Reply to topic  [ 4 posts ] 
BMW ConnectedDrive hacked 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
The ADAC (German equivalent of the AA) asked Heise Press (well respected computer magazine publisher) to find them an expert to look into what the cars were sending home to BMW.

Heise found an expert and lo and behold, he found, like Superfish last week, that BMW uses the same private key for all BMWs with ConnectedDrive! That means any car set-up to use the smartphone-to-unlock feature can be overridden! I read the article in German a couple of weeks ago, but I just found out that they have a translated version and it is no longer behind their paywall (subscribers get exclusive access for the first 2 weeks, then it is free for everyone).

http://www.heise.de/ct/artikel/Beemer-O ... 40957.html

Basically the modem chip does the encryption, uses weak security and can be hacked by a MitM attack using a Linux laptop with 3G/4G card. It took the security expert a while, he had to dismantle a working ConnectedDrive box and do some real work, but he found the weaknesses and could open BMWs easily.

You need to do some real hardware hacking to get the information, but once you have it, you can open any BMW that uses ConnectedDrive - the ones with the complete Infotainment system aren't susceptible to this attack, according to the security specialist.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Mon Mar 02, 2015 3:59 pm
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Fri Apr 24, 2009 6:37 am
Posts: 6954
Location: Peebo
Reply with quote
big_D wrote:
You need to do some real hardware hacking to get the information, but once you have it, you can open any BMW that uses ConnectedDrive - the ones with the complete Infotainment system aren't susceptible to this attack, according to the security specialist.


<tinfoil hat>It's a scam to sell more options :D </tinfoil hat>

_________________
When they put teeth in your mouth, they spoiled a perfectly good bum.
-Billy Connolly (to a heckler)


Mon Mar 02, 2015 5:02 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:26 pm
Posts: 17040
Reply with quote
Interesting. I have a friend who has quite a posh beemer with that software, I've passed it on to him. Thanks for finding the translation :).


Mon Mar 02, 2015 5:18 pm
Profile
Has a life

Joined: Tue Feb 17, 2015 11:12 pm
Posts: 74
Reply with quote
I dont like bmw drivers


Tue Mar 03, 2015 11:46 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 4 posts ] 

Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.