22 comments

  • spicyjpeg19 hours ago
    The article does not make it particularly clear, but the malware in question is delivered through <i>official first-party</i> OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a &quot;dumb&quot; screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
    • ghostly_s14 hours ago
      Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor&#x27;s update server was compromised? If so why don&#x27;t they just say so.
      • codedokode4 hours ago
        Cheap Android phones and tables often have built-in advertisement from manufacturer. One example of such software, it creates a window with Google Ads on top of browser window. The window is shown only when the browser is active to make it look like the ads is a part of the site. The ads appears only couple weeks after activation so that the user thinks it is a result of installation of some app and Youtube reviewers do not notice existence of malware. The adware consults a remote config which defines in what countries it should work. Another adware component automatically downloads and re-installs it if it is deleted.<p>I found all these details through examining the official firmware image and reverse engineering.<p>I don&#x27;t remember if I reported Google Ads id to Google. It is interesting that Google doesn&#x27;t notice and care about such use of their products.
      • bigiain5 hours ago
        &gt; we would have to assume the vendor&#x27;s update server was compromised<p>You say &quot;compromised&quot;. I say &quot;monetised&quot;.<p>:sigh:
      • supriyo-biswas13 hours ago
        To avoid charges of libel.
        • wbl12 hours ago
          In America its not libel if it&#x27;s true
          • apublicfrog12 hours ago
            I see nothing at a glance about the author (Dmitry Kalinin) being American, so I can&#x27;t imagine that is relevant.
            • bluGill9 hours ago
              there is the problem. We don&#x27;t know what country is in question. There are some countries where the truth is not a defense against libel. Thus, depending on where the author is from, or for that matter the publisher or other people who might happen to be in the chain, there could be a libel case if the truth was stated.
              • scoot48 minutes ago
                &gt; There are some countries where the truth is not a defense against libel<p>Germany, for example. Utterly bizarre and baffling that a democracy protects its politicians this way. &#x2F;s
    • manbash19 hours ago
      Indeed this is an odd disclosure and I am not familiar with past posts by them.<p>Moreover, no CVE is associated with this claimed vulnerability. It&#x27;s not even stated which Android version or automotive head-unit variant version is affected.
      • _joel18 hours ago
        <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Kaspersky_and_the_Russian_government" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Kaspersky_and_the_Russian_gove...</a>
        • _joel14 hours ago
          Oh, I see I&#x27;m getting downvoted by the Russian bots, quelle surprise.
        • p-e-w18 hours ago
          It’s astonishing how this relatively long article contains not a shred of actual evidence that any of this is true. It’s all “alleged”, “raised concerns”, “sources said” etc.
          • orbital-decay17 hours ago
            Wikipedia&#x27;s source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?
            • somenameforme5 hours ago
              Up until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of &#x27;transparency centers&#x27; offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations, and so on.<p>And if they were in any way affiliated with the Russian (or any) government, there seems no logical reason they&#x27;d publicly share their findings of the NSA malware, let alone the other transparency actions. Their data would be <i>vastly</i> more valuable if kept secret, because it&#x27;d open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems. Instead their actions benefited everybody, but obviously embarrassed the NSA and as a result the US.<p>[1] - <a href="https:&#x2F;&#x2F;media.kasperskycontenthub.com&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;43&#x2F;2018&#x2F;03&#x2F;08064459&#x2F;Equation_group_questions_and_answers.pdf" rel="nofollow">https:&#x2F;&#x2F;media.kasperskycontenthub.com&#x2F;wp-content&#x2F;uploads&#x2F;sit...</a>
              • orbital-decay2 hours ago
                KL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90&#x27;s and early 2000&#x27;s, together with some of their then-rivals like Dr. Web. There&#x27;s a reason they were trusted, and there&#x27;s a reason they tried to deny their takeover, they have a genuinely earned reputation.<p>This doesn&#x27;t mean they aren&#x27;t a FSB branch, in the same way e.g. NSO Group is a Mossad branch, with one difference that KL sell themselves as defensive and NSO Group doesn&#x27;t. It was confirmed by KL employees in their socials that the management has been largely taken over by actual FSB officers. Some have left the company out of protest because they felt it&#x27;s getting raided (отжим in Russia is not like your usual corporate takeover...). It&#x27;s impossible to link it now as most of these people are living abroad since 2022 or earlier and either removed all their stuff or their socials entirely, some have renounced their citizenship by this point. But as a general rule, assume every important business in Russia is taken over by the government since 2022, either directly or indirectly. In 2026, whitewashing <i>Kaspersky Labs</i> of all companies is weird.<p><i>&gt;But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government</i><p>There was also a war happening, which you aren&#x27;t saying.<p><i>&gt;Over the next years Kaspersky opened a bunch of &#x27;transparency centers&#x27; offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations</i><p>The audits are to check the checkboxes, they mean very little. Plenty of former Russian companies that moved abroad are keeping ties with the developers at home, despite all audits, fronting campaigns, and otherwise pretending they aren&#x27;t (not all though, others did actually migrate).<p><i>&gt;if they were in any way affiliated with the Russian (or any) government</i><p>I mean, YK himself is KGB and there are no former ones, as they say. KL is one of the main government cybersec contractors, for starters. In a country where the government controls most of the economy they are producing critical industrial security systems like data diodes and secure gateways with their own OS, you can go to their site and look at all this yourself.<p>Cybersec industry in general is heavily affiliated with their respective governments, I don&#x27;t think it&#x27;s a secret for anyone and denying this is just silly. Some of them are more than others.<p><i>&gt;there seems no logical reason they&#x27;d publicly share their findings of the NSA malware ... Their data would be vastly more valuable if kept secret, because it&#x27;d open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems.</i><p>What? This doesn&#x27;t make any sense, sorry. Security agencies usually publish or leak actions of their adversaries.<p><i>&gt;Instead their actions benefited everybody</i><p>Did their inaction benefited anyone? RuNet which has been great got basically destroyed and turned into a safe haven for half of world&#x27;s cybercriminals on their proud watch, and they aren&#x27;t writing anything on this. They serve as part of their &quot;roof&quot;.<p>Note I&#x27;m not saying they aren&#x27;t doing good things, you&#x27;re right, it&#x27;s pretty good when the spooks keep each other and cybercriminals in check, see the article in OP, Apple&#x27;s hardware backdoors (Operation Triangulation), and many other cases.
            • atmosx17 hours ago
              FSB? Oh you mean Russian “Federal Security Service” ?
              • _joel16 hours ago
                It&#x27;s been a while since I thought about Front Side Bus
              • jibal15 hours ago
                As it says in the first line of the WP article: &quot;Federal Security Service (FSB)&quot;
          • jibal15 hours ago
            The article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.)<p>&gt; “sources said”<p>Yes, that&#x27;s how Wikipedia works. <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Wikipedia:Neutral_point_of_view" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Wikipedia:Neutral_point_of_vie...</a>
          • DaSHacka17 hours ago
            Welcome to Wikipedia
    • markus_zhang16 hours ago
      This makes me think whether the whole chain is an intelligence side business — sell cheap electronics for profit and at the same time own them too.
    • camkego4 hours ago
      Interesting how there is possibly a new category of residential proxy malware “automotive proxy malware”
    • reaperducer17 hours ago
      <i>It cannot self-propagate to any Android-based head unit</i><p>Remember that not that long ago viruses spread through floppy disks.<p>Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
      • xp8411 hours ago
        I’ve never met anyone irl who used USB sticks full of music. I know the capability is there in most cars, just never seen it. It seems like Bluetooth capability and Spotify&#x2F;Apple Music landed in mainstream cars too soon after “play MP3s from USB” was added, for that to catch on.
        • zdragnar7 hours ago
          I did it for a few years, back when I had a new car with the capability but not a phone with a good mobile data plan.<p>It had the benefit of an information center with physical buttons too, so I could navigate around my library without touch screen madness or voice commands constantly failing to understand band and song names.
        • pdonis9 hours ago
          <i>&gt; I’ve never met anyone irl who used USB sticks full of music.</i><p>I&#x27;ve been doing it for years, since it&#x27;s so much more convenient than the alternatives: plug the stick into my car and I have my whole music library there and it Just Works.
        • briHass10 hours ago
          My hand is raised. I like having 8GB of music on an old (USB2 is fine) flash drive in my car as a fallback. On longer trips I&#x27;ll hookup the Android Auto, but if I don&#x27;t need maps and it&#x27;s a quick ride, shuffle &amp; repeat all enabled on the USB source.<p>Sure beats the radio, which plays 2 songs and then 5 min of commercials&#x2F;sweepers, and has the gall to run ads on the HD text transmission on FM designed for song information.
      • charcircuit16 hours ago
        Most people just bring their phone between cars for music.
        • pdonis9 hours ago
          My phone is much clunkier to use for this than a USB stick. Plus my phone can&#x27;t store my whole music library (because there&#x27;s too much other stuff already on it), whereas a single USB stick does it easily with plenty of room to spare.
          • charcircuit5 hours ago
            Phones can access the whole internet. A USB stick can&#x27;t stream Spotify or connect to the cloud.
    • mschuster9118 hours ago
      &gt; nor does it affect Android Auto which is a &quot;dumb&quot; screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit<p>Huh, how does that work anyway? And while we&#x27;re at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
      • 306bobby17 hours ago
        Wireless AA and CarPlay use a hotspot your car emits that your phone connects to and transfers the image&#x2F;inputs&#x2F;audio that way
        • scoot30 minutes ago
          Got into a weird situation recently where my cheap android head unit was displaying Car Play from my phone, but (Google Maps) audio from my partner&#x27;s.<p>Directions weren&#x27;t coming from my phone&#x27;s speaker or the car, but testing audio in the Maps app did (from the car).<p>Still not sure what combination of connections it had managed to get itself into!
      • m-s-y18 hours ago
        Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.
        • NewJazz14 hours ago
          Wow that&#x27;s cursed, never realized that&#x27;s how it worked.
          • xp8411 hours ago
            Cursed is exactly how I would describe it - because it works great until it doesn’t and it of course gives you zero clue why it won’t connect.
          • bluGill9 hours ago
            It&#x27;s a good idea actually, but it&#x27;s also really complex to get right.<p>Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it&#x27;s not near as high bandwidth.
            • izacus1 hour ago
              &gt; Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it&#x27;s not near as high bandwidth.<p>This sentence doesn&#x27;t make much sense - Auto (and CarPlay) still work in wired mode over USB 2.0 if the head unit supports it. They never worked over Bluetooth.<p>(And they use less than 15Mbps so USB 2.0s 480MBps are more than enough)
      • russelg6 hours ago
        Not sure about CarPlay, but Android Auto connects via wifi to the head unit for the video feed.
      • dhc0218 hours ago
        The way I understand it, the connection is negotiated via BT, but then wifi is used for the fat data pipe to run the display.
      • iamjackg13 hours ago
        It uses Bluetooth to stream audio, but everything else happens through a WiFi connection exposed by the car that the phone automatically pairs with after the Bluetooth handshake.
      • alphager16 hours ago
        They didn&#x27;t run over BT. BT is used to initiate communication and share the password to a wifi-network. It then uses that Wi-Fi network for most communication, keeping the BT channel strictly for telephony.
      • StilesCrisis17 hours ago
        I thought the latest Bluetooth protocols were basically designed to hand off to an ad-hoc Wi-Fi connection between the two devices after the initial handshake. (Might be an oversimplification of the real protocol)
      • izacus16 hours ago
        They actually run over WiFi (WiFi direct IIRC) - Bluetooth is mostly just used as a setup handshake and to help the head unit decide which phone in the car should be the one connected.
    • chrisjj16 hours ago
      &gt; It cannot self-propagate to any Android-based head unit<p>Article does not say that.
      • jibal8 hours ago
        So? spicyjpeg is pointing out what is true, not just regurgitating TFA.
      • ajross16 hours ago
        Headline really quite clearly implies it, though. I think the correction is apt.<p>Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.<p>Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like &quot;Malware infects Debian based refrigerators&quot;? What&#x27;d Debian do?
        • MBCook14 hours ago
          It’s no different than how the old Ford Sync or something else could have been compromised.<p>The two big things here in my mind are:<p>1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out<p>2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford&#x2F;VW&#x2F;Volvo&#x2F;whoever
          • ajross13 hours ago
            This <i>is not</i> Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.<p>The actually vulnerable system is a custom vehicle head unit that <i>merely happens to be running a software stack based on AOSP</i>. It&#x27;s not even &quot;Android&quot; in a product marketing sense.<p>Again, it&#x27;s like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It&#x27;s insane.
            • MBCook12 hours ago
              Do you mean Android <i>Automotive</i>?
  • Retr0id20 hours ago
    &gt; Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet<p>People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
    • axegon_19 hours ago
      Almost, though I understand I am the exception rather than the rule: Personally I have an aftermarket android head unit since the standard one was incredibly basic, no real time navigation updates, updating maps was a pain in the ass and so on. Initially I did pair it with my phone but since it is an aftermarket unit from a company which apparently does not exist anymore, newer phones cannot be paired with it. So my only option was to go the opposite route and use my phone as a wireless hotspot(almost - there&#x27;s a raspberry pi with openwrt between the two). And since I self-host everything, I had no choice but to hook it up to my vpn. That said, I understand the implications of doing this so ultimately the network access it gets is incredibly limited: everything that is not my music server and the maps provider has been cut off completely. The downside is that every now and then I get a &quot;can&#x27;t connect to google services&quot; notification though that is technically reassuring from a security perspective.
    • madduci14 hours ago
      Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself
      • bluGill9 hours ago
        How long until the 4G networks are turned off? There are a lot of cars that have a 3G sim or even a 2G sim. They can do nothing because those networks have been turned off.<p>At least I&#x27;m not aware of any car where they updated the radio in the car when the network got turned off. By contrast, I work for John Deere and just down the hall from me are people who made a ton of money when the 2G network got turned off because a lot of customers paid $1,000 upgrade to a newer radio. I think most people would agree that there is no future that their car radio does that is worth paying money to upgrade when the cell network turns off. At John Deere, we&#x27;re lucky that we have found pictures that customers find valuable enough that they are willing to pay to upgrade the radio when it goes obsolete.
        • toast04 hours ago
          &gt; How long until the 4G networks are turned off? There are a lot of cars that have a 3G sim or even a 2G sim. They can do nothing because those networks have been turned off.<p>There&#x27;s a good chance it will last longer than 3G. 5G was designed to coexist with 4G so a 5G base station can (optionally) use a 4G compatible beacon and use 4G for some timeslots and 5G for others. Even if 6G doesn&#x27;t do the same, 4G <i>can</i> live until 5G is turned off. 2G and 3G needed a whole channel allocated, which was too much in the US anyway. I understand in some countries they turned off 3G but left one channel of 2G for industrial&#x2F;embedded devices; maybe one channel per network or maybe one channel that all networks could roam to ... roaming seems more permissive outside the US, too.
      • drnick112 hours ago
        Keep in mind however that the 4G SIM is not there for the driver&#x27;s benefit, but for Nissan&#x27;s. It collects extremely invasive telemetry that is then sold to data brokers and consumed by car insurers and government agencies, among others. This is why I won&#x27;t drive a car that I own without first removing the onboard modem.
        • madduci4 hours ago
          Exactly and with the malware is much worse
    • ghostly_s14 hours ago
      &quot;Pairing&quot; with a head unit is not an open socket to dump anything you care to down the wire. That would require finding a rather remarkable vulnerability in one of the audio&#x2F;address book&#x2F;screen mirroring APIs the devices use.
      • Retr0id14 hours ago
        Bluetooth RCEs have happened in the past and will happen again.
    • buckle801719 hours ago
      Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists.<p>Just off the top of my head.
      • Retr0id19 hours ago
        That&#x27;s scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).
        • wongarsu19 hours ago
          If you infect tens of vehicles that&#x27;s not that valuable. But if you infect ten thousand vehicles, convinced a trusted member of one of the bigger black hat forums it&#x27;s real and have him vouch for your marketplace post, there should be some buyers for full movement profiles, call logs and address books of ten thousand people<p>And doing that doesn&#x27;t really interfere with also setting up and selling proxy endpoints
        • stymaar19 hours ago
          Yeah, especially since most of these are already available for purchase from data brokers.
          • Zigurd19 hours ago
            They&#x27;re called data <i>brokers</i> because they have a buy side, too. That might be peanuts to you, but to an AliExpress seller, it could be most of their profit.
      • carstenhag15 hours ago
        Some head units (working with a 1st party one atm) have two networks: OEM-paid (unlimited data) and user-paid. A 3rd party apk would be consuming all bought traffic quite soon.<p>Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.
    • kotaKat19 hours ago
      It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit.<p>The only valuable thing there is the relatively &#x27;clean&#x27; mobile connection... and this malware&#x27;s dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that&#x27;s free and always-on real estate!
      • brookst19 hours ago
        Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition &#x2F; accessory mode turns off, and go completely power-off 30-ish minutes later.<p>Otherwise any car sitting unused for a week or two would have a dead battery.
        • Zigurd19 hours ago
          I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.
          • wildzzz11 hours ago
            A lot of older cars didn&#x27;t turn off their OBD port, have their headunits go into standby, or even turn off the cigarette lighter port. Early OBD ports connected to dealer computers for a few minutes, not an always on dongle. Plain headunits just play music, what could they possibly accomplish by staying on when you turn off the car? It was a convenience having the cigarette outlet left powered so you could light a cigarette without turning on the car. Other than maybe a bag phone, what would you possibly plug into that?
          • smilespray18 hours ago
            If that was one of those ELM327 dongles, yes they have 12V and are known to drain your battery. They&#x27;re only meant for short diagnostic runs.
        • olyjohn18 hours ago
          They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.
          • lmz15 hours ago
            You would hope that the ignition switch really cuts the power to the head unit when it is switched to off.
            • toast04 hours ago
              Lots of head units will lose presets when they lose power.
            • carstenhag15 hours ago
              No you wouldn’t, because then you always have a cold boot of the headunit, even if you just accidentally hit the ignition. Users want the head unit to resume within a few seconds. Just like their phone.
              • brookst10 hours ago
                That’s why head units stay in low power mode for 30ish minutes when you turn off the car.<p>They do not stay in low power for weeks. Car batteries are really not that big, and cranking an engine takes some amps. I had a Subaru crosstrek that was recalled because their cellular modem was drawing IIRC 10ma 24&#x2F;7, which would kill the car if it sat 3 or 4 days.
        • speed_spread10 hours ago
          I&#x27;m pretty certain my car could go months running Android in low power mode just from the 12v battery, never mind the traction battery. But no, they had to have the head unit boot on every start and everything is slow for a minute, especially since the last update. These people can&#x27;t code for shit.
          • toast04 hours ago
            &gt; I&#x27;m pretty certain my car could go months running Android in low power mode just from the 12v battery, never mind the traction battery.<p>Most traction batteries are behind a relay or something and won&#x27;t be available for full time use...
        • kotaKat17 hours ago
          Some of these Android units also double as DVRs and dashcam recorders (parking mode!) as well so may be hooked onto the normal +12v rail.
  • dzdt19 hours ago
    There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19751872">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19751872</a>
    • Ccecil18 hours ago
      The car hacker&#x27;s handbook [1] has a chapter on just using the infotainment system to access the CAN. Specifically mentions &quot;attacking through the update system&quot;.<p>[1]<a href="https:&#x2F;&#x2F;opengarages.org&#x2F;handbook&#x2F;ebook&#x2F;" rel="nofollow">https:&#x2F;&#x2F;opengarages.org&#x2F;handbook&#x2F;ebook&#x2F;</a> (chapter 9)
    • 0110001118 hours ago
      An aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn&#x27;t. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?
      • RealityVoid18 hours ago
        Can&#x27;t vouch for all car architectures, but in most cases the head unit is QM and safety domains are usually segmented from each other. So even if the head unit talks CAN (it needs to get car data somehow) it will only communicate with the rest of the car through a gateway that will not allow it to take any dangerous actions.
        • bluGill9 hours ago
          That&#x27;s true for most cars, but some, particularly the older cars, they weren&#x27;t as concerned about security as they should have been. And so sometimes the radio can talk to things that it probably shouldn&#x27;t be able to talk to.
      • karlshea18 hours ago
        Mine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer&#x2F;rpm app.<p>I believe the connection exists because the steering wheel buttons&#x2F;iDrive talk to the original head unit over CAN.
        • rootusrootus17 hours ago
          That’s wild, I’ve never run across a head unit that had me connect OBD2. I think I would just ignore that bit of the install instructions.
          • karlshea8 hours ago
            I did not connect ODB2. The HU I got puts itself as a passthrough to the stock BMW HU (which you still need to be able to use, you switch the screen to its output by holding down a button), and that connector includes CAN.<p>There are numerous reasons the HU needs CAN, for example to get the steering wheel angle to be able to draw the guides over the backup camera feed. Or to switch to the backup camera feed when you put the car in reverse.
        • kanbankaren16 hours ago
          &gt; speedometer&#x2F;rpm<p>This is available on standard OBD-II. Maybe, it is accessible over CAN?
          • dx410015 hours ago
            My OBD-II connector has CAN-C (500kbit) and CAN-B (50kbit) - I use CAN-B primarily because I can control windows, doors, etc + get the speed &amp; rpm.
      • wildzzz11 hours ago
        The expensive ones do so you get more of an OEM infotainment experience. I guess you could potentially cause a crash over the CAN bus but there&#x27;s a very small overlap between cars that allow you to swap out headunits and cars that can be controlled enough over CAN to cause a crash. Other than commercial vehicles, I don&#x27;t think there are any new cars that have DIN stereos anymore.
      • dx410015 hours ago
        Many do - the one I was looking at for my vehicle in particular uses it to restore the steering wheel controls (which are broadcast over the CAN-B low speed bus)
    • jiaosdjf18 hours ago
      Manufacturers should be sued to absolute oblivion for doing what any developer would tell you is a security hole.
  • jackdecker19 hours ago
    For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ?<p>I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).<p>Also, feel like John Gruber is going to have a field day with this one
    • MBCook19 hours ago
      Android Automotive is the infotainment system’s OS and runs fully without a phone.<p>Android Auto is the Google equivalent of CarPlay and runs on your phone.<p>It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.
      • jackdecker18 hours ago
        So I can use android auto on an android automotive head unit - got it but also this seems needlessly confusing naming structure. Apple TV comparison is apt lol
        • wildzzz10 hours ago
          They are intended for different market segments. The consumers use Android Auto to project their phones. The headunit manufacturers build devices to run Android Automotive with custom skins. It&#x27;s like knowing whether a smartphone running Chrome is using Blink or Webkit. The user probably doesn&#x27;t know or care, they&#x27;ll use it the same way regardless.
        • MBCook15 hours ago
          It makes perfect sense in isolation. It’s a good name.<p>Unfortunately Android Auto already existed. So it’s confusing.
        • bluGill9 hours ago
          Normally you can use Android Auto on an Android AutoMorph head unit, however that&#x27;s not required. GM regularly disables Android Auto on all their head units even though it&#x27;s included in the base Android automotive OS.<p>I have such a car and I am so disappointed that I regularly tell people I would not buy another one and I would not recommend you buy a GM because they do that trip.
      • Zigurd18 hours ago
        Did they hire their branding person from Microsoft? And how about AppFunctions (Google) and App<i>Intents</i> (Apple)?
        • izacus16 hours ago
          How would you name them?
          • Zigurd16 hours ago
            Android Connect instead of Android Auto, and any word other than recycling the android app communication nomenclature &quot;Intent.&quot; But hey I&#x27;m no branding genius so let&#x27;s workshop this to close the loop.
    • dybber19 hours ago
      I don’t believe this is Android auto running from a phone, but a situation where the manufacturer have used Android Automotive as operating system for the built in head unit. As e.g. on Volvo’s.
    • inquirerGeneral19 hours ago
      [dead]
  • davoneus19 hours ago
    The logical endpoint of the entire &quot;the car as software&quot; concept. Can&#x27;t wait for the security vendors to start hawking &quot;AV for your car&quot;
    • Retr0id19 hours ago
      I hope we see &quot;de-smartification&quot; conversion kits that replace the electronics with more straightforward (and repairable) offline equivalents. The ultimate AV.
      • j16sdiz5 hours ago
        Don&#x27;t see this happens any time soon.<p>Many feedback loops in modern car is software based and interconnected with each other.<p>Kits that works half as good without software would be very expensive to make.
        • Retr0id2 hours ago
          I didn&#x27;t say without any software at all.
    • doublerabbit18 hours ago
      It&#x27;s already in televisions. Not long now.
  • jiaosdjf18 hours ago
    &quot;How has the automotive industry adapted to decades of computing best practices?&quot;<p>- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls<p>- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps<p>- Keyless entry basically a shit show of faraday pouches<p>- OBD port allowing thieves to clone a full key in seconds<p>- Even cars in decent neighbourhoods have to use steering locks<p>Sorry but this is a fucking joke and the automotive industry is cancer.<p>At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you&#x27;re lucky. That said, Tesla&#x27;s insistence that everything be done by touch screen is dog shit.<p>All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can&#x27;t even make a fucking phone holder standard, not even a fucking mounting point so I don&#x27;t have to block an air vent.
    • smilespray18 hours ago
      You had me until you started giving Tesla the thumbs-up, despite your caveat.
    • Telaneo15 hours ago
      &gt; &quot;How has the automotive industry adapted to decades of computing best practices?&quot;<p>Simple. It hasn&#x27;t.
  • codedokode4 hours ago
    Could these proxies be sold to AI companies for scraping websites?
  • gchamonlive18 hours ago
    Can&#x27;t be safer than the non-entertainment system from WV Up! that&#x27;s just a built-in head mount for your phone. Grab one with a large screen and it&#x27;s the safest thing you can get. Android still has an auto mode for this where it controls the car&#x27;s audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it&#x27;s safer too
  • 1970-01-0119 hours ago
    ..to add to a botnet for click fraud.<p>The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn&#x27;t click on ads. It took a war for them to become a target.
    • chrisjj16 hours ago
      &gt; Those PLCs monitoring water were ignored for a very long time because they couldn&#x27;t click on ads.<p>Somehow I doubt it. They&#x27;re ripe for ransomware attack.
  • MBCook19 hours ago
    So to do this the attacker has to compromise the update servers at $CAR_COMPANY?
    • timmmmmmay18 hours ago
      no, the update servers at $sketchy_aliexpress_aftermarket_head_unit_company, probably somewhat easier
  • bluGill19 hours ago
    One more reason cars should not be internet connected. They last for decades and manufactures don&#x27;t want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.
  • hndbwksam717 hours ago
    Concise and useful, rare combo
  • doublerabbit18 hours ago
    <p><pre><code> Norton AntiVirus for your car ECU&#x27;s. Protect your carfor just $220.95&#x2F;month * * Cars without subscription causes acceleration to be restricted to 60mph. </code></pre> After discovering the new OLED televisions come with antivirus, I&#x27;m done with thinking technology will ever be secure.
    • Telaneo15 hours ago
      Even from this perspective, it&#x27;s pretty easy to make things more secure by having less technology. Have the infotainment system just be a blank canvas for Carplay or AA to display on (there does need to be a bit back and fourth, phone needs to send audio to car, car needs to send GPS, speed and state of charge to phone (not strictly necessary, but there are user benefits from the phone having this information). The car itself doesn&#x27;t need a whole internet-connected general purpose computer attached to it, but doing that is an easy way for the manufacturer to supposedly add value.<p>Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don&#x27;t need to be general purpose computing devices either. I shouldn&#x27;t have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).
  • zb318 hours ago
    I&#x27;d not consider it malware if its sole purpose is to do ad&#x2F;click fraud. The user is not the target here, the user&#x27;s enemies are :)
  • IshKebab19 hours ago
    Um so which car is this? tw.com doesn&#x27;t seem to be in use.
  • coachdaniel20262 hours ago
    [flagged]
  • miohtama19 hours ago
    [flagged]
  • promptspheree19 hours ago
    [flagged]
  • lvbyte19 hours ago
    [dead]
  • sehw19 hours ago
    [dead]
  • waazy16 hours ago
    this is crazy
  • tiahura18 hours ago
    Apple&#x27;s gatekeeping doesn&#x27;t make IPhone users any safer.