Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

151–154 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#151

Earlier quoted context omitted.

Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app. I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.

That’s wild, I’ve never run across a head unit that had me connect OBD2. I think I would just ignore that bit of the install instructions.

As the other comment points out, if you've installed more than a few, you've definitly connected to the CAN bus.

Few headunits will ask you to connect to the OBD2 port for practical reasons, but the miscilanous manufacturer specific connectors you hook up often include CAN bus connections.

OBD2 port is just 1 of multiple ports with access to the network, even your headlights can be on the bus

Re: Malware infects Android-based automotive head unit firmware

#152

Earlier quoted context omitted.

I did not connect ODB2. The HU I got puts itself as a passthrough to the stock BMW HU (which you still need to be able to use, you switch the screen to its output by holding down a button), and that connector includes CAN. There are numerous reasons the HU needs CAN, for example to get the steering wheel angle to be able to draw the guides over the backup camera feed. Or to switch to the backup camera feed when you p…

It is really exposing the CAN bus, it is not some adjacent subsystem overlaying the steering guides and rearview video by interrupting the video signal? It's actually entirely coming from the aftermarket HU? That's fascinating! I wouldn't expect an aftermarket system to be too good at that functionality, guides tend to be carefully tuned for specific car/steering/camera combos. Ideally most cars should be relying hea…

Yes, the BMW NBT quadlock connector has K-CAN2 (so only body bus, no engine/chassis which is on a different CAN bus). (in true German over-engineering fashion it also has fiber for audio and Ethernet for diagnostics)

I brought up the backup camera as another reason the head unit has CAN, since in my car that's what's handling drawing the backup guide lines.

The aftermarket HU would have enough data to do so, but in my case it doesn't (although it does read CAN for buttons/iDrive). The original HU is still there and functioning, but the aftermarket Android is between the vehicle harness and the original HU with some passthrough and swapping of video cables.

I can hold down the Menu button on my iDrive and the Android HU switches the screen to show the original HU output and I can interact with it normally. And when I put the car into reverse it also switches so I can see the original backup camera feed, then switches back to Android after I drive forward again.

Of course I use none of the Android functionality at all, the whole ridiculous system is solely for CarPlay.

Re: Malware infects Android-based automotive head unit firmware

#153

"How has the automotive industry adapted to decades of computing best practices?" - Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls - Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps - Keyless entry basically a shit show of faraday pouches - OBD port a…

I don't know tesla cars. I absolutely agree with the rest of your points

Re: Malware infects Android-based automotive head unit firmware

#154

Earlier quoted context omitted.

Up until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection,…

KL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90's and early 2000's, together with some of their then-rivals like Dr. Web. There's a reason they were trusted, and there's a reason they tried to deny their takeover, they have a genuinely earned reputation. This doesn't mean they aren't a FSB branch, in the same way e.g. NSO Group is a Mossad b…

Kaspersky isn't just a credible lab. They were, and remain, the best antivirus provider, by their results on basically any and all test batteries. Similarly their founder (Eugen Kaspersky - I assume who you are referencing with "YK") has never worked for the KGB. He was educated at at a KGB affiliated school and afterwards went to work for the Ministry of Defense. Within a few years the USSR collapsed and he then went, and stayed, within the private sector.

But most importantly - companies (let alone other governments) providing detailed information on how other governments' cyber operations is most certainly not a thing that's done. That report I linked to is not just speaking in evidence free vagaries of the geopolitical 'leak' type you are alluding to. It provided extensive operational details and includes things such as even naming a specific driver as which is implied as being a Windows backdoor with plausible deniability.

They chose to publish it letting the NSA know exactly which methods had been discovered, how they were discovered, and even exact versions they detected and potentially on exactly which machines (if the NSA salts binaries), given that the hash/date info were also provided. All of this is immensely valuable information that could have been both weaponized and 'defensized' for Russian cyber purposes. Providing it helped the NSA more than anybody. Outside of Trumpian 5d chess, there's no rational explanation for this, if one assumes they are in any meaningful way controlled by the Russian government.

Post reply on HN