Page 1 of 2 12 LastLast
Results 1 to 25 of 42
  1. #1
    Enthusiast
    Join Date
    Nov 2013
    Location
    Maryland
    Posts
    152

    Uconnect has been hacked, go get patch.


  2. #2
    Enthusiast
    Join Date
    Apr 2015
    Location
    DFW, TX
    Posts
    141
    Has anyone installed the patch yet?

  3. #3
    Enthusiast
    Join Date
    Feb 2015
    Location
    GWN
    Posts
    769
    What the hell.

  4. #4
    I just did the update on my 2015 SRT Jeep. Beware, It did not go smoothly! Take your car to the dealer unless you feel confident you can work through computer issues. More to follow.

    The software update for my Jeep is MY15_V3__NAFTA_RA4_15_17_5.exe. There is a chance that it is the same for the Viper since it involves UConnect security. Someone else that downloads the update for a Gen V can tell us.
    Last edited by EZ 2B Green; 07-21-2015 at 11:00 PM.

  5. #5
    The online directions are pretty good assuming you are use to working with computers. I had trouble after downloading the Akamai software because I was expecting something to happen once the install was complete. Just hit "skip" in the Tutorial after it's loaded and you can download the UConnect update. You will need a 4GB (minimum) thumb drive.

    I plugged the drive into the Jeep dash and powered up in ACC mode and the update started. After loading 9 of 11 units the update stalled and my center stack and dash were frozen. This really sucked as all the vehicle controls are through the touch screen. My only option was to look up the fuses that control the center stack in hopes I could do a hard reset. After trying many fuses, the only thing that worked was pulling one of the power relays.

    I deleted the thumb drive file and started over in case the file was corrupted. I did not want to take any chances on another failed attempt so I hooked up a battery charger to maintain the system voltage level before inserting the thumb drive. The second try worked and the install completed. I want these two hours of my life back.
    Last edited by EZ 2B Green; 07-21-2015 at 10:28 PM.

  6. #6
    It looks like I need to do 2 of them. Where do you hook the usb cable, in any available that are used for music input? My Viper has 2 I think, not sure about my Ram 2500. Would rather do the update myself if possible and avoid the dealers.

  7. #7
    Enthusiast
    Join Date
    Apr 2014
    Location
    North Texas
    Posts
    405
    I just applied the update to both the Viper and the wife's Grand Cherokee and had no issues with the firmware load on either. Only visual change I was able to see was a new warning screen when selecting the performance pages on the Viper (general disclaimer about using it safely while driving).

  8. #8
    Enthusiast
    Join Date
    Apr 2014
    Location
    North Texas
    Posts
    405
    Quote Originally Posted by Blue T/A 2.0 View Post
    It looks like I need to do 2 of them. Where do you hook the usb cable, in any available that are used for music input? My Viper has 2 I think, not sure about my Ram 2500. Would rather do the update myself if possible and avoid the dealers.
    I used the USB connection between the seats (behind where your elbow falls while driving).

  9. #9
    Enthusiast
    Join Date
    Dec 2013
    Location
    Mass
    Posts
    1,079
    Networking 101. Define a Source address policy where the updates are coming from at Chrysler. That's the first of a few steps to prevent hacking.

  10. #10
    Enthusiast
    Join Date
    Oct 2013
    Location
    Margaritaville
    Posts
    858
    Does this affect the Darts as well?

  11. #11
    2013MY and 2014MY show they need update to 15.26.1 (With NAV - 8.4AN_RA4_15.26.1_MY13_&_M14) or (Without NAV - 8.4A_RA3_15.26.1_MY13_&_M14)
    2015MY shows update to 15.17.5 (8.4AN_RA4_15_17_5_MY15)

    Per the dealer system...

  12. #12
    Enthusiast
    Join Date
    Oct 2013
    Location
    Tysons Corner, VA
    Posts
    4,676
    It is painfully stupid to put a WiFi hotspot and cell connection in a car.

  13. #13
    Enthusiast
    Join Date
    Oct 2013
    Posts
    3,749
    Anyone know if this issue applies to U-Comment systems that have not been activated? Thanks in advance.

  14. #14
    Quote Originally Posted by Steve-Indy View Post
    Anyone know if this issue applies to U-Comment systems that have not been activated? Thanks in advance.
    This. I never use mine and it's never been registered/online.

  15. #15
    Enthusiast
    Join Date
    Oct 2013
    Location
    Tysons Corner, VA
    Posts
    4,676
    Quote Originally Posted by Steve-Indy View Post
    Anyone know if this issue applies to U-Comment systems that have not been activated? Thanks in advance.
    The cell connection is still online

  16. #16
    This is why I don't like technology integration into EVERYTHING.

  17. #17

  18. #18
    Enthusiast
    Join Date
    Oct 2013
    Location
    Washington, IL
    Posts
    1,739
    U-Connect

    Sophisticated enough to allow hackers to cripple a car driving down the highway.

    But unsophisticated enough that they can't send an auto update via this constant connection to fix it.

    Now where did I put that AOL CD...

  19. #19
    Enthusiast
    Join Date
    Oct 2013
    Location
    CT
    Posts
    2,733
    Quote Originally Posted by roadrunner View Post
    "Some chronic masturbator in a basement with a vendetta against you isn’t likely to just be able to rapidly type onto his keyboard and cut off your brakes." - classy

  20. #20
    I have a question….can I turn that shit off!

  21. #21
    Enthusiast
    Join Date
    May 2015
    Location
    Meadow Lake, Saskatchewan, Canada
    Posts
    943
    Thanx for the heads up apeas2!!! I thought the hacker could just turn on wipers etc. Clearly, it is much more serious than that. I just finished installing system software 8.4AN_RA4_15.26.1_MY13_&_M14 Cheers

  22. #22

  23. #23
    Enthusiast
    Join Date
    Nov 2013
    Location
    Rocky Mountains
    Posts
    1,888
    This is what scares me about new vehicles today and I am an electrical engineer who does Automation, Controls, SCADA and IT/OT Enterprise on Critical Industry Infrastructure (CII) clients over the past 20 years. Look it is very simple and was laid out in the 1970s Battlestar Gallactica series. Cylons were always hacking into this network or that. In the end, the concept is extremely simple. Split out your Critical Operating Systems from your infotainment systems. As in Battlestar Gallactica, "the two shall never met". I mean leave the firmware upgrades to a hardwired physical connection or make sure they run through a DMZ server first to connect. It is absolutely wreckless to just open it up to anyone via an internet connection and think you can handle the mitigating risks through managed IT. In the world of security, Managed IT is a BS Pollyanna world. Segregate the systems and if you feel you just must talk to the firmware critical operating system portions, then pay the money for nationwide licensed FCC spectrum and set up your private network operations which can not be hacked. I have that very licensed private system just waiting for you FCA, for the entire state of Colorado and most of the US through partners. It took me over 5 years to acquire and build. Problem solved, literally in an afternoon but not cheap by any stretch.

    Just because you can do everything possible in technology, doesn't mean you should. However my biggest beef is someone hacked into my 1996 RT/10 and now my windows never come up!

    Seriously though, "On-Star", "U-Connect" and all these other aspects are not for the drivers convenience. Look up your small print from the manufacturer in the user agreements (Teslas is all over the internet). In buying the vehicle, the manufacturer states they will collect all the data and has 100% right to all data that is collected for the owner of this vehicle agreed to in the purchase of the vehicle. I am not a tin foil hat guy but very leery about a new vehicle that has cellular and internet connectability. In reality, it is just not needed because you are in the car to drive.

    Problem is solvable with a better solution. These patches, etc. are all band aids as it will continue to happen. Remove the entry points completely and problem is solved. How many of you 1980s modern muscle car owners have been hacked in your PCMs? That is right, absolutely zero because there is no entry point.
    Last edited by Coloviper; 07-22-2015 at 04:06 PM.

  24. #24
    From past experience updating Windows operating systems and Apples IOS, I have encountered patches that have caused issues and had to be updated again to fix the previous patch that cause freezing screens, etc. I am a little reluctant for the immediate time to do the updates on 2 vehicles to see if these patches work or need to be updated. What a mess. I can't believe this is going on with cars now. Wish the world stopped in place in 1974.

  25. #25
    Enthusiast
    Join Date
    May 2015
    Location
    Meadow Lake, Saskatchewan, Canada
    Posts
    943
    Quote Originally Posted by Blue T/A 2.0 View Post
    From past experience updating Windows operating systems and Apples IOS, I have encountered patches that have caused issues and had to be updated again to fix the previous patch that cause freezing screens, etc. I am a little reluctant for the immediate time to do the updates on 2 vehicles to see if these patches work or need to be updated. What a mess. I can't believe this is going on with cars now. Wish the world stopped in place in 1974.
    All true. I was really surprised when I read about this today, but such is the world we live in............ I love the tech in my car, but issues like this are a big wake up call for sure. Talk about a "Ghost in the Machine".


 
Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •