Honda Civics and the Evil Valet(juniperspring.org)
390 points by librick 1 day ago | 94 comments
tl;dr: A reverse engineer discovered that 2021 Honda Civic headunits accept USB firmware updates signed with the publicly-known AOSP test key, enabling arbitrary code execution with brief physical access to the cabin USB port—an attack dubbed "EvilValet." The author released ota-builder and apk-rebuilder tools to facilitate building custom update files and reverse engineering, and is calling for contributors to catalog headunit versions and extend tooling since they're winding down active work on the project.
HN Discussion:
  • Confirms the technical findings and shares firsthand verification of the vulnerability
  • Broader concern that automotive infotainment systems are insecure surveillance platforms
  • ~Celebrates the weak signing as a positive enabling owner control and hardware ownership rights
  • Speculates about deeper security implications like CAN bus access and telematics abuse
  • Criticizes Honda's software competence and corporate security theater around signing practices