Live data from Hacker News

Honda Civics and the Evil Valet

juniperspring.org

101–105 of 105 posts

Re: Honda Civics and the Evil Valet

#101
post #88
post #78

Earlier quoted context omitted.

How do you validate “the real owner” if having the keys isn’t enough? That sufficient to steal the car. You could do a PIN/password, but if it is never used during operation, nobody will know it. Ask anyone who’s had a head unit that needed a PIN after losing power.

Mere possession is also enough for someone to steal your laptop, but that still shouldn't allow them to trivially install a secret persistent backdoor, or break your disk encryption. Agree that a PIN/Password would have usability problems with a car. Since no car manufacturer intentionally permits you to install software you want, there's no standard mechanism. But if this was standard I think an owner-set PIN would…

As someone who bought a used car with a weird head unit integration to set car features, behind a pin, and who was never able to get the pin (previous owner forgot, wasn’t written down, no clear path to reset)… I think it’s not a great solution.

Some cars have special valet keys, which prevent aggressive driving and high speeds, and maybe that’s the solution? But of course it means remembering to bring the special key.

Maybe the answer is just to look at loaning your car the same as handing your unlocked laptop to someone.

Re: Honda Civics and the Evil Valet

#102

Earlier quoted context omitted.

Not sure if you’re being sarcastic/satirical or not. If you are, fine. But if you’re not - why would someone driving a civic not be a target of an intelligence agency? It’s one of the most common cars about there, so if you want to fade into the background it’s a perfect car. Also, lots of otherwise “normal” people - scientists, engineers, journalists, lawyers - likely drive Honda civics. A spying device hidden in th…

Whenever we get to talking about three letter agencies, i wish people spent more time thinking about their threat model. Is the TLA surveilling me because they're broadly interested in everybody? OK then, the return on investment isn't there to pull an evil maid attack on public randos. If the TLA is interested in you because of who you specifically are, the average individual can't begin to plug all the possible hol…

Everyone should have security robust against nation-state actors by default in the most popular consumer products, so that people who need it can hide in the masses. I hope LLM-assisted “offensive security research” makes insecure software fully unusable so that companies finally take security seriously.

Re: Honda Civics and the Evil Valet

#103
post #70

Earlier quoted context omitted.

Okay, what is fully open? Do you really think the head unit developer would hand you over a huge developer documentation about every bit in the software? I'm freelancer and helped to develop some head units. I have a surprize for you: This documentation mostly doesn't exsists. Most of the time there are some chip datasheets and requirement documents, depending on the customer(car manufacturer) they are good or bad an…

I mean, yes. I would like to know that because it’s an unacceptable state of affairs from my perspective. If the production line relied on just always having someone working who remembered things instead of a proper solution to the Hit By a Bus problem I wouldn’t be buying that brand. It is my anecdata, uninformed opinion much of IT for cars is below average development. I started to wonder about this when I got a ho…

Oh, don't understand me wrong. I've never seen a better organized embedded development process than in automotive. Review rules, reproducable builds, sometimes good unit tests(not just senseless stupid shit that wastes developer time), a test department in another room that develops test software to automate hardware in the loop tests, huge hardware in the loop test rigs that are running the newest build 24/7. IT in cars is all other than below average. It's not the move fast and break things shit of silicon valley. And it's not the 'we ship it with the next update' shit of the game industry.

BUT, there is no documentation because there is no time to do it. There are SOP-1(Start of Production). This date is carved in stone. When a feature is not done for SOP-1, than it is not delivered in SOP-2. SOP-2 happens normally 6 month later. After that, updates are only done when something bad happens. The complete team moves on to the next head unit.

So, I would expect your bugs will not get fixed in any way, at least when they are not important enough to mobilize a new small team or some people that worked on it to fix them. Normally shortly before SOP-2, all tickets are closed, known bugs too. That feels a little frustrating as customer, but more as developer.

Oh, and don't think that you can run away from that by buing another brand. Normally not your car manufacturer develops the head unit. It's other companies and they work all the same and they work for all car companies.

Re: Honda Civics and the Evil Valet

#104
post #9

Hyundai head units at one point used an RSA key you got by googling “RSA key” (no joke: https://programmingwithstyle.com/posts/howihackedmycar/ ), an honestly even more amazing mistake since it required effort rather than just a default.

[deleted]

Re: Honda Civics and the Evil Valet

#105
post #82

Earlier quoted context omitted.

I'm hoping this comment is a joke? It's kind of nonsensical. > I wish other car makers were as reasonable as Honda here. I doubt they did this on purpose. > No "evil valet" with half a brain cell would waste time hacking the head unit if they have physical access to the car. Keep in mind that head units usually also contain historic data; stuff like left-over synced phone contacts in SQLite databases, historic locati…

> ??? People who drive Civics are boring, normal people with boring, normal lives. Not of any interest to the NSA.

John Cena drives a Civic Type R famously :)
Post reply on HN