LOST JEEPS
http://www.lostjeeps.com/forum/phpBB3/

Interesting paper on OSBII/CAN automotive security
http://www.lostjeeps.com/forum/phpBB3/viewtopic.php?f=45&t=52820
Page 1 of 1

Author:  dgeist [ Mon May 17, 2010 2:35 pm ]
Post subject:  Interesting paper on OSBII/CAN automotive security

Here's an interesting paper on the potential insecurities inherent in modern automotive communications systems:
http://www.autosec.org/publications.html

It looks like the target vehicle in this case is a Chevy, but many of the same concepts and potential vulnerabilities would be common to other platforms as well. Makes me want to get out a CAN-bus sniffer and go try to turn things of/off with the ODBII port...

Dan

Author:  Daksport [ Mon May 17, 2010 10:53 pm ]
Post subject:  Re: Interesting paper on OSBII/CAN automotive security

That just makes me dread how dependent modern day vehicles are on electronics. When you can't stop a vehicle no matter how hard you press the brake, something is wrong with the design.

Author:  dgeist [ Tue May 18, 2010 5:28 pm ]
Post subject:  Re: Interesting paper on OSBII/CAN automotive security

Daksport wrote:
That just makes me dread how dependent modern day vehicles are on electronics. When you can't stop a vehicle no matter how hard you press the brake, something is wrong with the design.


One thing to note is that the lychpin of the whole scenario was the fact that there's a device that bridges the low-speed (non-critical) and high-speed(critical) CAN buses. Other than the BCM, there shouldn't be one that does that... but OnStar talks on both, and if the protocol itself has no security mechanism built in (and there's no way to verify authenticity of messages on CAN), then you're screwed.... makes me not ever want to buy a product with celular uplink technology. I'll keep that in my pocket.

Dan

Page 1 of 1 All times are UTC - 5 hours [ DST ]
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/