Cars without subscription causes acceleration to be restricted to 60mph. After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.

Even from this perspective, it's pretty easy to make things more secure by having less technology. Have the infotainment system just be a blank canvas for Carplay or AA to display on (there does need to be a bit back and fourth, phone needs to send audio to car, car needs to send GPS, speed and state of charge to phone (not strictly necessary, but there are user benefits from the phone having this information). The car itself doesn't need a whole internet-connected general purpose computer attached to it, but doing that is an easy way for the manufacturer to supposedly add value.

Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don't need to be general purpose computing devices either. I shouldn't have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).

Re: Malware infects Android-based automotive head unit firmware

#78
post #21

There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872

An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?

Many do - the one I was looking at for my vehicle in particular uses it to restore the steering wheel controls (which are broadcast over the CAN-B low speed bus)

Re: Malware infects Android-based automotive head unit firmware

#79

Earlier quoted context omitted.

Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app. I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.

> speedometer/rpm This is available on standard OBD-II. Maybe, it is accessible over CAN?

My OBD-II connector has CAN-C (500kbit) and CAN-B (50kbit) - I use CAN-B primarily because I can control windows, doors, etc + get the speed & rpm.
Post reply on HN