Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm pretty sure that the infotainment hack was completely orthogonal to whether it was Beethoven, Iron Maiden, or blissful silence.

Having said that, a successful car infotainment system attack on android auto or apple carplay could, of course, compromise your phone.

So it's up to you whether you decide to cope with that possibility by breaking the law and navigating with a handheld device, or simply declining to do banking on your phone, since successful car exploits mean the attack surface against your phone is much larger than you might presume.



> separate the audio system from your car

I was responding to a comment about the security implications of letting the infotainment system interact with the vehicle controls, and I referenced an incident where someone compromised a car via that.

I have no idea how CarPlay would compromise your phone given apples sandbox but whomever finds it is gonna have a multimillion dollar payday since iOS jailbreaks are quite valuable.


The initial convo went:

> Paying with your phone just seems like one of those separation of concerns problem.

Followed by:

> You could then separate the audio system from your car and drive around with a boombox

The first discusses behaviors of end-users. The second was a lame attempt to take the mickey of that, which is why my response clearly indicated that, to my knowledge there are zero security implications of playing your music through your car's entertainment system.

This remains true.

You are discussing design flaws, not user behavior flaws, which is why I pointed out that the design flaws you bring up, in addition to doing you bodily harm, could conceivably also be part of an exploit chain that validates the original poster's concern about using his phone for banking.

But I still sincerely doubt that the choice of playing Beethoven or Iron Maiden either directly places you at risk*, or makes a difference to the ease of exploiting any design flaws in your vehicle.

IOW, the first behavior given (not using your phone for banking) is easy to construe as prophylactic, given that, yes, in fact, peoples' credentials have been stolen from their phones and bad things have happened, due to using phones for financial transactions.

The second behavior given (use a boombox instead of your car's audio) of course could theoretically alter outcomes, but to my knowledge, there has never been a car exploit that depends on whether you have fiddled with the volume control or station selector.

* Assuming of course, that your volume isn't so loud that you've riled up other people. That's always a risk.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: