Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Galler
Jan 28, 2008


Went to the BlackHat talk on that today. It was pretty interesting. No where near enough time to go into a lot of detail, but the white paper (90+ pages) will be released on Monday for those that want all the details.

The network change Sprint made a week or two back eliminated the ability to access the cars over the cellular network in that way. Unpatched cars are probably still accessible over WiFi but that would require someone to have actually paid for the hotspot feature. The WiFi uses WPA2 and the default password is strong enough, but the initial password generating code was reverse engineered and in most cases there will only be a few dozen password options. The current time is the only variable/unknown in the algorithm but the car likely doesn't know the time when it first boots and generates the password so it just uses a default time (Jan 1 2013 if I remember) and starts counting up from there. So basically take that date plus about 30 seconds and plug it into the algorithm.

The update filters the various ports. No idea if they actually fixed the ability to run arbitrary commands and code on the head unit (doubt it) or did anything about the V850 chip's (which is accessible from the head unit and talks on the CAN bus) firmware not bring signed or secured in anyway.

Adbot
ADBOT LOVES YOU

  • Locked thread