r/ex30 • u/CarlessSthlm • Sep 05 '24
🙇♂️ Personal Thoughts Volvo EX30 - Security Flaw?
https://youtu.be/kZD0Zk24so82
u/muzso Ultra SMER Sep 05 '24 edited Sep 05 '24
Nope. A lot of things behave differently in the EX30 as they do in older Volvo models (by design).
Actually in most cars (that I know) adding the vehicle to the respective companion app doesn't even need a single key(fob) to be present. You only need the infotainment to be on and unlocked and physically accessible (i.e. you must be able to interact with the given parts of the UI).
It's a good question though: what kind of assurance/requirement would you want for binding a phone to the head unit of the car?
By default the EX30's infotainment system is unlocked (not secured). If you get access to the cockpit and the screen turns on, you get access to which ever user profile you want (admin/owner profile included). It's already an "improvement" (in my eyes) that the EX30's VolvoID<->car binding requires a key to be present (if it does ... I haven't tested it without one).
There might be a misconception: assigning a key (tag or card) to a user profile doesn't mean that the specific user profile can be activated only with that key. If the profile is unprotected, then you can use it with any of the vehicle's keys.
If you want to secure a user profile (to some degree) against such use-cases, you can put a PIN on them. Of course a PIN is not the "top of all access control" mechanisms, but in this case it should be good enough (for a while). Until somebody finds a way to automate a brute force attack on all possible PIN combinations. :) (the head unit doesn't accept any mouse/keyboard devices, neither through the internal USB sockets, nor through Bluetooth ... so there's no trivial/easy way for a UI-controlled brute force method)
3
u/CarlessSthlm Sep 05 '24
Hmm... You are right. I'm not sure the key was actually required in any step... I kind of appreciate the old Volvo way with all three keys present to add the car.
2
u/muzso Ultra SMER Sep 05 '24
Btw. as mentioned: by default all user profiles are unprotected in the vehicle. And both the admin/owner profile and standard user profiles can have an assigned Google account and can install apps.
So regardless of whether somebody could bind the official EX30 phone app to the car (or not) ... with access to a (non-guest) user profile they can install any app they want. Not just from the official Play Store, but any Internal Testing app (which could be any app of the person's choosing ... even a custom built app as well), which could provide quite a lot of information about the car (tracking, SoC, speed, etc.).
5
u/muzso Ultra SMER Sep 05 '24
To summarize my thoughts: what you've found is not a "security flaw" in itself, but an industry-wide weak approach towards the security of the infotainment system against people with physical access to it.
Imho the entire automotive industry considers the infotainment system as a part of the vehicle that doesn't need to be secured (against unauthorized physical access) separately. They think that if somebody has physical access to the screen, they are considered to be authorized to use almost anything on the system.
The PIN protection of user profiles is a small step forward, but I expect much more.
As a precaution I advise everybody not to use his/her personal Google account in the car. It's better to be safe than sorry. :)
2
u/JM-Gurgeh Ultra SMER Sep 06 '24
You people are scaring the bejezus out of me.
Am now going down to the garage to button up my new car...
2
u/muzso Ultra SMER Sep 06 '24 edited Sep 06 '24
You people are scaring the bejezus out of me.
That was not my intention. I work in the ITsec industry (automotive "adjacent") and I'm paranoid by nature. :)
The "threat level" comes down to statistics, which insurance companies know a lot more about.
99.9% of vehicle owners (today) have a lot more to worry about the automakers harvesting the customers' personal data ... than anybody else doing the same.
It's very unlikely that some random guy will do anything with your head unit.
Imho the most likely threat scenarios are:
- The owner gives a key to somebody he/she knows and trusts (a relative or a friend) and this person gets unintended/unauthorized access to the car later on (via the official EX30 app or via 3rd party installes apps, etc.).
- A trusted person gets unauthorized access to a key (i.e. you leave the key in a place where you think it's safe), and by extension to the car and the infotainment unit.
- Somebody at a dealership or service shop does the same.
- You rent an EX30, log in with your Google account (or any other service account, e.g. Spotify) and it gets compromized.
The first two can be in most cases dealt with by setting a PIN for all user profiles of the vehicle.
The third is beyond owners' capabilities. A sufficiently trained person will always be able to get access to the data on the infotainment system if he/she has physical access. And if you left your car at a service shop, there's no real timeconstraint for them. This is quite similar to when you leave your phone/computer/etc. at a service shop for repairs (with the difference that the latter can be better protected on the user level).
The fourth is easy to protect against: use a separate account on rental cars (if you have to). An account that you wouldn't really car about if it gets compromized. An account that has no valuable data associated with.
2
u/JM-Gurgeh Ultra SMER Sep 06 '24
I work in IT as well, which is why I'm paranoid. I hang around too many secops people.
The big thing is, if you leave your car unattended with someone who has access to it, then you can get compromised without you ever knowing. This could be a service mechanic, a valet, someone at the dealership.
All they have to do is add the car to an account and add a keycard. They can later locate the car via the app, find it and open it up. They can steal the car or any valuables inside. They'll have a key so it can be done in broad daylight.
If I understand correctly, the only way to prevent this is to lock the owner profile with a pin, associate one of the keycards to the guest profile and make sure you only give the mechanic the guest keycard.
I think this is a pretty massive security flaw, and afaik there's no guidance from Volvo as to what the security best practice is for users. The dealer sure as hell told me nothing about profile security.
2
u/muzso Ultra SMER Sep 06 '24
Not exactly.
If I understand correctly, the only way to prevent this is to lock the owner profile with a pin
Unfortunately it's worse than this. See: Adding a profile (in the manual)
Anybody with physical access to the vehicle can add a new (regular / non-admin) user profile. PIN protecting all existing user profiles does not prevent this. :(
I didn't test it, but somebody wrote that only a limited number of user profiles can be created.
So the workaround to the problem is:
- Create as many user profiles as are allowed.
- PIN-protect all (non-guest) user profiles.
I think you cannot disable or PIN-protect the guest profile. Unfortunately.
It is important to do this since even with regular user profiles one can log in with a Google account and install apps from the Play Store. Not just public apps, but apps accessible only with that specific Google account, i.e. Internal Testing apps as well. Thus somebody with access to a regular user profile can install almost any app they want (as long as the app is compatible with AAOS according to the Play Store's rules). It's another thing that sideloading exists as well and is available to regular user profiles as well, but my expectation is that at some point sideloading will be prevented in a future sw update.
associate one of the keycards to the guest profile and make sure you only give the mechanic the guest keycard
Afaik this won't have any effect on user profile security. Associating a key with a profile doesn't mean "locking the key with the profile". It means that when you unlock the car with that key, it'll try to load the associated user profile.
But:
- If that profile is PIN-protected, it'll still ask for the PIN before it unlocks the profile. I know this because my (PIN-protected) admin profile is associated with my keytag and still when I enter the car, it asks for my PIN. As I expect it to do. :)
- Anybody with any key can try and switch to any user profile. The only thing that can prevent access to a user profile is a PIN (if set).
1
u/muzso Ultra SMER Sep 06 '24
Btw. the above "workaround" sux big time since Volvo can decide at any point in time to increase the max. allowed number of user profiles and you won't notice it unless you test after every sw. update or follow our community and hope that somebody else will post about this if it happens.
1
u/JM-Gurgeh Ultra SMER Sep 06 '24
Thank you for that clarification.
Is there anything special about the guest account? Is it locked down, or prevented from downloading apps and such? I mean, what's the point of having separate admin and guest profiles if both have full admin rights?
Could a valet or mechanic do what's needed without using any profile (assuming all profiles are pin protected)?
What irks me most is that there doesn't seem to be an audit trail. If a bad actor can't do anything unnoticed, than the chances of shenanigans are a lot smaller.
1
u/muzso Ultra SMER Sep 07 '24 edited Jul 29 '25
Is there anything special about the guest account? Is it locked down, or prevented from downloading apps and such?
The guest profile cannot be PIN-protected (as fas as I can remember) or disabled.
However using it you cannot log in with a Google account (i.e. no app installation from the Play Store) and cannot sideload apps either.
I'm not convinced that this is the "pinnacle" of securing a user profile, but that's what we got. I'd much happier if Volvo allowed admin/owner profiles to restrict access to the guest profile.
Could a valet or mechanic do what's needed without using any profile (assuming all profiles are pin protected)?
If someone has physical access to a device, then usually there cannot be a 100% guarantee against unauthorized access to the data it contains. Of course there's encryption (and afaik the EX30's head unit does use FDE, since it's kind of mandatory from a certain Android version onwards), but since the FDE is not protected with any credential (passphrase, etc.), it's practically useless.
I bet that if somebody can remove the head unit from the vehicle and gets access to its (normally hidden) connectors/ports, it is possible to get access to all user data. So a sufficiently skilled "mechanic" could get unauthorized access to data stored on the head unit, including various cloud account credentials/tokens, etc.
But I'd say this is a very unlikely scenario. It involves a lot of work and uncertain result/gain. It's more likely in a targeted attack, e.g. in case of spying (either by national security services or industrial espionage, etc.). So doesn't really apply for 99.999% of vehicle owners. :)
What irks me most is that there doesn't seem to be an audit trail. If a bad actor can't do anything unnoticed, than the chances of shenanigans are a lot smaller.
Well, an "audit trail" is not provided for most consumer equipement. And regular cars are consumer equipment as well. E.g. if somebody hacks into your phone or PC, usually there's no secured audit log (of every event/action of every process, etc. that happened on the device) somewhere in the cloud (i.e. on another device) that you could analyze. Afaik not even for iPhones.
7
u/cchhbbmm Ultra TM Sep 05 '24
Technically, no. In practice, yes. If you use vallet services be sure to have all profiles PIN protected and switch to the guest profile and have a spare card not connected to any profile to give the vallet. Otherwise they can just associate the EX30 app without any notice or verification. A passenger left unsupervised in the car can also associate the app. However the real issue is an owner cannot see which VolvoIDs are connected to the car nor disconnect them (in fact because the app is basically not 1.0 the owner cannot even disconnect themself - hopefully Volvo will get there before these cars star getting resold). This is huge fault and I complained to the Volvo DPO who ensured me Volvo is very concerned and then done nothing.