

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- So to do this the attacker has to compromise the update servers at $CAR_COMPANY?by MBCook
- no, the update servers at $sketchy_aliexpress_aftermarket_head_unit_company, probably somewhat easierby timmmmmmay
- One more reason cars should not be internet connected. They last for decades and manufactures don't want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.by bluGill
- ..to add to a botnet for click fraud.
The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
by 1970-01-01 - > Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads.
Somehow I doubt it. They're ripe for ransomware attack.
by chrisjj - I'd not consider it malware if its sole purpose is to do ad/click fraud. The user is not the target here, the user's enemies are :)by zb3
- Can't be safer than the non-entertainment system from WV Up! that's just a built-in head mount for your phone. Grab one with a large screen and it's the safest thing you can get. Android still has an auto mode for this where it controls the car's audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it's safer tooby gchamonlive
After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month * * Cars without subscription causes acceleration to be restricted to 60mph.by doublerabbit- Even from this perspective, it's pretty easy to make things more secure by having less technology. Have the infotainment system just be a blank canvas for Carplay or AA to display on (there does need to be a bit back and fourth, phone needs to send audio to car, car needs to send GPS, speed and state of charge to phone (not strictly necessary, but there are user benefits from the phone having this information). The car itself doesn't need a whole internet-connected general purpose computer attached to it, but doing that is an easy way for the manufacturer to supposedly add value.
Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don't need to be general purpose computing devices either. I shouldn't have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).
by Telaneo - The logical endpoint of the entire "the car as software" concept. Can't wait for the security vendors to start hawking "AV for your car"by davoneus
- It's already in televisions. Not long now.by doublerabbit
- I hope we see "de-smartification" conversion kits that replace the electronics with more straightforward (and repairable) offline equivalents. The ultimate AV.by Retr0id
- "How has the automotive industry adapted to decades of computing best practices?"
- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls
- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps
- Keyless entry basically a shit show of faraday pouches
- OBD port allowing thieves to clone a full key in seconds
- Even cars in decent neighbourhoods have to use steering locks
Sorry but this is a fucking joke and the automotive industry is cancer.
At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.
All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
by jiaosdjf - I don't know tesla cars. I absolutely agree with the rest of your pointsby newtwentysix
- > "How has the automotive industry adapted to decades of computing best practices?"
Simple. It hasn't.
by Telaneo - You had me until you started giving Tesla the thumbs-up, despite your caveat.by smilespray
- For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ?
I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).
Also, feel like John Gruber is going to have a field day with this one
by jackdecker - I don’t believe this is Android auto running from a phone, but a situation where the manufacturer have used Android Automotive as operating system for the built in head unit. As e.g. on Volvo’s.by dybber
- Android Automotive is the infotainment system’s OS and runs fully without a phone.
Android Auto is the Google equivalent of CarPlay and runs on your phone.
It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.
by MBCook - There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872by dzdt
- Manufacturers should be sued to absolute oblivion for doing what any developer would tell you is a security hole.by jiaosdjf
- An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?by 01100011
- The car hacker's handbook [1] has a chapter on just using the infotainment system to access the CAN. Specifically mentions "attacking through the update system".
[1]https://opengarages.org/handbook/ebook/ (chapter 9)
by Ccecil - > Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet
People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
by Retr0id - "Pairing" with a head unit is not an open socket to dump anything you care to down the wire. That would require finding a rather remarkable vulnerability in one of the audio/address book/screen mirroring APIs the devices use.by ghostly_s
- Also cars are often near other cars. Which offer wireless connectivity. Car software is almost never updated and is years old.
Nothing could go wrong.
by dolmen - Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itselfby madduci
- It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit.
The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!
by kotaKat - Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists.
Just off the top of my head.
by buckle8017 - Almost, though I understand I am the exception rather than the rule: Personally I have an aftermarket android head unit since the standard one was incredibly basic, no real time navigation updates, updating maps was a pain in the ass and so on. Initially I did pair it with my phone but since it is an aftermarket unit from a company which apparently does not exist anymore, newer phones cannot be paired with it. So my only option was to go the opposite route and use my phone as a wireless hotspot(almost - there's a raspberry pi with openwrt between the two). And since I self-host everything, I had no choice but to hook it up to my vpn. That said, I understand the implications of doing this so ultimately the network access it gets is incredibly limited: everything that is not my music server and the maps provider has been cut off completely. The downside is that every now and then I get a "can't connect to google services" notification though that is technically reassuring from a security perspective.by axegon_