#hacktheworld — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #hacktheworld, aggregated by home.social.
-
Ok. It's time to roast this circuit.
My tonneau cover has buttons on the rear of the truck that only operate IF it detects a remote OR a smartphone is actively connected to it via BLE. The BLE app requires you to have the app front and centre to work.
I also have no way WITHIN the truck to open or close the rear - unlike my previous unit, which used Homelink.
I have Phone as a key (PAAK) and keyless entry in to the vehicle, so I want a solution that doesn't rely on the phone or physical keys.
The idea: I'm going to use an ESP32 and CAN Transceiver to monitor my vehicle for CAN status messages indicating the vehicle is unlocked. Then, I can use the ESP32 to mimic a smartphone connection to a tonneau cover I have that ONLY works with a remote and/or smart phone app.
When the CAN bus sees the vehicle is unlocked, the ESP32 will connect to the BLE connection on the tonneau as if it's a mobile phone, using BLE pairing (key/pass handshakes).
Then it will allow the rear physically wired buttons to operate the tonneau cover, because the tonneau cover will go "There's an active phone connected”.
(I have already done a proof of concept with this and an ESP32 sat inside my truck, but without CAN authorization it won't be secure).
This circuit is specifically that. It's a “Disconnect from the cover as soon as the doors are locked" and “ONLY connect when the doors are unlocked”
But wait, there's more. Using the HomeLink buttons on my sun visor, I want to enable IN-VEHICLE control of the cover. That's what the 433 MHz circuit is for. Again, it will ONLY work WHEN the vehicle is unlocked and will ignore presses when the truck is locked.
For the future, I'll also implement the work done here: https://github.com/jantman/ford-f150-gen14-can-bus-interface/tree/main to have the rear tonneau cover light illuminate when the rear bed lights are activated.
Tell me I'm crazy. ;)
AND Yes, I know, PAAK is only as safe as the next update, or the next vulnerability. And I know that's an attack vector. But the beauty of this is that it will *also* work if I have to turn off PAAK, and use the old-school remote, without carrying around an extra remote.
AND yes, there are risks there too. I'm thinking of setting a Lock Out mode. I discovered the other day that if the ESP32 is connected, it AUTOMATICALLY rejects other pairings. Which could be a bonus for a ‘lock it down' mode.
-
Ok. It's time to roast this circuit.
My tonneau cover has buttons on the rear of the truck that only operate IF it detects a remote OR a smartphone is actively connected to it via BLE. The BLE app requires you to have the app front and centre to work.
I also have no way WITHIN the truck to open or close the rear - unlike my previous unit, which used Homelink.
I have Phone as a key (PAAK) and keyless entry in to the vehicle, so I want a solution that doesn't rely on the phone or physical keys.
The idea: I'm going to use an ESP32 and CAN Transceiver to monitor my vehicle for CAN status messages indicating the vehicle is unlocked. Then, I can use the ESP32 to mimic a smartphone connection to a tonneau cover I have that ONLY works with a remote and/or smart phone app.
When the CAN bus sees the vehicle is unlocked, the ESP32 will connect to the BLE connection on the tonneau as if it's a mobile phone, using BLE pairing (key/pass handshakes).
Then it will allow the rear physically wired buttons to operate the tonneau cover, because the tonneau cover will go "There's an active phone connected”.
(I have already done a proof of concept with this and an ESP32 sat inside my truck, but without CAN authorization it won't be secure).
This circuit is specifically that. It's a “Disconnect from the cover as soon as the doors are locked" and “ONLY connect when the doors are unlocked”
But wait, there's more. Using the HomeLink buttons on my sun visor, I want to enable IN-VEHICLE control of the cover. That's what the 433 MHz circuit is for. Again, it will ONLY work WHEN the vehicle is unlocked and will ignore presses when the truck is locked.
For the future, I'll also implement the work done here: https://github.com/jantman/ford-f150-gen14-can-bus-interface/tree/main to have the rear tonneau cover light illuminate when the rear bed lights are activated.
Tell me I'm crazy. ;)
AND Yes, I know, PAAK is only as safe as the next update, or the next vulnerability. And I know that's an attack vector. But the beauty of this is that it will *also* work if I have to turn off PAAK, and use the old-school remote, without carrying around an extra remote.
AND yes, there are risks there too. I'm thinking of setting a Lock Out mode. I discovered the other day that if the ESP32 is connected, it AUTOMATICALLY rejects other pairings. Which could be a bonus for a ‘lock it down' mode.
-
After going at least a year without a working personal laptop, I finally just dropped some $ for a new #Framework laptop that I'll be running #Linux on, for my certification and advocacy projects in 2026. It'll arrive in time for me to assemble during my upcoming #holiday break, during which I will very much enjoying nerding out. #HackClub #HackTheWorld #Ctrl+Alt+Create #RightToRepair
-
After going at least a year without a working personal laptop, I finally just dropped some $ for a new #Framework laptop that I'll be running #Linux on, for my certification and advocacy projects in 2026. It'll arrive in time for me to assemble during my upcoming #holiday break, during which I will very much enjoying nerding out. #HackClub #HackTheWorld #Ctrl+Alt+Create #RightToRepair
-
Tiens, le flipper 🐬 serait capable de bypasser le système de sécurité des rolling codes qui protège les clés de nos véhicules...
According to SAN ⬇️
"SAN obtained a copy of the firmware and tested the attack in a controlled setting with the permission of vehicle owners. In one case, capturing a single unlock signal allowed the Flipper Zero to repeatedly lock, unlock and open the trunk of the target car.
The hack also disabled the original key fob until it was manually reset.
Vehicles vulnerable to the attack include numerous models manufactured by Chrysler, Dodge, Fiat, Ford, Hyundai, Jeep, Kia, Mitsubishi and Subaru, according to an infographic provided with the firmware. The infographic says updates to attack other car makers, such as Honda, are “in development.” It also mentions high-end car companies such as Alfa Romeo, Ferrari and Maserati."
...
"The hack appears to be based on a 2022 attack known as “RollBack,” developed by researchers at CrySys Lab in Hungary. The researchers demonstrated how rolling code protections could be broken by capturing valid signals and replaying them in a specific order to bypass a vehicle’s code synchronization system."
👇
https://san.com/cc/millions-of-cars-at-risk-from-flipper-zero-key-fob-hack-experts-warn/[related]
"Flipper Zero Dark Web Firmware Cracks Rolling Code Security in Modern Cars"
👇
https://gbhackers.com/flipper-zero-cracks-rolling-code-security-in-modern-cars/[FR]
⬇️
"Flipper Zero et codes tournants - Cette faille qui fait trembler le secteur de l'automobile"
👇
https://korben.info/flipper-zero-codes-tournants-verite-faille-automobile-darkweb.html#flipper #FlipperZero #cyberveille #car #carsecurity #hacktheworld
-
🚀 Sfida accettata! Microsoft lancia il concorso per scoprire i migliori hacker del mondo! #HackTheWorld
🔗 https://www.tomshw.it/hardware/microsoft-lancia-un-concorso-per-il-miglior-hacker-2024-11-21
-
I received my swag kit for completing the Hack the Box Certified Penetratration Specialist exam. This was a wild ride! #HTB #HTBAcademy #HackTheWorld
-
x86 Assembly should be taught in schools in lieu of AP Math. #hacktheworld
-
x86 Assembly should be taught in schools in lieu of AP Math. #hacktheworld
-
Just discovered https://fccid.io/ where you can paste the #fcc ID of any wireless device and find out through the submitted documents/pictures which CPU, RAM, Modem, etc... it uses. Super useful for #openwrt folks to know which routers they can target with a future build.
#hacktheworld #embedded -
Just discovered https://fccid.io/ where you can paste the #fcc ID of any wireless device and find out through the submitted documents/pictures which CPU, RAM, Modem, etc... it uses. Super useful for #openwrt folks to know which routers they can target with a future build.
#hacktheworld #embedded -
What a great view! 🔭 #R2R #DiVOC #HackTheWorld