Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automotive WiFi? #147

Open
MV10 opened this issue Oct 21, 2017 · 13 comments
Open

Automotive WiFi? #147

MV10 opened this issue Oct 21, 2017 · 13 comments

Comments

@MV10
Copy link

MV10 commented Oct 21, 2017

Anybody know who is responsible for WiFi for the various auto manufacturers? Chevy, Ford, all of them offer WiFi these days. (I'm not so concerned about somebody snooping traffic, but the ability to inject packets sounds a few steps away from potential buffer overflows...)

@kristate
Copy link
Owner

This is a good point. Amazing how far Wi-Fi has been integrated into our lives.

Perhaps we should start a list for cars? I found this list:
https://www.cars.com/articles/which-2017-cars-offer-in-car-wi-fi-1420692490461/

@zeadope-zz
Copy link
Contributor

Maybe list the technologies instead:

  • QNX
  • Apple Car Play (runs on Blackberry’s QNX platform)
  • Android Auto (by Google in-car)

@kristate
Copy link
Owner

@zeadope right, but there are also weirder integrations like JEEP's which was hacked last year:
https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

@zeadope-zz
Copy link
Contributor

zeadope-zz commented Oct 21, 2017

@kristate check out the documentation of the hackers here: https://www.scribd.com/mobile/doc/236073361/Survey-of-Remote-Attack-Surfaces#

Many brands use Uconnect (FCA US). I can’t find what underlying technology they use. -Might be QNX might be something else-.

Update: CHRYSLER, DODGE, JEEP®, RAM, MOPAR®, SRT®, FIAT®, ALFA ROMEO brands use Uconnect which IS a layer on top of QNX.

Older generations QNX use the network stack “io-net”, the newer/current versions might use “io-pkt” for easier updates from netBSD.

However current netBSD appears to be using wpa_supplicant, which has been patched.

Just don’t use your car as a Wi-Fi client. :)

@kristate
Copy link
Owner

Any word from QNX/ Blackberry?

@zeadope-zz
Copy link
Contributor

zeadope-zz commented Oct 21, 2017

No, most likely blackberry automotive branch won’t say anything directly to the public. Car manufacturers will most likely provide self updates using USB or though official dealerships.

@MV10
Copy link
Author

MV10 commented Oct 21, 2017

A lot of Android Auto runs on QNX as well. My truck is a 2017 Chevy and it's QNX. That's just the OS, not really clear if it would be an OS responsibility or whomever made the radio chipset... looking pretty complex. And you know auto makers and dealers... I'm not expecting a fast turn-around on this.

@zeadope-zz
Copy link
Contributor

zeadope-zz commented Oct 21, 2017

Most GM enabled brands use MyLink/IntelliLink based on QNX.

zeadope-zz pushed a commit to zeadope-zz/krackinfo-additions that referenced this issue Oct 22, 2017
@zeadope-zz
Copy link
Contributor

zeadope-zz commented Oct 22, 2017

I've made a start and added a concept VEHICLE.md, but it needs some work.

  • Optimize layout
  • Add brands (that have models with Wi-Fi):
    • Fiat Chrysler Automobiles N.V. (missing Maserati)
    • General Motors
    • Volkswagen Group
    • Toyota
    • Honda Motor Co., Ltd. (Honda auto and new motorcycle cruiser)
    • Hyundai Motor Group (Genesis Motors, Hyundai Motor Company, Kia Motors)
    • Ford Motor Company
    • BMW
    • Mercedes
    • Tata motors (Jag, Land Rover)
    • Nissan Group (Datsun, Infinity, Mitsubishi, Nissan, Renault)
    • Tesla Motors, Inc.
    • Groupe PSA (Citroën, Peugeot, Opel, etc.)
    • Geely Holding Group (Volvo Cars / AB Volvo)
    • Ferrari N.V. (Ferrari)
    • ...
  • Filling it with model specific data (edition, from year, status, comment)
  • ...

@MV10
Copy link
Author

MV10 commented Oct 22, 2017

Shouldn't Blackberry be on the response matrix in general?
(Although as far as I can tell they haven't said a word about it, so far.)

@zeadope-zz
Copy link
Contributor

RIM’s (owner of Blackberry) board might not want to do that for several reasons. Also there might be legal concerns with RIM and manufacturers contracts.
Manufacturers might only come with an update/recall as soon as internal/external investigation is complete. Maybe there is nothing to be concerned about for all we know.
If they say something now without any certainty, this WILL affect sales by a lot. People might also not choose the brand for their next vehicle.
This is a very delicate situation I guess.

kristate added a commit that referenced this issue Oct 23, 2017
@zeadope-zz
Copy link
Contributor

zeadope-zz commented Oct 28, 2017

#181 PSA Groupe

@edjm
Copy link

edjm commented Nov 2, 2017

2017 Honda CR-V can be added to this list. It uses Android 4.2.2. Based on Google searches, it looks like the 2016 Honda Civic and Pilot do as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants