The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…
> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
Malware infects Android-based automotive head unit firmware
91–100 of 154 posts
Re: Malware infects Android-based automotive head unit firmware
#92Earlier quoted context omitted.
Headline really quite clearly implies it, though. I think the correction is apt. Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities. Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigera…
It’s no different than how the old Ford Sync or something else could have been compromised. The two big things here in my mind are: 1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out 2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW…
The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
Re: Malware infects Android-based automotive head unit firmware
#93The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…
Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.
Re: Malware infects Android-based automotive head unit firmware
#94Earlier quoted context omitted.
Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.
To avoid charges of libel.
Re: Malware infects Android-based automotive head unit firmware
#95> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself
Re: Malware infects Android-based automotive head unit firmware
#96Re: Malware infects Android-based automotive head unit firmware
#97Earlier quoted context omitted.
It’s no different than how the old Ford Sync or something else could have been compromised. The two big things here in my mind are: 1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out 2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW…
This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question. The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software…
Re: Malware infects Android-based automotive head unit firmware
#98The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…
It cannot self-propagate to any Android-based head unit Remember that not that long ago viruses spread through floppy disks. Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
Re: Malware infects Android-based automotive head unit firmware
#99Earlier quoted context omitted.
Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.
Wow that's cursed, never realized that's how it worked.
Re: Malware infects Android-based automotive head unit firmware
#100Earlier quoted context omitted.
Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.
I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.