Anybody read through http://www.autosec.org/pubs/cars-usenixsec2011.pdf already? My car-tech knowledge is way to rudimentary to get a better idea on that stuff.
>"Anybody read through http://www.autosec.org/pubs/cars-usenixsec2011.pdf already?" To what end? At a glance: * These attacks were demonstrated on a "moderately priced late model sedan" which is surely a bit of a different situation than a brand new luxury car. That could mean more sophisticated systems and likely less time to reverse engineer - assuming you don't believe the manufacturer is complicit. * On page 5 an…
Car electronics change very little year to year. If you have an unreported exploit, it wouldn't surprise me if it were valid for more than 5 production years. The bigger issue is that the networks in these cars are only secured by physical access, and there are more devices on the bus every year.
A remote exploit must fetch a pretty penny, so I would expect professionals to get to work on pre-production units as soon as they are available in the hope that they don't change substantially.
then gain intimate physical access to the vehicle to seed the exploits before eventually remotely exploiting them
I think you read this wrong - the car was disassembled to explore the systems, but after vulnerability development, physical access to a target was not required. This is suggested by "Sniff MAC address, brute force PIN, buffer overflow" and "Call car, authentication exploit, buffer overflow". If modification was required, executing an exploit would involve a predetermined handshake (which is described later in the paper), not something as crude as buffer overflows.