News: 1586442013

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Consumer reviewer Which? finds CAN bus ports on Ford and VW, starts yelling 'Security! We have a problem...'

(2020/04/09)


Modern connected cars contain security threats, consumer org Which? has said after commissioning analyses of two models, a Ford and a Volkswagen.

While Which?'s insistence that the flaws are "serious" is perhaps wide of the mark, the research does highlight the lack of robust security features protecting CAN buses and in-vehicle infotainment (IVI) from malicious people.

Researchers from Context Information Security were able to find their way into two cars' infotainment units, the dash-mounted screen that displays everything from car information to GPS-based moving maps to your favourite radio station or motorway playlist.

"While the cars proved more difficult to hack into than many connected products, Context researchers managed to find weaknesses in the cars' security designs and were even able to identify what is suspected to be a Wi-Fi password from Ford's manufacturing plant," said Context in a separate statement from Which's one.

The Ford model it looked at was a Focus Titanium Automatic 1.0L petrol model, while the VW was a Polo SEL TSI Manual 1.0L, also the petrol-powered variant.

Context found that "simply lifting the VW badge on the front of the car gave access to the front radar module, which could potentially allow a hacker to tamper with the collision-warning system." That is, someone malicious could pull the radar sensor out.

Ian Tabor, a security-focused network architect who runs Car Hacking Village UK, told The Register : "The access to the ADAS radar system wiring could potentially give access to the CAN network that controls the security of the vehicle depending on how the CAN networks are segregated, not just affect the collision warning system."

Seeing as the VW is not a Tesla and is not marketed as having an "autopilot" that helps you drive, disabling the radar transceiver reduces safety back to the level of older cars, driven (mostly) successfully by qualified humans who watch the road ahead. Nonetheless, a criminal with time, knowledge and physical access to the target network (the car) is a very real infosec threat.

Meanwhile, Context's bods were also probing the Ford's CAN bus and items connected to it. Its IVI was "connected to three separate buses, including the powertrain," which the researchers said "could potentially give access to engine controls."

Both cars' wireless key locking systems were vulnerable to relay and replay attacks, a well-known problem gleefully [1]exploited by car thieves and largely ignored by industry despite having been a known issue for years.

Remarking on what the study did not appear to have looked at, Tabor commented: "There is no mention of the EU mandated E-Call system that could potentially be tracking the vehicle at all times?"

Nonetheless, Context did say it had found what looked very much like a Ford factory Wi-Fi password saved in that car's IVI, presumably from factory testing.

Inevitably, Which", which describes itself as a "consumer champion" demanded more "regulations" on CAN bus security to reduce what it claimed was "the risk, both to financial and to human life." It is unclear exactly how Which? reached that conclusion, with its study not detailing any direct interference with safety-critical systems it was able to achieve. At most it was able to suggest that tyre pressure sensors could indicate a flat tyre was fully pumped up.

Most drivers are probably capable of noticing if one or more tyres is flat or running on the wheel rim, El Reg suggests, knowing full well commenters will now flood the comments section with Police! Camera! Action! clips to prove us wrong.

Previous infosec research directed at cars has made [2]similar findings over the years .

Nonetheless, Which won't have endeared itself to either the security or automotive industries. VW [3]denied to ITV that compromising the IVI could lead to control over safety-critical systems, while Ford reportedly refused to accept delivery of the Which? report at all. ®

Carnote

In a thoughtful gesture, car hacker chap Tabor gave us his top tips for connected car security:

Wiping data from the vehicle IVI may only delete the data from the frontend; the data still may be in the car's internal database.

Revoke access when selling your car. This may require going through the manufacturer's website. You may again also want to delete any data from the website so that data isn't available to the next user or the manufacturer.

Resellers of used cars should also check the previous owner has removed their data, whether the reseller is a main dealer, auction, small reseller or private seller.

When renting or leasing just don't connect your car to Bluetooth devices without checking what data is being transmitted and how you can access it to wipe it from the car later on.

Never set home/work in the car's GPS. If you lose your keys or criminals steal them and pinch the car too, they could then find your house or workplace for a followup burglary.

Check the Onboard Diagnostics 2 (OBD2) port for tracking devices if you're worried about your physical security.

Sponsored: [4]Forrester Build a Digital Experience Portfolio



[1] https://www.bracknellnews.co.uk/news/18350930.keyless-car-thief-drives-bmw-off-driveway-bracknell/

[2] https://www.theregister.co.uk/2018/03/10/auto_manufacturers_are_asleep_at_the_wheel_when_it_comes_to_security/

[3] https://www.itv.com/news/2020-04-09/security-flaws-in-ford-and-vw-connected-cars-could-pose-risk-to-drivers-which/

[4] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936

Oneman2Many

Thank the EU for stopping encryption of the CAN bus.

Also need access to the bus to begin with.

Don't worry, I am sure OTA updates will be fine.

Wellyboot

An encrypted CAN bus would kill non dealer servicing overnight as the manufacturers decide to rent out diagnostic equipment for £000's per month.

You're spot on with the access though, the car wifi & entertainment has to be air gapped from any safety critical system.

Alister

Most drivers are probably not capable of noticing if one or more tyres is flat or running on the wheel rim, El Reg suggests

TFTFY

Giles C

Given what I have seen on the roads

I think there are some drivers that would fail to notice if there car was sat on by an elephant.

The best one was a car that created its own smokescreen the back was completely covered in soot, or the one where two wheels were flat.

So most people are completely unaware of what there car is doing.

fuzzie

Did I read this correctly that their issue with the VW was that the could remove the radar sensor?

Did they least try and do something more interesting like replace it with a malicious one or one that spewed out bad/faulty measurements? Being able to remove a sensor doesn't seem like such a 'leet hack or huge vulnerability.

Paul Shirley

The not well enough flagged (apparently) issue is you can possibly connect to CAN from it and do it without breaking into the car.

vilemeister

Its 'reviews' like this that will make the car manufacturers pot the entire engine bay in resin so can't remove something, and then you also have to go to them to get it repaired/a new engine installed.

Sil

Ford refusing to read the report shows Which is definitely not wrong.

It's just like the absolute joke of the security of medical equipment: it interests nobody, until some organization will give us a nasty wake-up call.

CAN + security != CAN and would break things

My other car WAS an IAV Stryker

"The lack of robust security features protecting CAN buses" was intentional to make sure any semi-idiot can wire up this engine and that transmission and so-and-so's ABS and eventually come up with a working drivetrain without being a cryptosecurity expert or needing signed keys, licenses, or proprietary tools.

(Yes, SOME proprietary tools are needed, but any CAN transceiver and parsing software built to the published standards should read 90% of CAN busses and all contents not using the Proprietary-flagged data frames. And those Prop frames can still be recorded even if the raw binary/hex is meaningless without further definition.)

"Nonetheless, a criminal with time, knowledge and physical access to the target network (the car) is a very real infosec threat." Physical access is ALWAYS the discriminator when it comes to CAN. There is no issue as long as the air-gap is maintained.

Do there need to be improvements within the industry? YES.

Does it need to be a multi-corporate effort? Absolutely.

Would it increase processing overhead within every single device on the bus and increase power consumption and device cost? You betcha. Every bus, every device, and every message would have to be strongly encrypted. Any bus-connected device that can be forced into non-encrypted mode is a vulnerability. Any tool that can do that for maintainers/technicians becomes a tool for criminals also. Any decryption must happen internal to the device/tool.

But... Any all-access keys used for the tools are essentially a backdoor that can and will be eventually leaked. And if the devices make keys randomly on every power-up and/or after certain time intervals (which can also be randomized), then the tools will be broken and can't parse bus traffic.

I don't know the solution, but so many vehicles--passenger, commercial, and "other"--are currently vulnerable.

Re: CAN + security != CAN and would break things

Bogbody

Encryping the canbus data leads to one thing - the vehicle is eventualy not repairable. A wonderful piece of planned obselesance.

I point the reader in the direction of Vauxhaul/opel following the PSA takeover.

How long before the relevant servers become unavailable and the canbus cant be read, decrypted or modified. Several modules on the Astra (for example) cant be serviced/replaced without access to the central server.

Indeed updates for the infotainment/satnav system have allready dried up.

No update is available that shows the new A14 around Huntingdon ( yes, yes read the f@$king roadsigns). What other module have or will develop a bug that needs an update (well the auto lights on function for a start!)

Cars made before about 2005 can be fixed with mechanical and electrical skills.

Todays cars would also need a crypro and software engineer.

Re: CAN + security != CAN and would break things

boltar

"Todays cars would also need a crypro and sodtware engineer."

Unfortunately the manufacturers are simply giving idiots all the Shiny Shiny toys that they want. Why anyone wants all the bells in whistles in a car beyond a basic ICE when a phone can do all the same functions better beats me, but there we are. For now I'm sticking with my 12 year old car with analogue dials, a radio, CD player and nowt else.

Re: CAN + security != CAN and would break things

Anonymous Coward

Couple notes;

* encryption doesn't have to be an all or nothing affair, even on a given CAN bus. At least one manufacturer does a mix of completely clear coms, encrypted coms, and communication with secure checksums (so data is easy to read but hard to forge... secure data is also timestamped to defeat replay attacks).

* symmetric encryption keys that are unique to a given vehicle work. Keys are stored at a central repository maintained by the manufacturer so that diagnostic tools can update replacent parts (obvious weakpoint, but much better than a single master key).

* there are industry standard tools to manage all of this. See AUTOSAR for one example. Automotive ECU software is hugely modular and model driven (essentialle nobody "writes code" in automotive as much as you write specs, build models, and let the tools build the software).

As mentioned, physical access eventually wins.

Source: I make a living speaking CAN to modules that don't always come with documentation. Job includes making a given part think its going down the highway in a vehicle even though it's sitting on a tester.

a known issue for years?

Mike 16

"Keyless entry" has been a thing for _decades_, and I recall that handy capture/replay devices were available to thieves within months.

Meanwhile, the advice to not pair ones Bluetooth devices to random rental cars is good, but ignores that some modern cars (I refrain from naming the maker, as I suspect my new car is snooping all my comms :-) will pair with a device (such as my iPhone) without asking for or getting permission.

Lies! All lies! You're all lying against my boys!
-- Ma Barker