Topic: Cybersecurity, Property Rights, Cars

0

AFTER JEEP HACK, CHRYSLER RECALLS 1.4M VEHICLES FOR BUG FIX
07.24.15
WELCOME TO THE age of hackable automobiles, when two security researchers can cause a 1.4 million product recall.
On Friday, Chrysler announced that it’s issuing a formal recall for 1.4 million vehicles that may be affected by a hackable software vulnerability in Chrysler’s Uconnect dashboard computers. The vulnerability was first demonstrated to WIRED by security researchers Charlie Miller and Chris Valasek earlier this month when they wirelessly hacked a Jeep I was driving, taking over dashboard functions, steering, transmission and brakes. The recall doesn’t actually require Chrysler owners to bring their cars, trucks and SUVs to a dealer. Instead, they’ll be sent a USB drive with a software update they can install through the port on their vehicle’s dashboard.
Chrysler says it’s also taken steps to block the digital attack Miller and Valasek demonstrated with “network-level security measures”?presumably security tools that detect and block the attack on Sprint’s network, the cellular carrier that connect Chrysler’s vehicles to the Internet.
Miller, one of the two researchers who developed the Uconnect-hacking technique, said he was happy to see the company respond. “I was surprised they hadn’t before and I’m glad they did,” he told WIRED in a phone call. He particularly praised the move to work with Sprint to prevent attacks through its network.
“Blocking the Sprint network is a huge thing,” Miller adds. “The biggest problem before was that cars would never get fixed or fixed way down the road. Assuming that they did [the Sprint network fix] correctly?you don’t have to worry about that tail-end of cars that won’t get fixed.”
Valasek wrote on Twitter that he’d tested the attack again and found that Sprint’s network does now appear to be blocking the Jeep attack:
Looks like I can’t get to @0xcharlie’s Jeep from my house via my phone. Good job FCA/Sprint!
? Chris Valasek (@nudehaberdasher) July 24, 2015
Chrysler had already issued a patch in a software update for its vehicles last week, but announced it with a vague press release on its website only. A recall, by contrast, means all affected customers will be notified about the security vulnerability and urged to patch their software. “The recall aligns with an ongoing software distribution that insulates connected vehicles from remote manipulation, which, if unauthorized, constitutes criminal action,” writes a Chrysler spokesperson in an email.
In its press statement about the recall, Chrysler offered the following list of vehicles that may be affected:
?2013-2015 MY Dodge Viper specialty vehicles
?2013-2015 Ram 1500, 2500 and 3500 pickups
?2013-2015 Ram 3500, 4500, 5500 Chassis Cabs
?2014-2015 Jeep Grand Cherokee and Cherokee SUVs
?2014-2015 Dodge Durango SUVs
?2015 MY Chrysler 200, Chrysler 300 and Dodge Charger sedans
?2015 Dodge Challenger sports coupes
That list of potentially vulnerable cars is slightly longer than the one Chrysler gave WIRED on Monday, which excluded the the Chrysler 200 and 300, and the Dodge Charger and Challenger. The 1.4 million number it’s targeting with the recall is also far larger than the 471,000 vehicles Miller and Valasek had estimated to possess the vulnerable Uconnect computers.
In its statement, Chrysler also said that to its knowledge the hacking technique Miller and Valasek had developed had never been used outside of the WIRED demonstration. It also pointed out that hacking its vehicles wasn’t easy. That’s true: Miller and Valasek had worked on their Jeep hacking exploit for over a year. “The software manipulation addressed by this recall required unique and extensive technical knowledge, prolonged physical access to a subject vehicle and extended periods of time to write code,” reads Chrysler’s statement.
In one less credible part of the statement, however, Chrysler also claims that “no defect has been found,” and that “[Fiat Chrysler Automobiles] is conducting this campaign out of an abundance of caution.”
Given that Miller and Valasek were able to hack the Jeep I was driving on a highway from a laptop 10 miles away, that “no defect” claim doesn’t hold up. “No defect was found (other than the remote vulnerability that can result in full physical control),” wrote Valasek on his twitter feed.
Careful Chrysler owners don’t need to depend on that network protection or wait for a USB drive to be mailed to them to patch their Uconnect computers. They can download the patch to a computer right now, put it on a USB drive, and install it on the dashboard. Start here to get that software fix.
One recall won’t change the fact that cars, SUVs and trucks are increasingly connected to the Internet and vulnerable to hacker attacks like the one Valasek and Miller have demonstrated. Congress has taken note of the rising threat of car hacking, too, with two senators introducing a bill earlier this week to set minimum cybersecurity standards for automobiles.
That bill would require cars to be designed with certain security principles, such as isolating physical components from Internet connections and including features that detect and block attacks. But for now, Miller says that a recall is a strong first step for Chrysler. “What I really want is for them to design secure cars and include detection mechanisms,” Miller says. “They can’t do that in three days. This is the most we could hope for.”

============

Car hack uses digital-radio broadcasts to seize control
22 July 2015
By Chris Vallance, BBC Radio 4
Several car infotainment systems are vulnerable to a hack attack that could potentially put lives at risk, a leading security company has said.
NCC Group said the exploit could be used to seize control of a vehicle’s brakes and other critical systems.
The Manchester-based company told the BBC it had found a way to carry out the attacks by sending data via digital audio broadcasting (DAB) radio signals.
It coincides with news of a similar flaw discovered by two US researchers.
Chris Valasek and Charlie Miller showed Wired magazine that they could take control of a Jeep Cherokee car by sending data to its internet-connected entertainment and navigation system via a mobile-phone network.
Chrysler has released a patch to address the problem.
However, NCC’s work – which has been restricted to its labs – points to a wider problem.
The UK’s Society of Motor Manufacturers and Traders has responded by saying that car companies “invest billions of pounds to keep vehicles secure as possible”.
Breached brakes
NCC demonstrated part of its technique to BBC Radio 4’s PM programme at its offices in Cheltenham.
By using relatively cheap off-the-shelf components connected to a laptop, the company’s research director, Andy Davis, created a DAB station.
Because infotainment systems processed DAB data to display text and pictures on car dashboard screens, he said, an attacker could send code that would let them take over the system.
Once an infotainment system had been compromised, he said, an attacker could potentially use it as a way to control more critical systems, including steering and braking.
Depending on the power of the transmitter, he said, a DAB broadcast could allow attackers to affect many cars at once.
“As this is a broadcast medium, if you had a vulnerability within a certain infotainment system in a certain manufacturer’s vehicle, by sending one stream of data, you could attack many cars simultaneously,” he said.
“[An attacker] would probably choose a common radio station to broadcast over the top of to make sure they reached the maximum number of target vehicles.”
Mr Davis declined to publicly identify which specific infotainment systems he had hacked, at this point.
Lab simulation
In many ways, modern cars are computer networks on wheels.
Mike Parris, of SBD, another company that specialises in vehicle security, said modern cars typically contained 50 interlinked computers running more than 50 million lines of code.
By contrast, he said, a modern airliner “has around 14 million lines of code”.
Such technology allows the latest cars to carry out automatic manoeuvres. For example, a driver can make their vehicle parallel park at the touch of a button.
Mr Davis said he had simulated his DAB-based attack only on equipment in his company’s buildings because it would be illegal and unsafe to do so in the outside world.
But he added that he had previously compromised a real vehicle’s automatic-braking system – designed to prevent it crashing into the car in front – by modifying an infotainment system, and he believed this could be replicated via a DAB broadcast.
“If someone were able to compromise the infotainment system, because of the architecture of its vehicle network, they would in some cases be able to disable the automatic braking functionality,” he said.
Jeep attack
On Tuesday, Wired magazine reported that two US security researchers had managed to remotely take control of a Jeep Cherokee’s air-conditioning system, radio and windscreen wipers while its journalist was driving the vehicle.
Mr Valasek – director of vehicle security research at IOActive – said that NCC’s attack appeared to have similarities with his own.
“I mean that’s essentially what we did over the cell [mobile] network – we took over the infotainment system and from there reprogrammed certain pieces of the vehicle so we could send control commands,” he said.
“So, it sounds entirely plausible.”
But he added that such exploits were beyond the reach of most criminals.
“It takes a lot of time skill and money,” he said.
“That isn’t to say that there aren’t large organisations interested in it.”
More details about both the NCC and the US team’s research will be presented to the Black Hat security convention in Las Vegas next month.


Automakers Say You Don’t Really Own Your Car
APRIL 3, 2015
BY KIT WALSH
EFF is fighting for vehicle owners’ rights to inspect the code that runs their vehicles and to repair and modify their vehicles, or have a mechanic of their choice do the work. At the moment, the anti-circumvention prohibition in the Digital Millennium Copyright Act arguably restricts vehicle inspection, repair, and modification. If EFF is successful then vehicle owners will be free to inspect and tinker, as long as they don’t run afoul of other regulations, such as those governing vehicle emissions, safety, or copyright law.
You can support EFF’s exemption requests by adding your name to the petition we’ll submit in the rulemaking.
Most of the automakers operating in the US filed opposition comments through trade associations, along with a couple of other vehicle manufacturers. They warn that owners with the freedom to inspect and modify code will be capable of violating a wide range of laws and harming themselves and others. They say you shouldn’t be allowed to repair your own car because you might not do it right. They say you shouldn’t be allowed to modify the code in your car because you might defraud a used car purchaser by changing the mileage. They say no one should be allowed to even look at the code without the manufacturer’s permission because letting the public learn how cars work could help malicious hackers, “third-party software developers” (the horror!), and competitors.
John Deere even argued that letting people modify car computer systems will result in them pirating music through the on-board entertainment system, which would be one of the more convoluted ways to copy media (and the exemption process doesn’t authorize copyright infringement, anyway).
The parade of horribles makes it clear that it is an extraordinary stretch to apply the DMCA to the code that runs vehicles. The vast majority of manufacturers’ concerns have absolutely nothing to do with copyright law. And, as the automakers repeatedly point out, vehicles are subject to regulation by other government agencies with subject matter expertise, which issue rules about what vehicles are and are not lawful to operate on public roadways.
The DMCA essentially blundered into this space and called all tinkering and code inspection into question, even acts that are otherwise lawful like repairing your car, making it work better at high altitude, inspecting the code to find security and safety issues, or even souping it up for use in races on a private course. We’re presenting the Copyright Office with the opportunity to undo this collateral damage and leave regulating auto safety to specialized agencies, who understandably have not seen fit to issue a blanket prohibition against vehicle owners’ doing their own repairs and safety research.
Here’s how you can help. The opponents of the vehicle exemptions say that no one really cares about the restrictions they place on access to vehicle code, so the Copyright Office should deny the exemptions. Now, we cited a number of projects, and thousands of people wrote to the office to support the exemptions, but we are confident there are even more projects, businesses, and individuals out there who need these exemptions and it would be a shame if the Copyright Office didn’t know it.
If you have had problems with vehicle repair or tinkering because you were locked out of your vehicle’s computers, if you would have engaged in a vehicle-related project but didn’t because of the legal risk posed by the DMCA, or if you or your mechanic had to deal with obstacles in getting access to diagnostic information, then we want to hear from you?and the Copyright Office should hear from you, too.
Email us at 1201cars@eff.org to let us know. It will help strengthen our case for the Copyright Office. We can also incorporate your comments anonymously, if you’d prefer.


Read More at the Archives.

Leave A Reply

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More