Honda Civics and the Evil Valet
- Honda Civics have security risks in their infotainment systems.
- Updates are shipped on specially-formatted USB drives with outdated Android versions.
- Arbitrary code execution is possible with physical access to the front USB port.
The Internet’s Verdict: 70% Hyped, 30% Skeptical
Security Concerns
Most cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics.
Most (if not all) cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics. What makes this even worse is the sensors they have onboard these days; the microphones, cameras, GNSS receivers, wifi and BT radios make them into mobile surveillance platforms.
Vulnerabilities
To update 10th-gen Honda Civics, Honda ships updates on specially-formatted USB drives.
To update 10th-gen Honda Civics, Honda ships updates on specially-formatted USB drives. They’re essentially Android 4.2.2rc1-era recovery packages with some Honda-added version checks (which can be spoofed).
This doesn’t require root/su and can be done with physical access to the front USB port.
Focus Keyword: Honda Civic