Many Lexus Navigation Systems Bricked By Over-The-Air Software Update (theverge.com)
An anonymous reader quotes a report from The Verge: An unknown number of Lexus automobiles have seen their infotainment and navigation head units broken by a bug in an over-the-air software update from Lexus. The glitch, which was confirmed by a Lexus spokesperson, was delivered in a routine software update. In affected cars, it can cause the dashboard screen to spontaneously reset itself and, as a result, both the radio and navigation system can be unusable. It affects cars equipped with Lexus' Enform system with navigation. Lexus social media channels have been flooded by frustrated owners, but the company has been unable to give any estimates for when the problem will be resolved. The company also couldn't say whether customers will see the problem fix itself with another software update or if they will need to head into dealers to get it fixed. Some users on Twitter have reported success with disconnecting their battery for a few moments to force a reset of the system.
The company also couldn't say whether customers will see the problem fix itself with another software update or if they will need to head into dealers to get it fixed. Some users on Twitter have reported success with disconnecting their battery for a few moments to force a reset of the system.
If a reset of the system can fix the problem, it's not bricked. If a software update can fix it, it's also not bricked.
"Bricked" means it is completely unrepairable and useless as anything other than a brick.
Karma: Terrifying (mostly affected by atrocities you've committed)
Car manufacturers do not understand InfoSec and should not be networking cars. It is only matter of short time until someone reverse-engineers update mechanism, inevitably discovering that they did not implement code signing and integrity checking, craft malicious update and bricks (or worse) cars equipped with such functionality.
More so, in 15 years your networked car could still be on the road. Even if 2015 best-practices are followed, by 2030 how resistant do you think such over-the-air update functionality going to be to, for example, quantum-capable attackers?
underneath the buzzwords and the snobby sales experience it's still a Toyota for a $10,000 premium over a regular Toyota but that is how they make your money, their money
I haven't been in the market for a new car in almost 15 years thanks to my honda running like a watch. With new integrated systems and "smart" features connected to every facet of the vehicle, how possible would it be to swap out the radio with an aftermarket they can't "brick" and disable the "smart" features so your car is, ya know.. 100% yours and not dependent on "the man" for if it will work properly any given day?
as a lexus driver im accustomed to certain quirks but this is unreal. First the car comes with "turning signals" which honestly I dont see any reason to use, and now the GPS, my only means of figuring out how to make a left turn against 5 lanes of traffic at 90 miles per hour is broken?! Whats next?? youll tell me the little L on the front of my car hasnt doesnt give me godlike powers over traffic?
Good people go to bed earlier.
the delaer can fix it and do other updates for $150 + labor.
What about data roaming where a 1-2 GB update can cost as much as an new car in data roaming fees?
...who video their displays WHILE THEY'RE DRIVING.
What about cars auto staring in the garage to run updates / re change battery's (hybrids).
Let's some acts like the laptop bios updates and says must have engine on to reduce risk of a battery failing / some systems are only on with key on mode and there is some kind of anti battery drain system that may kick in with out the engine on?
In Soviet Russia Lexus bricks YOU!
No, that's not quite it.
In Soviet Russia you brick update?
how a friend describes the ES...
obviously less valid as you move up the model line but thought was funny...
of a more deserving group?
I pointed out this very flaw in a comment not too long ago:
https://slashdot.org/comments....
Why anyone would let an unknown person send random software to a vehicle I bought and own any time they want without me knowing it is simply begging for this type of situation.
People are upset about Microsoft forcing updates on them, they should be equally upset at car manufacturers or anyone else who does the same thing.
But I'm sure there will be hypocritical excuses for why this is acceptable despite large portions of the /. community who would go on a rampage if this were done to their home machines.
We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
Get ready for it people, and buy AV software for your cars.
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
What they need to do, is open the right door while holding the brake pedal down as they re-apply power to the vehicle.
Once it powers on, they open the trunk to enter recovery mode where they can flash the infotainment system back to it's stock kernel! Fixed!
"Service Department, have you tried disconnecting and reconnecting the battery?"
Automatic Updates on any sort of mission critical system is a bad idea. Over the Air automatic updates are even worse.
How bad does the situation have to get before people will start to build in proper security starting from the design stage. Every industry using electronics in their products needs to hire a bunch of paranoid security engineers and give them veto power over everyone else.
"Grab them by the pussy" -- President of the United States of America
They cant autostart AFAIK. Starting them still requires you to push the power button. The keyfob is required to be within 15-20 feet (from my experiance with a 2010 Prius rental) and unless you want the care stolen no one leaves it in the car lose.
Well I've wrestled with reality for thirty five years doctor, and I'm happy to say I finally won out over it.
What about in your home with the keys in a cup near the car but inside?
Actually, it can. In later models, it's part of the Lexus Enform system. That "power button" is just a simple momentary contact that tells the computer to "go". The computer (part of it) is always running to see that button press. You aren't turning a large, high current racecar kill switch. That said, they won't autostart to "charge the batteries", mostly because the charge monitors are on when the car is "off".
(If that were the case, my totalled HS would've been starting itself every few hours to recharge the partially shorted 12V battery. The high voltage traction batteries don't run the ECU. Also, that's the only time in 5 years I've seen that car "boot". And no, the clips in the fuse box for "jump starting" aren't enough to start the car; you need to get to the actual battery.)
9/10s of what you just said is bullshit.
Even on the newer cars with serialized ECMs the worse you need is either an aftermarket tool for changing the 'accepted' serial numbers for the PCM (a probably slightly impotent safety measure for ensuring the same modules that came from the factory are working together, or an 'authorized service staff' is making a legitimate repair.) Now while it is possible some dickish manufacturers ARE doing what the PP is saying, no manufacturer I heard of, as of about 5 years ago was doing so, even on new cars. Most of the abuse was in the entertainment modules and having part of the keyfob security system built into a module in the entertainment system to force you to buy their media upgrade rather than installing your own deck, and even then most of them were simply an extra case dimpled into the deck with their own connectors to the harness and removable if you had a nearby place to mount them and a replacement unit that matched the OEM fascia (most newer cars have ruined the 1-2 DIN stereo format that had been defacto since the 60s-70s. Even if the slot is correct the new fascias would leave it looking like a skyscraper with a hole in the side of it.)
With a 0% market share (generously rounded upwards), it cannot be that many. I am surprised anyone even noticed.
This happened to my NEW 2016 Lexus RX 350. I called a local Lexus dealership and he said he had been swamped with calls about the issue.
He admitted it was a Lexus glitch with the update software.
The fix was to disconnect the negative battery cable for 8-10 minutes. The system did a hard reset and everything seems to work fine.