Daniel Cuthbert Profile picture
Documentary photographer, old creaky hacker. Co-author of @OWASP ASVS standard. Blackhat/Brucon Review Board & UK Government Cyber Security Advisory Board

Dec 5, 2018, 19 tweets

Next up, one talk I feel is huge and monumental and will impact the car hacking movement #BHEU

@ToyotaMotorCorp infotec team opening up about vehicle security. The glorious and sexy world of ECUs and CAN. CAN has no concept of security at all, and was never developed with it in mind

Hat tip to those lovable rogues @0xcharlie & @nudehaberdasher

Toyota and other car companies now actively researching and preparing for cyber security attacks. There’s a blatant lack of cyber security engineers who also understand the automotive industry. #carhacking

Today’s cars have overly large attack surface areas. Thankfully stellar efforts have been made to get people interested. @CarHackVillage but what exists is a harmless real car for people to test and to learn

What is needed is an attractive platform for vehicular cyber security . One that is open and valid. So @ToyotaMotorCorp have created PASTA.

The ability to write to ECU firmware is huge. You can create more, explore more and do so in a safe environment. #carhacking

And this is PASTA AND I JUST MANGASM’D

Very compact and made in Japan.

There are 4 ECUs that allow writing and modifying using C. OBD-II, clipping area and a junction box. This helps with physical access attack simulation and defence. Junction boxes help with addition of new ECUs. This adds to in-vehicle networks (think adaptability and making new)

They based it around the RX63N microcontroller by Renesas. Toyota designed the ECU from scratch and will release full schematics and code to @github

Then they are opening up the CAN protocol to all, no more secrets like other car manufacturers. Yes Toyota!!!

A key design choice was making this adaptable. Couple it with a model car. Oh my hat

Full interaction with simulators, which means you can test how a potential attack will impact the safety and operability of the car

This being blackhat, let’s pwn a car. Inject malicious CAN packets. Manipulate steering

To date, NO car manufacturer would even attempt at doing what Toyota has just done. I couldn’t praise Toyota enough here. This industry has adopted security through security for too long. This is what @BlackHatEvents is all about. #BHEU

Roadmap will include full support for LIN, CAN FD, IVI, wireless I/F. It’s a joint initiative with Yokohama University. They want to force discussion about the critical nature of automotive security and get everyone involved

I stand by my initial comment: this will hopefully now change the fact that vehicular security has not been taken seriously and been a closed club for few. Massive respect. github.com/pasta-auto @pasta_auto @ToyotaMotorCorp #BHEU

Final pictures of my Xmas present

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling