Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News
    • Blogs
    • Security Watch

    Impress Chicks: Hack Your Car’s GPS

    Written by

    Lisa Vaas
    Published April 20, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      It is now possible to plant a bullfight on the highway to block your parents from coming home too early (SatNav Code 1456), plant a bomb alert at your house (SatNav Code 1516) or misdirect a rival to a meadow, where you can then confront him and steal his girlfriend, because, as the GPS hackers say (insert heavy French accent):

      “I am ze evil hacker, so now you are een my power.”

      Such was the message from GPS hackers Andrea Barisani—chief abuse officer of the CanSecWest security conference and chief security engineer at Inverse Path—and Inverse Path Hardware Hacker Daniele Bianco.

      This skullduggery—which can also include planting boxing matches, fog, airplane crashes and a host of other alerts on a car’s navigation system—is possible because there’s essentially no form of data authentication in RDS-TMC (Radio Data System-Traffic Message Channel), the service now being used throughout Europe and North America to enable in-car satellite navigation.

      Traffic information displayed on SatNav, the GPS technology in Barisani’s Honda, is “implicitly trusted” by drivers, he said, which means that many nasty things can be attempted.

      TMC uses RDS for transmission over FM broadcasts: Traffic messages are sent from a TIC (Traffic Information Center) to radio broadcast stations, which broadcast the messages to GPS-enabled car receivers.

      Barisani and Bianco tested the feasibility of decoding and injecting arbitrary TMC messages into a victim (i.e., Barisani’s car) using off-the-shelf software and cheap electronics. One component, for example, was a commercially available RDS-TMC encoder. The encoder costs about $40, but you can build your own, the hackers said.

      A simplified description of their technique: To communicate with the encoder’s chip set, the duo used an I2C bus and a custom C application. They set all the relevant parameters, such as PTY (Program Type) and PI (Program Identification) in the RDS data. An FM transmitter can be tuned to arbitrary frequencies, but it’s important to have a stable transmitter for data injection, Barisani said. This setup can cover long distances, but it might be desirable to keep it short enough to reach only the victim car, he said.

      The hack further involves locking the SatNav tuner and then hijacking channels through obfuscation of channel and sending of packets. When SatNav locks on to the hijacked channel, the hackers send a fake FM broadcast over an unused frequency.

      Wait. You would want to do this why?

      To impress chicks, as was demonstrated in a video clip of the scene described above: enemy is misdirected to meadow, waiting hacker confronts enemy, pwned enemy falls to his knees, girlfriend croons “Who are you?”, evil hacker winds up locked in passionate embrace, etc.

      Barisani noted that upon explanation of his research work, his father inquired as to his son’s plans regarding getting a life. His initial list of possible GPS code injection includes messages informing drivers of traffic backups, bad weather, full parking lots, overcrowded service areas, accidents and roadworks.

      Where it really gets interesting, Barisani said, is in the ability to close roads, bridges and tunnels with a number of events, including messages that certain routes are closed, that there’s no through traffic or that there are accidents ahead.

      “The Event table supports a number of security-related messages,” Barisani said. “I doubt anyone ever used them so far.”

      The messages pose “a very interesting target for social engineering purposes,” he said. “Homeland Security would freak out.” That’s because Code 1518 pertains to a terrorist incident, while Code 1481 pertains to an air raid danger. Other alerts pertain to air crashes, bomb alerts, delays due to parades and many more.

      TMC supports lightweight encryption for commercial services, used for signal discrimination rather than authentication. Only Location Code is encrypted, but the encryption key can be “trivially” broken by sampling some data, the hackers said. Terminals that support encryption are also expected to access unencrypted data, so code injection is still possible regardless of encryption.

      There are other technologies on the horizon that would stand a better chance at blocking tampering. TPEG (Transport Protocol Experts Group) is the new standard designed for replacing TMC. It supports encryption, but encryption still remains optional. GST (Global System for Telematics) is another, one that’s an “impressive new architecture for delivering a number of services,” Barisani said, but adoption is many years away.

      Another possibility is Microsoft DirectBand, used for MSN Direct, another FM subcarrier channel for data transmission. It has more bandwidth—15 times that of RDS—and full encryption. Other than special wristwatches, it’s also been used on SatNav systems for traffic information, but it’s a closed standard that’s not available in Europe.

      It looks “very promising,” Barisani said, and he’d be happy to play with it.

      My advice: Paper maps still work.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×