{"id":80070,"date":"2016-08-06T12:45:46","date_gmt":"2016-08-06T16:45:46","guid":{"rendered":"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/index.php\/"},"modified":"2022-07-09T16:58:54","modified_gmt":"2022-07-09T20:58:54","slug":"slam-the-door-on-hackers","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/slam-the-door-on-hackers\/","title":{"rendered":"Slam the Door on Hackers"},"content":{"rendered":"<p><a href=\"http:\/\/mitechnews.com\/new-products-contracts\/acg-detroit-hosts-discussion-on-how-automotive-and-technology-collide\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-104971\" title=\"Slam the Door on Hackers\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/connectedcar-logo.png?resize=105%2C90&#038;ssl=1\" alt=\"Slam the Door on Hackers\" width=\"105\" height=\"90\" \/><\/a>Last year two white-hat hackers Charlie Miller and Chris Valasek, <a href=\"http:\/\/www.theverge.com\/2015\/7\/21\/9009213\/chrysler-uconnect-vulnerability-car-hijack\" target=\"_blank\" rel=\"noopener noreferrer\">remotely <strong>compromised<\/strong><\/a><strong> a <a href=\"http:\/\/www.jeep.com\/en\/cherokee\/\" target=\"_blank\" rel=\"noopener noreferrer\">Jeep Cherokee<\/a><\/strong>. The <strong>cybersecurity<\/strong> researchers used\u00a0 existing functionality in the car to take control.\u00a0 They were able to disable the car\u2019s transmission and brakes, while the vehicle was in reverse, and take over the steering wheel.<\/p>\n<p id=\"W1F7Px\"><em><a href=\"https:\/\/karambasecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104990 size-thumbnail\" title=\"Karamba Security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Karamba_Logo.png?resize=75%2C72&#038;ssl=1\" alt=\"Karamba Security\" width=\"75\" height=\"72\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Karamba_Logo.png?resize=75%2C72&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Karamba_Logo.png?resize=150%2C144&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Karamba_Logo.png?w=404&amp;ssl=1 404w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a><a href=\"http:\/\/www.theverge.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">The Verge<\/a><\/em> <a href=\"http:\/\/www.theverge.com\/2016\/8\/2\/12353186\/car-hack-jeep-cherokee-vulnerability-miller-valasek\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> the researchers are back and have <a href=\"https:\/\/www.wired.com\/2016\/08\/jeep-hackers-return-high-speed-steering-acceleration-hacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">compromised their Jeep Cherokee<\/a>, fooling the car into doing <strong>dangerous things. <\/strong>Things like turning the steering wheel or activating the parking brake at highway speeds. This year&#8217;s attack requires physical access to the car.<\/p>\n<h3>Hackers use the diagnostic port<\/h3>\n<p>The team used a laptop connected to the <strong><a title=\"On-board diagnostics\" href=\"http:\/\/en.wikipedia.org\/wiki\/On-board_diagnostics\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">OBD II<\/a> engine diagnostic port<\/strong> to control even more vehicle systems. The <em>Verge<\/em> says the researchers were able to update the electronic control unit. This allowed them to take control of the steering at any time. They could turn the steering wheel at any speed, activate the parking brake, or adjust the cruise control settings.<\/p>\n<h3>Electronic control unit<\/h3>\n<p>Most operations in a car have their own designated <strong>electronic control unit<\/strong> (<a title=\"Engine control unit\" href=\"https:\/\/en.wikipedia.org\/wiki\/Electronic_control_unit\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">ECU<\/a>) controller. Some ECU&#8217;s manage things like a car\u2019s navigation and entertainment systems. Others manage more <strong>critical systems<\/strong> like braking and fuel injection.<\/p>\n<p><a href=\"http:\/\/www.orange-business.com\/en\/blogs\/connecting-technology\/security\/hackers-use-dab-radio-as-back-door-into-connected-car\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104975\" title=\"Radio are a gateway for attackers\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hacker_car_radio.jpg?resize=140%2C70&#038;ssl=1\" alt=\"Radio are a gateway for attackers\" width=\"140\" height=\"70\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hacker_car_radio.jpg?resize=150%2C75&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hacker_car_radio.jpg?resize=75%2C38&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hacker_car_radio.jpg?w=460&amp;ssl=1 460w\" sizes=\"auto, (max-width: 140px) 100vw, 140px\" \/><\/a>A connected car\u2019s ECUs all operate on one network, self-contained within the vehicle. Tel Aviv start-up <strong><a href=\"https:\/\/karambasecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Karamba<\/a><\/strong> co-founder David Barzilai, warns. \u201c<em>If hackers gain access to just one of these controllers, they can get to all of them.<\/em>\u201d<\/p>\n<h3>Harden ECU<\/h3>\n<p>The Israeli company hopes to sell <a href=\"https:\/\/www.karambasecurity.com\/product\" target=\"_blank\" rel=\"noopener noreferrer\">Carwall<\/a> Detroit automakers. Carwall is a tool that <strong>installs anti-hacking technology<\/strong> into chip-bearing auto parts before they hit the assembly line. Rgis could prevent hackers from crashing your new <a title=\"Connected car\" href=\"http:\/\/en.wikipedia.org\/wiki\/Connected_car\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">connected car<\/a>. Mr. Barzilai <a href=\"https:\/\/techcrunch.com\/2016\/04\/07\/karamba-security-raises-2-5-million-to-keep-hackers-out-of-connected-cars\/\" target=\"_blank\" rel=\"noopener noreferrer\">told<\/a> <em><a href=\"https:\/\/techcrunch.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">TechCrunch<\/a><\/em> the startup\u2019s technology can head off hackers at the pass. Carwall \u201c<strong>hardens\u201d the controller<\/strong>s, or small computers, within a vehicle that are externally connected.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20201111205158\/https:\/\/timscogitorium.com\/tinblog\/2011\/03\/your-car-now-needs-a-different-kind-of-firewall.html\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104977 size-thumbnail\" title=\"Carwell, a tool that installs anti-hacking technology\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/firewall.gif?resize=75%2C75&#038;ssl=1\" alt=\"Carwell, a tool that installs anti-hacking technology\" width=\"75\" height=\"75\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/firewall.gif?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/firewall.gif?resize=150%2C150&amp;ssl=1 150w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>Karamba\u2019s Carwall is installed on the controllers, either as a retrofit or before the controllers are built into new cars. The software <strong>locks in the factory settings<\/strong>, and prevents any foreign code or banned behaviors from running on them. This essentially <strong>blocks a hackers<\/strong> ability to reach into a car\u2019s CAN Bus, and mess with the car\u2019s critical functions.<\/p>\n<p>\u201c<em>If indeed we are successful \u2013 if all hacks are blocked \u2013 then [you] don\u2019t have to worry<\/em>,\u201d said Karamba\u2019s Barzilai. &#8220;A<em> hack that crashes your software is bad enough. A hack that crashes your car takes it to a whole new level.<\/em>\u201d<\/p>\n<p>Karamba\u2019s technology is designed to monitor every bit of code that tries to run on the ECUs and to make sure it <strong>comes from legitimate sources<\/strong>. \u201cWe are the gatekeepers,\u201d Mr. Barzilai <a href=\"http:\/\/mitechnews.com\/cyber-defense\/israeli-company-offers-detroit-chip-technology-prevent-car-hacking\/\" target=\"_blank\" rel=\"noopener noreferrer\">told<\/a> <em><a href=\"http:\/\/mitechnews.com\/cyber-defense\/israeli-company-offers-detroit-chip-technology-prevent-car-hacking\/\" target=\"_blank\" rel=\"noopener noreferrer\">MiTechNews<\/a><\/em>.<\/p>\n<h3>Out of stealth mode<\/h3>\n<p><em><a href=\"http:\/\/www.itproportal.com\/2015\/07\/28\/inside-secure-securing-connected-cars-needs-holistic-approach\/\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104979\" title=\"monitor every bit of code that tries to run\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/car_hack_protect-e1569016268178-150x100.jpg?resize=135%2C90&#038;ssl=1\" alt=\"monitor every bit of code that tries to run\" width=\"135\" height=\"90\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/car_hack_protect-e1569016268178.jpg?resize=150%2C100&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/car_hack_protect-e1569016268178.jpg?resize=75%2C50&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/car_hack_protect-e1569016268178.jpg?w=272&amp;ssl=1 272w\" sizes=\"auto, (max-width: 135px) 100vw, 135px\" \/><\/a>TechCrunch<\/em> says Karamba has not yet scored a contract with top automotive suppliers that make ECU\u2019s. They are targeting firms like <a href=\"https:\/\/web.archive.org\/web\/20161004181259\/http:\/\/www.continental-automotive.com\/www\/automotive_de_en\/themes\/passenger_cars\/chassis_safety\/passive_safety_sensorics\/electronic_control_units\/\" target=\"_blank\" rel=\"noopener noreferrer\">Continental<\/a>, <a href=\"https:\/\/web.archive.org\/web\/20170326112606\/http:\/\/www.bosch.com\/en\/com\/bosch_group\/business_sectors_divisions\/automotive_technology\/automotive_electronics\/automotive-electronics.html\" target=\"_blank\" rel=\"noopener noreferrer\">Robert Bosch<\/a>, <a title=\"Delphi Automotive\" href=\"https:\/\/www.borgwarner.com\/newsroom\/press-releases\/2020\/10\/02\/borgwarner-completes-acquisition-of-delphi-technologies\" target=\"_blank\" rel=\"homepage nofollow noopener noreferrer\">Delphi Automotive<\/a>, or <a href=\"http:\/\/news.panasonic.com\/global\/topics\/2015\/44285.html\" target=\"_blank\" rel=\"noopener noreferrer\">Panasonic<\/a>. But it has only just emerged from stealth and begun to shop its security software around.<\/p>\n<p><a href=\"http:\/\/www.ylventures.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">YL Ventures<\/a> has invested $2.5 million to fund Karamba\u2019s growth, <em>MiTechNews<\/em> reported. Compared with the funding that some <a title=\"Silicon Valley\" href=\"http:\/\/maps.google.com\/maps?ll=37.37,-122.04&amp;spn=1.0,1.0&amp;q=37.37,-122.04 (Silicon%20Valley)&amp;t=h\" target=\"_blank\" rel=\"geolocation nofollow noopener noreferrer\">Silicon Valley<\/a> security companies pick up, that\u2019s not a huge amount. But it\u2019s enough to move CEO Ami Dotan to <a href=\"https:\/\/www.google.com\/maps\/place\/2723+S+State+St,+Ann+Arbor,+MI+48104\/@42.2476226,-83.7407027,1458m\/data=!3m1!1e3!4m5!3m4!1s0x883cafbf2a8141b1:0xa3ebecd9ca5ed52d!8m2!3d42.2476186!4d-83.7385194\" target=\"_blank\" rel=\"noopener noreferrer\">Ann Arbor<\/a>, where he\u2019ll start making sales calls.<\/p>\n<p>Karamba isn&#8217;t alone in attacking <a href=\"https:\/\/wp.me\/p2wgaW-kp0\" target=\"_blank\" rel=\"noopener noreferrer\">car security<\/a>. <a href=\"https:\/\/securitycloud.symantec.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Symantec<\/a> (<a title=\"NASDAQ: SYMC\" href=\"http:\/\/www.google.com\/finance?q=NASDAQ:SYMC\" target=\"_blank\" rel=\"googlefinance nofollow noopener noreferrer\">SYMC<\/a>), the old school antivirus firm is working on auto security within its &#8220;internet of things&#8221; unit. Symantec recently released a\u00a0 white paper &#8220;<a href=\"https:\/\/web.archive.org\/web\/20150906104428\/http:\/\/www.symantec.com:80\/content\/en\/us\/enterprise\/other_resources\/building-security-into-cars-iot_en-us.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Building Comprehensive Security into Cars<\/a>,&#8221; (PDF) detailing the many electronics and sensors that have to be protected.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<div>\n<p><em>Chrysler is doing a small part to reduce connected car hacking. They recently launched a <a href=\"https:\/\/web.archive.org\/web\/20210127073904\/https:\/\/bugcrowd.com\/fca\" target=\"_blank\" rel=\"noopener noreferrer\">bug bounty program<\/a> with <a href=\"https:\/\/web.archive.org\/web\/20211203141145\/https:\/\/www.bugcrowd.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bugcrowd<\/a> that will pay out as much as $1,500 per bug found. On the other hand, Apple is offering a bug bounty of up to <a href=\"https:\/\/www.securityweek.com\/apple-offers-200000-bug-bounty-program\" target=\"_blank\" rel=\"noopener noreferrer\">$200,000<\/a> for bugs that won&#8217;t kill you.<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"http:\/\/www.digitaltrends.com\/cars\/jeep-hackers-return-with-new-tricks\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Latest Jeep hack reminds us why we should keep our cars&#8217; software updated<\/a> (digitaltrends.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Israeli startup Karamba has developed Carwall, a firewall for electronic control units (ECU) to keep hackers out of your connected car.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[2686,276,1733,2544,166,2739,2740,832,2738,1788,2741,19,4,2742,165,1366,2737],"class_list":["post-80070","post","type-post","status-publish","format-standard","hentry","category-cars","tag-2686","tag-ann-arbor","tag-chrysler","tag-connected-cars","tag-detroit","tag-ecu","tag-fca","tag-internet-of-things","tag-israel","tag-jeep","tag-karamba","tag-michigan","tag-security","tag-start-up","tag-symantec","tag-symc","tag-tel-aviv"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/80070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=80070"}],"version-history":[{"count":16,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/80070\/revisions"}],"predecessor-version":[{"id":129989,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/80070\/revisions\/129989"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=80070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=80070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=80070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}