CanSecWest 2024
Presentations
From March 20 to 22
Death by a Thousand Cuts: Compromising Automotive Systems via Vulnerability Chains
In recent years, with the continuous development of electic vehicles (EV), intelligent networking and traditional auto manufacturing have collided intensely, blurring the boundary between cyber security and physical security. In the past, many attacks against cars focused on car keys, but nowadays, are cars adequate to deal with attacks from the internet? In this presentation, our goal is to hack an EV without physical contact. We will introduce our team's black box security testing on several EV models, starting from a situation where we had no debugging access, to finally chaining multiple vulnerabilities together into exploit chains for stealing the vehicle through an attack.