CAN do attitude: How thieves steal cars using network bus
- Reference: 1680777249
- News link: https://www.theregister.co.uk/2023/04/06/can_injection_attack_car_theft/
- Source link:
It all started when a Toyota RAV4 belonging to one of the tech gurus suffered suspicious damage to the front wing and headlight housing, and was eventually successfully stolen. Some sleuthing and reverse engineering revealed how the motor was finally nicked.
Ken Tindell, CTO of Canis Automotive Labs, said the evidence pointed to thieves' successful execution of a so-called CAN injection.
[1]
A Controller Area Network (CAN) bus is present in nearly all modern cars, and is used by microcontrollers and other devices to talk to each other within the vehicle and carry out the work they are supposed to do.
[2]
[3]
In a CAN injection attack, thieves access the network, and introduce bogus messages as if it were from the car's smart key receiver. These messages effectively cause the security system to unlock the vehicle and disable the engine immobilizer, allowing it to be stolen. To gain this network access, the crooks can, for instance, break open a headlamp and use its connection to the bus to send messages. From that point, they can simply manipulate other devices to steal the vehicle.
"In most cars on the road today, these internal messages aren't protected: the receivers simply trust them," Tindell detailed [4]in a technical write-up this week.
[5]
The discovery followed an investigation by Ian Tabor, a cybersecurity researcher and automotive engineering consultant working for EDAG Engineering Group.
It was driven by the theft of Tabor's RAV4. Leading up to the crime, Tabor noticed the front bumper and arch rim had been pulled off by someone, and the headlight wiring plug removed. The surrounding area was scuffed with screwdriver markings, which, together with the fact the damage was on the kerbside, seemed to rule out damage caused by a passing vehicle. More vandalism was later done to the car: gashes in the paint work, molding clips removed, and malfunctioning headlamps.
A few days later, the Toyota was stolen.
[6]
Refusing to take the pilfering lying down, Tabor used his experience to try to figure out how the thieves had done the job. The MyT app from Toyota – which among other things allows you to inspect the data logs of your vehicle – helped out. It provided evidence that Electronic Control Units (ECUs) in the RAV4 had detected malfunctions, logged as Diagnostic Trouble Codes (DTCs), before the theft.
According to Tindell, "Ian’s car dropped a lot of DTCs."
[7]Tesla Semi, out since December, already facing a recall over brakes
[8]Alarming: Tesla lawsuit claims collision monitoring system is faulty
[9]Microsoft and GM deal means your next car might talk, lie, gaslight and manipulate you
[10]Waymo robo taxis rack up a million miles without killing anyone
Various systems had seemingly failed or suffered faults, including the front cameras and the hybrid engine control system. With some further analysis it became clear the ECUs probably hadn't failed, but communication between them had been lost or disrupted. The common factor was the CAN bus.
In reality, the faults were generated as the thieves broke into a front headlamp and tore out the wiring, and used those exposed connections to electrically access the CAN bus and send messages telling other parts of the system to basically give the miscreants the car. Disconnecting the headlamp caused the wave of aforementioned network communications failures. But how were the crucial unlock messages actually injected?
Tabor took to the dark web to look for equipment that may have been involved in the theft of his car and found a number of devices targeting the CAN bus. He worked with Noel Lowdon of vehicle forensics company Harper Shaw to look into reverse engineering a contender – a gadget capable of talking to a connected CAN bus and cunningly concealed within a normal-looking Bluetooth smart speaker. The fake speaker comes with cables you insert into an exposed bus connector, you press a button on the box, and it sends the required messages to unlock the car.
Since Tindell had helped develop Volvo's first CAN-based car platform, he was brought in to help understand the gadget's involvement in the car theft. More technical details are provided in the above write-up.
As the automotive industry develops ever more sophisticated tech systems for their vehicles, scumbags find more inventive ways to abuse these systems for their own ends.
Last year, a keyless entry exploit was demonstrated against [11]Honda Civics manufactured between 2016 and 2020. Weak crypto used in the keyless entry system in [12]Tesla's Model S was blamed for the ease with which researchers could gain entry. Back in 2016, [13]security researchers demonstrated how crooks could break into cars at will using wireless signals that could unlock millions of vulnerable VWs. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZC7sp0-n8YtZ9JL@wMmfLwAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZC7sp0-n8YtZ9JL@wMmfLwAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZC7sp0-n8YtZ9JL@wMmfLwAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://kentindell.github.io/2023/04/03/can-injection/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZC7sp0-n8YtZ9JL@wMmfLwAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZC7sp0-n8YtZ9JL@wMmfLwAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/04/03/the_tesla_semi_out_since/
[8] https://www.theregister.com/2023/03/17/tesla_sued_over_faulty_collision/
[9] https://www.theregister.com/2023/03/14/microsoft_gm_chatgpt_car/
[10] https://www.theregister.com/2023/03/02/waymo_robo_taxis_crashes/
[11] https://www.theregister.com/2022/03/25/honda_civic_hack/
[12] https://www.theregister.com/2018/09/12/tesla_hack/
[13] https://www.theregister.com/2016/08/11/car_lock_hack/
[14] https://whitepapers.theregister.com/
Re: Easily solvable....
I'm not sure how that would help here, as CAN doesn't have anything equivalent to MAC ids?
It's not that easy to protect CAN messages:
1) Some form of payload validation/encryption could be added - this is not really practical, as a lot of systems still use the original CAN protocol, which only supports 8 byte payloads.
2) Some more recent CAN hardware allows the authorised sender of a particular CAN identifier (message) to invalidate any attempt to generate a spoofed message (basically, the "owner" of the identifier intentionally corrupts any transmission that it does not initiate). In this case, the thief would have to disable the security node before the spoof would work.
3) Split the vehicle architecture so that there are multiple CAN buses (this is quite often the case anyway), and ensure that it is not physically possible to access any bus that is security-related from outside of the vehicle. This would not prevent this type of attack, but it would mean that the security system would have a chance to activate some other defence mechanism as it would be able to detect an intrusion via the alarm system.
Re: Easily solvable....
CAN proper doesn't have MAC IDs that identify specific senders or receivers, its just an address that's used to allow particular nodes to identify messages that are of interest to them. (This is a bit confusing to network types (and really messy to set up) so a lot of CAN type messages use CAN/Open which is a message format that implies a controller talking to individually addressed nodes.)
The failure here is to assume that the physical bus was safe and that messages couldn't be reverse engineered and misused. Toyota, like early Internet protocol designers, didn't think that anyone would access, much less misuse, the system for criminal gain. It should be easy to engineer secure messages, if a bit of a pain to implement.
Re: Easily solvable....
"The failure here is to assume that the physical bus was safe and that messages couldn't be reverse engineered and misused. Toyota, like early Internet protocol designers, didn't think that anyone would access, much less misuse, the system for criminal gain. It should be easy to engineer secure messages, if a bit of a pain to implement."
Which really shouldn't have happened. With early network pioneers it's understandable as there was no precedent for what they were creating, but in this case it's just a new type of network, and experience shows that networks will always get targeted for nefarious purposes, so security should have been a core consideration of the design. It doesn't take a great deal of imagination to think up scenarios which might get attempted, and attempt to block / severely mitigate them at the design stage.
Cui Bono?
I was thinking that the complacency/incompetence of the motor industry in regards to electronic theft was staggering, what with all the fundamental security rules being broken, but then I got to thinking, well, if theft is below a level where buyers will avoid the brand, what motivation is there for the car industry to make security a priority. Never ascribe to malice what may be ascribed to incompetence is a useful rule of thumb, and I doubt the manufacturers are deliberately making their vehicles easy to steal, but a moderate level of theft and thus extra sales doesn't actually seem to to have much of a downside for them.
Re: Vui Bono?
"...but a moderate level of theft and thus extra sales doesn't actually seem to to have much of a downside to counter the extra sales."
Leaking this kind of info would also 'boost' sales, the invisible column in the spreadsheet, repeat customers? Maybe not if their car gets boosted!
What's old is new?
Still hot wiring cars! Now it's from the outside! Now they break into the exterior lighting compartment, that's thinking out of the box!
Re: What's old is new?
that's thinking out of the box!
.. quite literally ..
One big mess of bad programs and connections
...break open a headlamp and use its connection to the bus to send messages.
You know you are doing it wrong when the headlamp can pawn the car.
Time to add producer liability to the books?
Massive improvement in security over the decades
You used to be able to steal a car by reaching under the wheel arch, unplugging a connector and plugging in your CAN bus device. At this rate, next decade you will need a hammer for one of the windows _and_ a screw driver to get to a CAN bus connector.
I still don't understand why cars aren't using asymmetric keys, your key stores the cars public key and your car stores the public key's of your physical key, you know the way SSL, SSH, Wireguard works. I'm so glad my car doesn't have key less entry
This is nothing to do with keyless entry.
Ah yes, because keys are SO secure.
(They're not. Car locks are notoriously easy to pick.)
Another one of those classic "illgeal sure, but props for the ingenuity"
nice
Why do headlamps need to be smart? At most, the only things accessible in the light should be lamp itself (including electronics for driving any LEDs) and possibly some sort of sensor. Any electronics required for controlling the lights should be buried somewhere where they are not easily accessible outside the car.
Wiring harnesses are expensive. CAN reduces wiring costs by networking the parts together rather than everything being point to point connections.
Could be done by putting the CAN smarts in the socket and using a dumb light. Make it so the socket cannot be replaced without access to the engine bay.
They already do something like that for the rear lights - There's often a single CAN connected circuit board behind the coloured lens with the smarts and the various bulbs plug into the board. But that was in the incandescent era, The much longer lifetimes of LEDs allow them to complicate matters nicely as LEDs can be expected to outlive the car so allowing easy replacement is no longer necessary.
amount of cars I see with a LED light arrangement not working is quite worrying - especially at the cost of a total replacement
Some Mercs have wireless Headlamp cluster controllers. If a person selling one with a "faulty" bulb, beware, that may be a £500 fix!
less than a BMW then.
Some bimmers require you to drain the coolant and remove the radiator in order to change a light bulb. Purposely designed to make more money for the dealers and prevent owner servicing.
Its rounded up to a 2 hour job and up to 750 squids to you guv.
Re: less than a BMW then.
I had a Mark 6 Golf Plus with those LED rear lamp clusters. Failed for a pastime. 500 quid a pop, too.
Security is expensive.
You have it, or you don't.
Apparently, Toyota doesn't.
"Why do headlamps need to be smart?"
There's plenty of stuff inside a humble headlamp cluster that needs controlling via the CAN bus: as well as the dip, main, side and parking lights, there are the indicators, the motors for the self leveling function (required for certain types of high intensity lights), there might also be sensors for detecting failures. Yes, you could have the bus connection secure inside the vehicle and all those functions separately hardwired into the light cluster, but as pointed out elsewhere here, wiring looms are expensive to fit, bulky and can wear out due to vibration etc. (The CAN bus is more robust than a conventional loom, it's differential driven and the spec is such that even if one wire breaks, it will still work).
This isn't new. I heard over 10 years ago from someone who knew about doing nefarious things to cars for a living, that a very well known brand had their CANbus exposed at the headlights. Looking back, it probably wasn't just that brand.
when you implement smart in a foolish way is it still... "smart"?
It is "smart" for marketing and profit only. The argument that it is cheaper (especially during "chip shortages") is laughable. It is a new 'additional' technology bolted in.
It is a light which is either on or off. It should use very little power and it should be simple not smart.
This exploit is pure silliness as it should not even exist as a potential.
This is right up there with subscriptions for basic functions of the car and in dash tablets more uselessness in modern vehicles...
They can be smart these days.
Reactive/auto sensors, cornering, auto-dim, there's quite a list.
Sure, most of it just needs a control unit to tell the lamp what to do, but those lamps return diagnostic data, too - and I suspect that's the problem.
What annoys me is the manufacturers should put security on a separate system. However, with the difficulty in getting chips, I can see why they'd route everything through one system instead.
Flip side: How hard is it to add a limiter to say 'if the car unlock doesn't come through this route, don't unlock the car, the same for the ignition, and for the immobilizer: That would stop this plugging a CAN into a headlight circuit to allow bypassing/disabling security systems.
The only way to protect your vehicle is to put a disclok on the steering wheel. That's it.
If your car is going to be stationary for a while, take the rear wheels off and put it on bricks.
You can't rely on yet more technology to help mitigate the problems technology has brought to the car.
Even that isn't always enough
"Transcript" of a conversation at a place I once worked (names "randomised"):
Eve: "Hi Steve, I see you're having trouble with that flashy Toyota Supra again"?
Steve: "What do you mean"?
Eve: "They're loading on to the flatbed now".
Steve: "****".
The car had all sorts of locks and immobilisers, but it still went missing.
Re: Even that isn't always enough
We had a transit van nicked from right beside one of our buildings, during the day when people were in the building. It was found by the police a few hours later dumped in a layby with the engine ripped out - apparently there was quite a demand for transit engines at the time.
"The only way to protect your vehicle is to put a disclok on the steering wheel"
https://www.lancashiretelegraph.co.uk/news/1973370.car-thieves-use-transporter-lift-12-cars-four-days/
They'll just lift the cars away instead. In the story above, police think the cars were stolen for scrap, meaning they wouldn't even need to get the car into a workshop somewhere and use a disk cutter in slow time to cut the steering wheel lock off.
Whenever I see a car on a transporter with its alarm blaring I always wonder ....
Yep
Either stolen or repossessed!
Good to know
So when you buy a car in the future and the manufacturer wants to lock you out, you have a way to get around it
Oh my god
If it's accessible from the outside, then it shouldn't be trusted. End of.
(and really there should be two buses, a secure inaccessible one for the engine management and control and another less secure one for all the other crap like lights and media player)
Re: Oh my god
It’s hardly “accessible” if you need to break open the car to get to it.
Re: Oh my god
why bother to have one that is less secure?
Lights and media, shouldn't need a bus, just power. if that's what you mean.
Re: Oh my god
Should be OK to run the secure control bus as an encrypted VPN or similar over the insecure bus.
Most decent auto systems already have a wall between the critical subsystem and the passenger toadying subsystems, so it shouldn't need a revolution in the architecture.
Re: Oh my god
Not really, as CAN is a hard real-time bus (which means messages are very time critical). For example, I work on systems where a specific CAN message is sent out 1000 times a second and is used to trigger events in other nodes (setting outputs, sampling inputs). Most nodes run on low-end microprocessors (which are very cheap - you don't want to have to spend an extra few £/$ per node when there are lots of them).
I don't have a car that's likely to be stolen (it's 18 years old and has a manual transmission in the US) but if I did, I'd install a hidden switch somewhere in the cabin, with a relay that simply cut power to the ECU when toggled off, then make a habit of flipping it when I parked the car. Maybe a couple of hours of work for a lot of peace of mind.
I remember someone making a double number plate for a car , there were 3 number plates the one on the car had the normal number in front of that was one held with electromagnets on one side it has the normal plate on the other it said stolen.
The idea was a switch in the car had to pressed to engage the magnet otherwise when you drove off it would flop down and reveal the word stolen to anyone following
Seems very simple in principle.
Mind you the biggest protection they could make for bus networks is to route the cables where they are only accessible with a bit of work, ie the headlamp bus connector is only accessible if you remove the headlamp which also means opening the bonnet and stripping out a few covers first.
Been happening to Alfa Romeos as well
This is not confined to Toyotas only, there's been a spate of thefts of Alfa Romeo Stelvios and Giulias recently where a similar approach was used, in this case they "remove" (rip out) the cruise control rader module in the front grille which gives access to a CANbus connecter on a bus which talks to the car's security systems. They can then unlock the car and once inside program a new key into the car's computer (using the connection from the bumper) and drive off.
Third parties are now offering steel brackets to surround the radar module to prevent them from removing it and accessing the connector. Top tip: the original plastic bracket is often damaged during attempts and Alfa only sell it together with the radar module for an eye watering amount.
The module is actually from Bosch and is used by other brands, including Volkswagen / Audi, and VAG sell the plastic mounting bracket separately, just in case anyone with a broken off radar sensor is reading this.
Easily solvable....
My XC90 (RIP) used MAC based authorisation for things like the Radio, etc, and replacement radios wouldn't work unless you switched off the MOST protection
HOWEVER: The second that you turn on mechanisms like this for the entire bus, hobbiest CANBus readers are likely to stop working for all but the most simplistic of faults
At the very least, radio keyfob messsages should be signed