Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What you're describing sounds like a firewall for CAN. It's a complex solution that will inevitably be insecure.

"Yeah it sucks, but it is what it is."

This attitude might work with some other things, but the automotive industry will have to deal with security in a reasonable fashion. This is potentially life-and-death stuff and consumers actually have choice here. Not everyone understands the full implication of someone tracking their cellphone or hacking their email, but everyone can imagine what will happen if your car will get out of your control.



FWIW some companies handle this better than others. In this case FCA took the Uconnect code from a different division and integrated it. People make mistakes, something was listening and passing on more than it should in that system, now it is fixed. I'm really impressed with the researchers work.

I've been trying to describe two things. One, the way that CAN bus operates, so some of the technical solutions people have been making just are impossible. People should imagine that CAN bus is something like RS-485 or the old systems that had some mix of ISA and PCI, not like switched ethernet. The second item is a bit of how these things happen in business world, for good or bad, not that I agree with it or anything.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: