CanSecWest 2024

Presentations

From March 20 to 22

Linfeng Xiao, Qican Ma, RapidDNS Robert Yuen Linfeng Xiao, Qican Ma, RapidDNS Robert Yuen

Death by a Thousand Cuts: Compromising Automotive Systems via Vulnerability Chains

In recent years, with the continuous development of electic vehicles (EV), intelligent networking and traditional auto manufacturing have collided intensely, blurring the boundary between cyber security and physical security. In the past, many attacks against cars focused on car keys, but nowadays, are cars adequate to deal with attacks from the internet? In this presentation, our goal is to hack an EV without physical contact. We will introduce our team's black box security testing on several EV models, starting from a situation where we had no debugging access, to finally chaining multiple vulnerabilities together into exploit chains for stealing the vehicle through an attack.

Read More