Got An IPod? Want To Steal Some Cars?

Jack Baruth
by Jack Baruth

…We also found that the entire attack can be implemented in a completely blind fashion—without any capacity to listen to the car’s responses. Demonstrating this, we encoded an audio file with the modulated post-authentication exploit payload and loaded that file onto an iPod. By manually dialing our car on an office phone and then playing this “song” into the phone’s microphone, we are able to achieve the same results and compromise the car.

This tidbit, found on page 11 of “Comprehensive Experimental Analyses of Automotive Attack Surfaces” by researchers from the University of California (San Diego) and the University of Washington, says exactly what you think it says: it’s becoming easy for intelligent, dedicated criminals to steal your car — or, worse yet, to control certain functions of the car remotely while you’re driving it.

The complete article details the team’s attempts to find vulnerabilities in an unnamed, “100,000 to 200,000 units per year” sedan. Here’s another super-fun discovery by the team. I’ve bolded the horrifying part for our readers who don’t like long quotes.

For the former, we experimentally verified this by compromising two cars


(located over 1,000 miles apart), having them both join the IRC channel, and then both simultaneously respond to a single command (for safety, the command we sent simply made the audio systems on both cars chime). Finally, the high-bandwidth nature (up to 1 Mbps at times) of this channel makes it easy to exfiltrate data. (No


special software is needed since ftp is provided on the host platform.) To make this concrete we modified our attack code for two demonstrations: one that periodically “tweets” the GPS location of our vehicle and another that records cabin audio conversations and sends the recorded data to our servers over the Internet.

The entire article is worth reading, even if talk of “stack overflows” won’t exactly rivet those of you who didn’t grow up writing “sploits”. It details one exploit in which the team remotely unlocked a car and started it up so an “unskilled accomplice” could drive it away. Another scenario: by compromising a group of cars in the Google parking lot, decoding the VINs to determine which ones were expensive, and correlating the location of the car at 7pm to known property records, it would be possible to sell Google executive conversations to third parties. Gosh, I can’t think of anyone who would pay money to hear what the Google CEO is talking about in private.

The team goes on to state how the exploits they discovered can be easily disabled in the future by adding encryption, reducing unnecessary “easter eggs” in embedded vehicle code, and more thorough debugging. What they do not explicitly state is that anyone familiar with how the car business works will be rolling on the proverbial floor laughing at the idea of automakers taking due care with their on-board electronics.

Not frightened by the idea of losing your car to hackers in Romania? Unconcerned that someone might be able to remotely throw random inputs into the adaptive steering in your wife’s BMW while simultaneously cranking the stereo to 110 dB, permanently locking the doors, and turning off the headlights? Just think of what will happen when self-driving cars become the norm.

Jack Baruth
Jack Baruth

More by Jack Baruth

Comments
Join the conversation
2 of 17 comments
  • Daveainchina Daveainchina on Jan 15, 2012

    The heck with car thieves, what about either some teenager doing the "I wonder if I could....." or worse a terrorist deciding to suddenly attack all the cars in all the major cities with say, loud stereo, reverse the input of the steering wheel and full acceleration. How many accidents do you think would happen within 3 minutes. How many dead, or in the hospital? Lastly, who'd feel safe going to work in their car again? Everyone would be trying to buy 1970's pinto's etc. That would truly be a catastrophe on a scale that I don't think we're ready to deal with.

  • CPTG CPTG on Jan 17, 2012

    You can't be scared of something if it is inevitable to happen. Remember the car thief that stole the victim's caddy? It had an ONSTAR in it. Victim called ONSTAR, who GPS'd its location and notified the Police. When the Police ID's the vehicle, ONSTAR asked the Police if they wanted ONSTAR to disable the vehicle and they did (cut off the fuel supply). I'm not worried about the future of NETWORKED Cars. It just means you'll have to install a firewall and security software to prevent intruders. Or do what I plan to do...buy an Apple iCAR---see, no more security worries because it is a totally closed system.

  • ToolGuy The other day I attempted to check the engine oil in one of my old embarrassing vehicles and I guess the red shop towel I used wasn't genuine Snap-on (lots of counterfeits floating around) plus my driveway isn't completely level and long story short, the engine seized 3 minutes later.No more used cars for me, and nothing but dealer service from here on in (the journalists were right).
  • Doughboy Wow, Merc knocks it out of the park with their naming convention… again. /s
  • Doughboy I’ve seen car bras before, but never car beards. ZZ Top would be proud.
  • Bkojote Allright, actual person who knows trucks here, the article gets it a bit wrong.First off, the Maverick is not at all comparable to a Tacoma just because they're both Hybrids. Or lemme be blunt, the butch-est non-hybrid Maverick Tremor is suitable for 2/10 difficulty trails, a Trailhunter is for about 5/10 or maybe 6/10, just about the upper end of any stock vehicle you're buying from the factory. Aside from a Sasquatch Bronco or Rubicon Jeep Wrangler you're looking at something you're towing back if you want more capability (or perhaps something you /wish/ you were towing back.)Now, where the real world difference should play out is on the trail, where a lot of low speed crawling usually saps efficiency, especially when loaded to the gills. Real world MPG from a 4Runner is about 12-13mpg, So if this loaded-with-overlander-catalog Trailhunter is still pulling in the 20's - or even 18-19, that's a massive improvement.
  • Lou_BC "That’s expensive for a midsize pickup" All of the "offroad" midsize trucks fall in that 65k USD range. The ZR2 is probably the cheapest ( without Bison option).
Next