Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

91–100 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#91

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

It uses Bluetooth to stream audio, but everything else happens through a WiFi connection exposed by the car that the phone automatically pairs with after the Bluetooth handshake.

Re: Malware infects Android-based automotive head unit firmware

#92
post #84
post #68

Earlier quoted context omitted.

Headline really quite clearly implies it, though. I think the correction is apt. Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities. Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigera…

It’s no different than how the old Ford Sync or something else could have been compromised. The two big things here in my mind are: 1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out 2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW…

This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.

The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.

Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.

Re: Malware infects Android-based automotive head unit firmware

#93

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.

To avoid charges of libel.

Re: Malware infects Android-based automotive head unit firmware

#94

Earlier quoted context omitted.

Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.

To avoid charges of libel.

In America its not libel if it's true

Re: Malware infects Android-based automotive head unit firmware

#95
post #85
post #2

> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.

Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself

Keep in mind however that the 4G SIM is not there for the driver's benefit, but for Nissan's. It collects extremely invasive telemetry that is then sold to data brokers and consumed by car insurers and government agencies, among others. This is why I won't drive a car that I own without first removing the onboard modem.

Re: Malware infects Android-based automotive head unit firmware

#96
post #94

Earlier quoted context omitted.

To avoid charges of libel.

In America its not libel if it's true

I see nothing at a glance about the author (Dmitry Kalinin) being American, so I can't imagine that is relevant.

Re: Malware infects Android-based automotive head unit firmware

#97
post #92
post #84

Earlier quoted context omitted.

It’s no different than how the old Ford Sync or something else could have been compromised. The two big things here in my mind are: 1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out 2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW…

This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question. The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software…

Do you mean Android Automotive?

Re: Malware infects Android-based automotive head unit firmware

#98

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

It cannot self-propagate to any Android-based head unit Remember that not that long ago viruses spread through floppy disks. Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.

I’ve never met anyone irl who used USB sticks full of music. I know the capability is there in most cars, just never seen it. It seems like Bluetooth capability and Spotify/Apple Music landed in mainstream cars too soon after “play MP3s from USB” was added, for that to catch on.

Re: Malware infects Android-based automotive head unit firmware

#99
post #90
post #49

Earlier quoted context omitted.

Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.

Wow that's cursed, never realized that's how it worked.

Cursed is exactly how I would describe it - because it works great until it doesn’t and it of course gives you zero clue why it won’t connect.

Re: Malware infects Android-based automotive head unit firmware

#100
post #29
post #19

Earlier quoted context omitted.

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.

I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.

A lot of older cars didn't turn off their OBD port, have their headunits go into standby, or even turn off the cigarette lighter port. Early OBD ports connected to dealer computers for a few minutes, not an always on dongle. Plain headunits just play music, what could they possibly accomplish by staying on when you turn off the car? It was a convenience having the cigarette outlet left powered so you could light a cigarette without turning on the car. Other than maybe a bag phone, what would you possibly plug into that?
Post reply on HN