What are the risks of using the obd interface?

OBD's original purpose is two, one is to provide maintenance personnel with a test interface, and the other is to determine emission standards. Whether it is maintenance or environmental protection, OBD is functionally outputting the vehicle's ECU parameters to an external device. Therefore, AutomaTIc, ClickDrive, Dash represent a lot of hardware, and the entrance of OBD is approved. With the data flow and data computing capabilities of smart phones, many cards such as smart, economical and environmentally friendly vehicles are played. The domestic water testers first came into contact with OBD, and they were deeply fascinated by the unlimited data interface of “Qian Jing”. They rushed into the market. Since 2012, the vehicle OBD has become active in the domestic market and has become a dream. Open the "Golden Key" of the car networking gate.

What are the risks of using the obd interface?

With the continuous development and popularization of engine electronic control technology, coupled with the rise of the Internet of Vehicles, OBD fault diagnosis is becoming more and more familiar to everyone. Now the red flag driving school Xiaobian will tell you about the specificity of the OBD interface function and pin definition of the car fault diagnosis. Happening. . OBD full name: On Board DiagnosTIcs translated into Chinese is: The on-board automatic diagnosis system "OBD II" is "on Board DiagnosiTIcs II", which is the abbreviation of Type II on-board diagnostic system. In order to standardize the diagnosis of vehicle emissions and drive-related faults, since 1996, all new vehicles sold in the United States must have similar diagnostic instruments, fault codes and maintenance procedures, that is, comply with OBD II procedures. As economic globalization and automobile internationalization become more and more high, as a basis for driving and emission diagnosis, OBD II system will be more and more widely implemented and applied.

The OBD II program makes car fault diagnosis simple and uniform, and maintenance personnel do not need to specialize in learning each manufacturer's new system. For example, the OBD system will monitor the vehicle's exhaust gas from the engine's operating conditions at any time. If it exceeds the standard, it will immediately issue a warning. When the system fails, the fault (MIL) light or the check engine (Check Engine) warning light is on, and the powertrain control module (PCM) stores the fault information in the memory, and the fault code can be read from the PCM through a certain program. . According to the fault code, the maintenance personnel can quickly and accurately determine the nature and location of the fault.

In 2014, the researchers collected 19 domestic (12 domestic, 7 foreign) OBD products and nearly 60 mobile internet applications. Comprehensive safety testing and evaluation is performed for each application.

1. 50% of the OBD boxes being investigated have communication security risks or are even used to control the car

What are the risks of using the obd interface?

2. 7 out of every 10 Android car apps have a moderate to high privacy risk

The amount of privacy breaches does not directly represent the level of development of application security. In fact, in order to fully obtain the personal privacy information and vehicle information of their application users, many manufacturers actively collect too many user personal information in the application development code, and submit this information to the cloud service database to create a user's file. To facilitate future service promotion and accurate advertising. The geographic location is the most common collection of information, and up to 90% of the car network OBD applications collect the user's geographic location for real-time traffic conditions, GPS positioning and driving itineraries. Cell phone information (IMSI/IMEI) SMS and address book information are also in the category of high frequency information collection. The image below is a distribution of "Privacy Disclosure Scores". Up to 70% of IoT applications have a medium to high user privacy breach.

What are the risks of using the obd interface?

3. 60% of Android app has more than 3 security vulnerabilities

Among the survey applications, URI and component exposure accounted for the largest proportions of 77.2% and 69.8%, respectively. In terms of code protection, code confusing techniques are not commonly used.

What are the risks of using the obd interface?

We conducted safety tests on two foreign OBD products, and the results were not optimistic. It is easy to find the function that sends the instruction in one of the code programs, and the proprietary protocol is too simple. As long as the corresponding command is sent to the device via Bluetooth via the mobile phone, the purpose of controlling the car can be achieved. The other is even worse, basically no anti-reverse measures, code confusion, but the confusion is weak, no reinforcement, resulting in code logic leaks. No perception of repackaging. It is easy to tamper with the program flow or implant malicious java code.

Before installing, you must understand whether the product reads data or writes data. The obd has no effect, but the data is written to have a certain impact. How to distinguish it is not to impose some actions on the car itself, such as remote start. Influential

Filing Cabinet

A filing cabinet refers to a metal cabinet in which documents and materials are placed. It is an indispensable thing in work and life. A narrow sense file cabinet refers to a cabinet used to place office documents and materials, usually in an office, study, etc.; a broad sense file cabinet can be used to place various things. It is generally used in offices, archives, reference rooms, storage rooms or personal study rooms.

Filing  Cabinet

Metal Filing Cabinet, Filing Cabinet For Documents Storage, OEM Filing Cabinet, Height Adjustable Filing Cabinet

Wuxi Lerin New Energy Technology Co.,Ltd. , https://www.lerin-tech.com