← Back to context

Comment by MBCook

5 hours ago

It’s no different than how the old Ford Sync or something else could have been compromised.

The two big things here in my mind are:

1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out

2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever

This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.

The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.

Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.