spicyjpeg6 hours ago
The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
ghostly_s2 hours ago
Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.
supriyo-biswasan hour ago
To avoid charges of libel.
manbash6 hours ago
Indeed this is an odd disclosure and I am not familiar with past posts by them.
Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
_joel6 hours ago
_joel2 hours ago
Oh, I see I'm getting downvoted by the Russian bots, quelle surprise.
p-e-w6 hours ago
It’s astonishing how this relatively long article contains not a shred of actual evidence that any of this is true. It’s all “alleged”, “raised concerns”, “sources said” etc.
orbital-decay5 hours ago
Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?
atmosx5 hours ago
FSB? Oh you mean Russian “Federal Security Service” ?
_joel3 hours ago
It's been a while since I thought about Front Side Bus
jibal3 hours ago
As it says in the first line of the WP article: "Federal Security Service (FSB)"
jibal3 hours ago
The article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.)
> “sources said”
Yes, that's how Wikipedia works. https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_vie...
DaSHacka5 hours ago
Welcome to Wikipedia
markus_zhang3 hours ago
This makes me think whether the whole chain is an intelligence side business — sell cheap electronics for profit and at the same time own them too.
reaperducer4 hours ago
It cannot self-propagate to any Android-based head unit
Remember that not that long ago viruses spread through floppy disks.
Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
charcircuit4 hours ago
Most people just bring their phone between cars for music.
mschuster916 hours ago
> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit
Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
306bobby5 hours ago
Wireless AA and CarPlay use a hotspot your car emits that your phone connects to and transfers the image/inputs/audio that way
m-s-y5 hours ago
Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.
NewJazzan hour ago
Wow that's cursed, never realized that's how it worked.
iamjackgan hour ago
It uses Bluetooth to stream audio, but everything else happens through a WiFi connection exposed by the car that the phone automatically pairs with after the Bluetooth handshake.
dhc025 hours ago
The way I understand it, the connection is negotiated via BT, but then wifi is used for the fat data pipe to run the display.
alphager4 hours ago
They didn't run over BT. BT is used to initiate communication and share the password to a wifi-network. It then uses that Wi-Fi network for most communication, keeping the BT channel strictly for telephony.
StilesCrisis5 hours ago
I thought the latest Bluetooth protocols were basically designed to hand off to an ad-hoc Wi-Fi connection between the two devices after the initial handshake. (Might be an oversimplification of the real protocol)
izacus4 hours ago
They actually run over WiFi (WiFi direct IIRC) - Bluetooth is mostly just used as a setup handshake and to help the head unit decide which phone in the car should be the one connected.
chrisjj4 hours ago
> It cannot self-propagate to any Android-based head unit
Article does not say that.
ajross4 hours ago
Headline really quite clearly implies it, though. I think the correction is apt.
Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.
Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
MBCook2 hours ago
It’s no different than how the old Ford Sync or something else could have been compromised.
The two big things here in my mind are:
1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out
2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
ajrossan hour ago
This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.
The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
Retr0id7 hours ago
> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet
People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
axegon_6 hours ago
Almost, though I understand I am the exception rather than the rule: Personally I have an aftermarket android head unit since the standard one was incredibly basic, no real time navigation updates, updating maps was a pain in the ass and so on. Initially I did pair it with my phone but since it is an aftermarket unit from a company which apparently does not exist anymore, newer phones cannot be paired with it. So my only option was to go the opposite route and use my phone as a wireless hotspot(almost - there's a raspberry pi with openwrt between the two). And since I self-host everything, I had no choice but to hook it up to my vpn. That said, I understand the implications of doing this so ultimately the network access it gets is incredibly limited: everything that is not my music server and the maps provider has been cut off completely. The downside is that every now and then I get a "can't connect to google services" notification though that is technically reassuring from a security perspective.
madduci2 hours ago
Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself
ghostly_s2 hours ago
"Pairing" with a head unit is not an open socket to dump anything you care to down the wire. That would require finding a rather remarkable vulnerability in one of the audio/address book/screen mirroring APIs the devices use.
Retr0id2 hours ago
Bluetooth RCEs have happened in the past and will happen again.
buckle80177 hours ago
Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists.
Just off the top of my head.
Retr0id7 hours ago
That's scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).
wongarsu6 hours ago
If you infect tens of vehicles that's not that valuable. But if you infect ten thousand vehicles, convinced a trusted member of one of the bigger black hat forums it's real and have him vouch for your marketplace post, there should be some buyers for full movement profiles, call logs and address books of ten thousand people
And doing that doesn't really interfere with also setting up and selling proxy endpoints
stymaar7 hours ago
Yeah, especially since most of these are already available for purchase from data brokers.
Zigurd6 hours ago
They're called data brokers because they have a buy side, too. That might be peanuts to you, but to an AliExpress seller, it could be most of their profit.
carstenhag3 hours ago
Some head units (working with a 1st party one atm) have two networks: OEM-paid (unlimited data) and user-paid. A 3rd party apk would be consuming all bought traffic quite soon.
Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.
kotaKat7 hours ago
It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit.
The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!
brookst7 hours ago
Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later.
Otherwise any car sitting unused for a week or two would have a dead battery.
Zigurd6 hours ago
I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.
smilespray5 hours ago
If that was one of those ELM327 dongles, yes they have 12V and are known to drain your battery. They're only meant for short diagnostic runs.
olyjohn6 hours ago
They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.
lmz3 hours ago
You would hope that the ignition switch really cuts the power to the head unit when it is switched to off.
carstenhag3 hours ago
No you wouldn’t, because then you always have a cold boot of the headunit, even if you just accidentally hit the ignition. Users want the head unit to resume within a few seconds. Just like their phone.
kotaKat5 hours ago
Some of these Android units also double as DVRs and dashcam recorders (parking mode!) as well so may be hooked onto the normal +12v rail.
dzdt7 hours ago
There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872
Ccecil6 hours ago
The car hacker's handbook [1] has a chapter on just using the infotainment system to access the CAN. Specifically mentions "attacking through the update system".
[1]https://opengarages.org/handbook/ebook/ (chapter 9)
011000116 hours ago
An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?
RealityVoid6 hours ago
Can't vouch for all car architectures, but in most cases the head unit is QM and safety domains are usually segmented from each other. So even if the head unit talks CAN (it needs to get car data somehow) it will only communicate with the rest of the car through a gateway that will not allow it to take any dangerous actions.
karlshea6 hours ago
Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app.
I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.
rootusrootus4 hours ago
That’s wild, I’ve never run across a head unit that had me connect OBD2. I think I would just ignore that bit of the install instructions.
kanbankaren3 hours ago
> speedometer/rpm
This is available on standard OBD-II. Maybe, it is accessible over CAN?
dx41003 hours ago
My OBD-II connector has CAN-C (500kbit) and CAN-B (50kbit) - I use CAN-B primarily because I can control windows, doors, etc + get the speed & rpm.
dx41003 hours ago
Many do - the one I was looking at for my vehicle in particular uses it to restore the steering wheel controls (which are broadcast over the CAN-B low speed bus)
jiaosdjf6 hours ago
Manufacturers should be sued to absolute oblivion for doing what any developer would tell you is a security hole.
jackdecker7 hours ago
For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ?
I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).
Also, feel like John Gruber is going to have a field day with this one
MBCook7 hours ago
Android Automotive is the infotainment system’s OS and runs fully without a phone.
Android Auto is the Google equivalent of CarPlay and runs on your phone.
It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.
jackdecker6 hours ago
So I can use android auto on an android automotive head unit - got it but also this seems needlessly confusing naming structure. Apple TV comparison is apt lol
MBCook2 hours ago
It makes perfect sense in isolation. It’s a good name.
Unfortunately Android Auto already existed. So it’s confusing.
Zigurd6 hours ago
Did they hire their branding person from Microsoft? And how about AppFunctions (Google) and AppIntents (Apple)?
izacus4 hours ago
How would you name them?
Zigurd4 hours ago
Android Connect instead of Android Auto, and any word other than recycling the android app communication nomenclature "Intent." But hey I'm no branding genius so let's workshop this to close the loop.
dybber7 hours ago
I don’t believe this is Android auto running from a phone, but a situation where the manufacturer have used Android Automotive as operating system for the built in head unit. As e.g. on Volvo’s.
inquirerGeneral7 hours ago
[dead]
davoneus7 hours ago
The logical endpoint of the entire "the car as software" concept. Can't wait for the security vendors to start hawking "AV for your car"
Retr0id7 hours ago
I hope we see "de-smartification" conversion kits that replace the electronics with more straightforward (and repairable) offline equivalents. The ultimate AV.
doublerabbit5 hours ago
It's already in televisions. Not long now.
jiaosdjf6 hours ago
"How has the automotive industry adapted to decades of computing best practices?"
- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls
- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps
- Keyless entry basically a shit show of faraday pouches
- OBD port allowing thieves to clone a full key in seconds
- Even cars in decent neighbourhoods have to use steering locks
Sorry but this is a fucking joke and the automotive industry is cancer.
At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.
All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
smilespray5 hours ago
You had me until you started giving Tesla the thumbs-up, despite your caveat.
Telaneo3 hours ago
> "How has the automotive industry adapted to decades of computing best practices?"
Simple. It hasn't.
gchamonlive6 hours ago
Can't be safer than the non-entertainment system from WV Up! that's just a built-in head mount for your phone. Grab one with a large screen and it's the safest thing you can get. Android still has an auto mode for this where it controls the car's audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it's safer too
1970-01-017 hours ago
..to add to a botnet for click fraud.
The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
chrisjj4 hours ago
> Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads.
Somehow I doubt it. They're ripe for ransomware attack.
[deleted]7 hours agocollapsed
MBCook7 hours ago
So to do this the attacker has to compromise the update servers at $CAR_COMPANY?
timmmmmmay6 hours ago
no, the update servers at $sketchy_aliexpress_aftermarket_head_unit_company, probably somewhat easier
hndbwksam75 hours ago
Concise and useful, rare combo
doublerabbit5 hours ago
Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month *
* Cars without subscription causes acceleration to be restricted to 60mph.
After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.Telaneo3 hours ago
Even from this perspective, it's pretty easy to make things more secure by having less technology. Have the infotainment system just be a blank canvas for Carplay or AA to display on (there does need to be a bit back and fourth, phone needs to send audio to car, car needs to send GPS, speed and state of charge to phone (not strictly necessary, but there are user benefits from the phone having this information). The car itself doesn't need a whole internet-connected general purpose computer attached to it, but doing that is an easy way for the manufacturer to supposedly add value.
Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don't need to be general purpose computing devices either. I shouldn't have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).
bluGill7 hours ago
One more reason cars should not be internet connected. They last for decades and manufactures don't want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.
zb36 hours ago
I'd not consider it malware if its sole purpose is to do ad/click fraud. The user is not the target here, the user's enemies are :)
IshKebab7 hours ago
Um so which car is this? tw.com doesn't seem to be in use.
[deleted]3 hours agocollapsed
miohtama7 hours ago
[flagged]
promptspheree6 hours ago
[flagged]
lvbyte7 hours ago
[dead]
sehw7 hours ago
[dead]
waazy4 hours ago
this is crazy
tiahura5 hours ago
Apple's gatekeeping doesn't make IPhone users any safer.