Author Topic: CAN bus hacked, WIRED documentary  (Read 2251 times)

0 Members and 1 Guest are viewing this topic.

Offline MTTopic starter

  • Super Contributor
  • ***
  • Posts: 1847
  • Country: aq
CAN bus hacked, WIRED documentary
« on: July 25, 2026, 11:44:10 am »


 

Offline rteodor

  • Frequent Contributor
  • **
  • Posts: 492
  • Country: ro
Re: CAN bus hacked, WIRED documentary
« Reply #1 on: July 25, 2026, 12:16:35 pm »
Adding missing TL;DW

A Bluetooth to CAN device bridge, named KARR, is installed in the car as an smart alarm system to be sold as an option. It has deep access to car functions and the BT side can be hacked with zero technical knowledge.
Sometimes the device is not desired by the buyer and in such cases it is simply deactivated but it remains active in the car network. Hackers can do stuff to the car and the car owner does not know what is happening: car can be immobilized, bricked stolen, carjacked, etc...

An awareness campaign is needed because every car has to be patched manually via the the phone BT app.
« Last Edit: July 25, 2026, 12:27:23 pm by rteodor »
 
The following users thanked this post: voltsandjolts

Offline Psi

  • Super Contributor
  • ***
  • Posts: 12640
  • Country: nz
Re: CAN bus hacked, WIRED documentary
« Reply #2 on: July 25, 2026, 12:26:44 pm »
Gaining CAN access to a car is pretty much the same as gaining root access to a PC.
So yes, if you have an insecure root shell accessible over your wifi router running WEP encryption you are pretty screwed.
Greek letter 'Psi' (not Pounds per Square Inch)
 

Offline tom66

  • Super Contributor
  • ***
  • Posts: 8848
  • Country: gb
  • Professional HW / FPGA / Embedded Engr. & Hobbyist
Re: CAN bus hacked, WIRED documentary
« Reply #3 on: July 25, 2026, 02:02:56 pm »
Gaining CAN access to a car is pretty much the same as gaining root access to a PC.
So yes, if you have an insecure root shell accessible over your wifi router running WEP encryption you are pretty screwed.

Around 70% of cars sold today do not have appropriate anti-spoofing mechanisms in the CAN bus.   It is still possible to pull off a CAN bus attack on many modern cars for the purposes of theft or access to the car, because automakers are not being pushed hard enough to improve this.
 

Online langwadt

  • Super Contributor
  • ***
  • Posts: 5789
  • Country: dk
Re: CAN bus hacked, WIRED documentary
« Reply #4 on: July 25, 2026, 02:20:04 pm »
Gaining CAN access to a car is pretty much the same as gaining root access to a PC.
So yes, if you have an insecure root shell accessible over your wifi router running WEP encryption you are pretty screwed.

Around 70% of cars sold today do not have appropriate anti-spoofing mechanisms in the CAN bus.   It is still possible to pull off a CAN bus attack on many modern cars for the purposes of theft or access to the car, because automakers are not being pushed hard enough to improve this.

as long as it requires physical access why does it really matter?


 

Offline tom66

  • Super Contributor
  • ***
  • Posts: 8848
  • Country: gb
  • Professional HW / FPGA / Embedded Engr. & Hobbyist
Re: CAN bus hacked, WIRED documentary
« Reply #5 on: July 25, 2026, 02:56:47 pm »
as long as it requires physical access why does it really matter?

Physical access to the CAN bus on modern cars is easier than you might expect. 

For instance, you can get access to CAN on many cars by taking out a headlight, which, depending on the make and model may be connected to the powertrain bus.

This is the cause for many Toyota RAV4 thefts:
https://kentindell.github.io/2023/04/03/can-injection/
 

Offline hans

  • Super Contributor
  • ***
  • Posts: 1971
  • Country: 00
Re: CAN bus hacked, WIRED documentary
« Reply #6 on: July 25, 2026, 03:05:37 pm »
Gaining CAN access to a car is pretty much the same as gaining root access to a PC.
So yes, if you have an insecure root shell accessible over your wifi router running WEP encryption you are pretty screwed.

Around 70% of cars sold today do not have appropriate anti-spoofing mechanisms in the CAN bus.   It is still possible to pull off a CAN bus attack on many modern cars for the purposes of theft or access to the car, because automakers are not being pushed hard enough to improve this.

Genuinely interested how the other 30% do protect their CAN bus against spoofing.

Afaik CAN relies on all nodes to be willing to cooperate.
If you add a "bad node" electrically or by protocol, you can screw the termination, flood the bus with high priority messages, or spoof whatever packet you want as its just a bunch of IDs+packets that are being sent around.

Obviously having headlights run on the same bus as the car doors, alarm or engine is a big design flaw.
But likewise its impossible to have each critical component on its own bus.. because its not really a bus anymore, might as well use RS232.
 

Offline bobxyz

  • Regular Contributor
  • *
  • Posts: 58
  • Country: us
Re: CAN bus hacked, WIRED documentary
« Reply #7 on: July 25, 2026, 07:21:36 pm »
I wonder how long it will be before someone reverse engineers the KARR update-over-BT app and develops their own brick-this-car update?  Sure seems like there will be lots of mayhem and lawsuits out of this.
 

Offline tom66

  • Super Contributor
  • ***
  • Posts: 8848
  • Country: gb
  • Professional HW / FPGA / Embedded Engr. & Hobbyist
Re: CAN bus hacked, WIRED documentary
« Reply #8 on: July 25, 2026, 07:31:57 pm »
Gaining CAN access to a car is pretty much the same as gaining root access to a PC.
So yes, if you have an insecure root shell accessible over your wifi router running WEP encryption you are pretty screwed.

Around 70% of cars sold today do not have appropriate anti-spoofing mechanisms in the CAN bus.   It is still possible to pull off a CAN bus attack on many modern cars for the purposes of theft or access to the car, because automakers are not being pushed hard enough to improve this.

Genuinely interested how the other 30% do protect their CAN bus against spoofing.

Afaik CAN relies on all nodes to be willing to cooperate.
If you add a "bad node" electrically or by protocol, you can screw the termination, flood the bus with high priority messages, or spoof whatever packet you want as its just a bunch of IDs+packets that are being sent around.

Obviously having headlights run on the same bus as the car doors, alarm or engine is a big design flaw.
But likewise its impossible to have each critical component on its own bus.. because its not really a bus anymore, might as well use RS232.

Yeah, you can screw with the CAN bus, but if you use higher level messaging e.g. UDS with authentication, then it doesn't matter how much you screw with the bus, you can't generate the "start drivetrain" message because you don't have the keys for each side of the link, usually assigned at manufacturing stage.
 

Offline SparkyFX

  • Frequent Contributor
  • **
  • Posts: 721
  • Country: de
Re: CAN bus hacked, WIRED documentary
« Reply #9 on: July 25, 2026, 07:43:54 pm »
The CAN-Bus itself honors spoofing with a frame collision, which requires a node to shut itself down after a set amount of occurences. So flooding the bus leads to nodes switching themselves into error passive status, right after the first collision (think something  around 100ms) as long as they follow the CAN spec and try to retransmit the erroneous frame  right afterwards. All controllers read back what they wrote and are supposed to mark an error by issuing an error frame.

Depending on manufacturer there are huge differences in what could happen. From shutdown of the whole car to limp home mode (only basic functionality available to get to the nearest garage).

If a hacker would use diagnostic commands to execute functions there are limits implemented to what can be done, e.g. there is no fully blocking the brakes while driving. But it's not standardized or mandated by law what exactly, only legal liability. What could be sent to a "connected car" changed that game slightly.

Oh, and the CAN bus is easily accessible via the on board diagnostic connector, located within 1 arms length of the driver. It is there for emissions testing, reading trouble codes and such.
« Last Edit: July 25, 2026, 07:47:24 pm by SparkyFX »
Support your local planet.
 

Online langwadt

  • Super Contributor
  • ***
  • Posts: 5789
  • Country: dk
Re: CAN bus hacked, WIRED documentary
« Reply #10 on: July 25, 2026, 07:54:13 pm »
The CAN-Bus itself honors spoofing with a frame collision, which requires a node to shut itself down after a set amount of occurences. So flooding the bus leads to nodes switching themselves into error passive status, right after the first collision (think something  around 100ms) as long as they follow the CAN spec and try to retransmit the erroneous frame  right afterwards. All controllers read back what they wrote and are supposed to mark an error by issuing an error frame.

Depending on manufacturer there are huge differences in what could happen. From shutdown of the whole car to limp home mode (only basic functionality available to get to the nearest garage).

If a hacker would use diagnostic commands to execute functions there are limits implemented to what can be done, e.g. there is no fully blocking the brakes while driving. But it's not standardized or mandated by law what exactly, only legal liability. What could be sent to a "connected car" changed that game slightly.

Oh, and the CAN bus is easily accessible via the on board diagnostic connector, located within 1 arms length of the driver. It is there for emissions testing, reading trouble codes and such.

the OBD connector will only give you limited access for reading trouble codes and such standardized requests, to get any further than that you need codes

 

Offline u666sa

  • Frequent Contributor
  • **
  • Posts: 893
  • Country: us
  • Miami, FL
    • Codernov Electronics Repair
Re: CAN bus hacked, WIRED documentary
« Reply #11 on: July 25, 2026, 08:53:53 pm »
Pretty much any leased or financed car has this thing. Since buying with cash is rare and frowned upon, yes. All cars have this KARR system installed.  :popcorn:
 

Offline tom66

  • Super Contributor
  • ***
  • Posts: 8848
  • Country: gb
  • Professional HW / FPGA / Embedded Engr. & Hobbyist
Re: CAN bus hacked, WIRED documentary
« Reply #12 on: July 25, 2026, 09:50:23 pm »
Oh, and the CAN bus is easily accessible via the on board diagnostic connector, located within 1 arms length of the driver. It is there for emissions testing, reading trouble codes and such.

There are usually multiple CAN buses in modern vehicles.  The CAN signals on the OBD-II port should go to the BMS as the gateway.  It might be shared with some of the infotainment stuff, but this varies by vehicle.  But it absolutely should not be connected directly to the powertrain bus, as that is a significant safety issue (losing powertrain bus at speed due to a wonky diagnostics tool, for instance).
 

Offline default0.0player

  • Regular Contributor
  • *
  • Posts: 106
  • Country: cn
Re: CAN bus hacked, WIRED documentary
« Reply #13 on: July 25, 2026, 09:55:09 pm »
Can we, as customers, hack the CAN bus of our own cars to bypass the DRM as shown here?
 

Offline Psi

  • Super Contributor
  • ***
  • Posts: 12640
  • Country: nz
Re: CAN bus hacked, WIRED documentary
« Reply #14 on: July 25, 2026, 11:16:13 pm »
Anyone pushing for CAN bus security should understand that the only security your likely to get from that push will block auto repairs and make repair more expensive. The manufacturers will be the only ones holding all the keys.
You'll end up where auto repair shops have to pay for expensive one-time keys to perform repair tasks.

The push shouldn't be for CAN bus security, it should be a push for right to repair first.
Otherwise it's likely to make things worse.
« Last Edit: July 25, 2026, 11:27:52 pm by Psi »
Greek letter 'Psi' (not Pounds per Square Inch)
 
The following users thanked this post: spostma

Online ConKbot

  • Super Contributor
  • ***
  • Posts: 1418
Re: CAN bus hacked, WIRED documentary
« Reply #15 on: July 26, 2026, 01:18:17 am »
Oh boy, if the auto manufacturers don't add encryption and the trusted platform module from PCs into  car headlights, then you car is going to get stolen and you're going to have horrible things happen to your back side in a parking garage. :palm:

No, it's not justifying making 3rd party replacements not work. It's only a part frequently damaged in accidents, and even rendered too damaged to work safely by the sun. You're being paranoid.
 

Online langwadt

  • Super Contributor
  • ***
  • Posts: 5789
  • Country: dk
Re: CAN bus hacked, WIRED documentary
« Reply #16 on: July 26, 2026, 01:57:34 am »
Oh boy, if the auto manufacturers don't add encryption and the trusted platform module from PCs into  car headlights, then you car is going to get stolen and you're going to have horrible things happen to your back side in a parking garage. :palm:

No, it's not justifying making 3rd party replacements not work. It's only a part frequently damaged in accidents, and even rendered too damaged to work safely by the sun. You're being paranoid.

they point of "component protection" is to stop people stealing your stupidly expensive head lights etc. and selling the used.

thief are stealing mirrors from some cars  because they contain cameras and sensors (blind-spot detection, lane assist) the can easy cost €1000 each

the fallout will of course be that soon you can't just get a used one be cause it' be encrypted and married to the car

 

Offline Randy222

  • Super Contributor
  • ***
  • Posts: 1826
  • Country: ca
Re: CAN bus hacked, WIRED documentary
« Reply #17 on: July 26, 2026, 02:00:27 am »
CANbus, wifi, BT, IIS, SQL, linux, ntkrnl, etc.

There's always a way in, it's software.

Not even Mythos combing the source code can stop it.
 

Online langwadt

  • Super Contributor
  • ***
  • Posts: 5789
  • Country: dk
Re: CAN bus hacked, WIRED documentary
« Reply #18 on: July 26, 2026, 02:04:04 am »
CANbus, wifi, BT, IIS, SQL, linux, ntkrnl, etc.

There's always a way in, it's software.

Not even Mythos combing the source code can stop it.

if you separate out the wireless stuff and make there wires inaccessible from outside, you'll at least need to get in the car and then all bets are off anyway
 

Offline Cyclotron

  • Supporter
  • ****
  • Posts: 2237
  • Country: us
  • *POOF*
Re: CAN bus hacked, WIRED documentary
« Reply #19 on: July 26, 2026, 04:18:58 am »
Car's that are easy enough to roll under you can pop the trans connector pop a Tee in and add your own node to the bus.
This bus is almost always directly connected to the ECU and Security node so you're in.
 

Offline Randy222

  • Super Contributor
  • ***
  • Posts: 1826
  • Country: ca
Re: CAN bus hacked, WIRED documentary
« Reply #20 on: July 26, 2026, 04:27:51 am »
CANbus, wifi, BT, IIS, SQL, linux, ntkrnl, etc.

There's always a way in, it's software.

Not even Mythos combing the source code can stop it.

if you separate out the wireless stuff and make there wires inaccessible from outside, you'll at least need to get in the car and then all bets are off anyway

Moderns vehicles have something like 20+ ECM devices hooked in. Getting one of them to do something it normally would not do, via Rf, is probable.

Being wired is just the easy way.

IIRC, not too long ago, the hacker(s) was able to reach up into wheel-well and connect to a connector which then allowed them to unlock the vehicle, start it, drive away.
 

Offline rteodor

  • Frequent Contributor
  • **
  • Posts: 492
  • Country: ro
Re: CAN bus hacked, WIRED documentary
« Reply #21 on: July 26, 2026, 07:50:34 am »
CANbus, wifi, BT, IIS, SQL, linux, ntkrnl, etc.

There's always a way in, it's software.

Not even Mythos combing the source code can stop it.

Cost and effort can and often do stop it.
 

Offline hans

  • Super Contributor
  • ***
  • Posts: 1971
  • Country: 00
Re: CAN bus hacked, WIRED documentary
« Reply #22 on: July 26, 2026, 08:35:01 am »
Doubtful :)

I've worked in agriculture automotive branch before. Reverse engineering was part of the game to add a special customer to the pool, which had a different machine that maybe required some specific CAN messages to be spoofed.
Later on I patched some other ECUs in machine code to have it behave in how I wanted it to be.

I'm sure agriculture business is a lot more "wild west" than road automotive, since tractors are workhorses on closed fields that make farmers a lot of $$$. So inevitably they want them to do exactly what they want/need. Not all of them are too concerned about safety, ironically.

Thats different than say chiptuning which is mainly "because we can", and which is often fairly cheap once someone pulls it off. But finding the maps within new car ECUs, a way to unlock these chips and reprogram them, etc. is also often the result of a lot reverse engineering work.

In my experience, protections etc. only cause slow downs to this process. Especially if you own the exact hardware and one is willing to sacrifice a module for this purpose.

To be honest I will grief the day when agriculture manufacturers start encrypting their whole CAN bus, because I have very fond memories of having electronics/software "magic switch" to make proprietary garbage do things I want them to do..
 

Offline JPortici

  • Super Contributor
  • ***
  • Posts: 3914
  • Country: it
Re: CAN bus hacked, WIRED documentary
« Reply #23 on: July 26, 2026, 09:38:18 am »
sometimes chiptuning is also "because we're good" ;) nowadays chiptuning is not only to increase power.

We were thinking about replicating this KARR system, too, as we also make some antitheft devices, some based on bluetooth for authentication which is, i know, a poor choice but it's convenient. The client wants something that's convenient, unfortunately, even if we're about to do full circle and go back to modding the physical buttons (instead of reading them through CAN)

Now, if only manufacturer stopped doing retarded shit such as having the security bits share the bus with components that can be reached from the outside of the car (like alfa romeo, land rover and toyota... You don't even have to remove the hadlight for some toyotas, you can reach and empty connector from behind the wheel), or keep an unautheticated, always on, wifi connection (kia, hyundai, suzuki, ...) to the radio that can access the main bus bypassing the gateway, and security keys sent in plaintext, and keep the same between models...

My very old punto had better software security than a luxury car today
 

Offline mendip_discovery

  • Super Contributor
  • ***
  • Posts: 1163
  • Country: gb
Re: CAN bus hacked, WIRED documentary
« Reply #24 on: July 26, 2026, 10:21:58 am »
I wonder if you can access these systems via the trailer connection on some cars. That would be rather worrying.

I have a external WiFi antenna and I have a a kinda reverse wardrive as it picks up all the cars that pass. I have wondered if I could finger print track these cars just from the WiFi hotspot.
Motorcyclist, Nerd, and I work in a Calibration Lab :-)
--
So everyone is clear, Calibration = Taking Measurement against a known source, Verification = Checking Calibration against Specification, Adjustment = Adjusting the unit to be within specifications.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->