Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
> “sources said”
Yes, that's how Wikipedia works. https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_vie...
Remember that not that long ago viruses spread through floppy disks.
Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
Article does not say that.
Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.
Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
The two big things here in my mind are:
1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out
2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
Just off the top of my head.
And doing that doesn't really interfere with also setting up and selling proxy endpoints
Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.
The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!
Otherwise any car sitting unused for a week or two would have a dead battery.
[1]https://opengarages.org/handbook/ebook/ (chapter 9)
I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.
This is available on standard OBD-II. Maybe, it is accessible over CAN?
I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).
Also, feel like John Gruber is going to have a field day with this one
Android Auto is the Google equivalent of CarPlay and runs on your phone.
It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.
Unfortunately Android Auto already existed. So it’s confusing.
- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls
- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps
- Keyless entry basically a shit show of faraday pouches
- OBD port allowing thieves to clone a full key in seconds
- Even cars in decent neighbourhoods have to use steering locks
Sorry but this is a fucking joke and the automotive industry is cancer.
At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.
All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
Simple. It hasn't.
The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
Somehow I doubt it. They're ripe for ransomware attack.
Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month *
* Cars without subscription causes acceleration to be restricted to 60mph.
After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don't need to be general purpose computing devices either. I shouldn't have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).