2017+ Super Duty The 2017+ Ford F250, F350, F450 and F550 Super Duty Pickup and Chassis Cab

Custom Screen Animation

Thread Tools
 
Search this Thread
 
  #16  
Old 01-08-2019, 08:41 PM
h20camper's Avatar
h20camper
h20camper is offline
Logistics Pro
Join Date: Apr 2017
Location: Lost in the Ozone....
Posts: 3,891
Received 273 Likes on 188 Posts
Originally Posted by Tricon
I could see them using the MD5's just for file integrity, and the HMAC to stop idiots like us from borking the whole thing.
This seems most likely to me too.
 
  #17  
Old 01-08-2019, 10:43 PM
Section179's Avatar
Section179
Section179 is offline
Fleet Mechanic
Join Date: Apr 2018
Posts: 1,503
Received 160 Likes on 88 Posts
I think you need to switch to NoSQL in the cloud and explore a blockchain alternative for decentralizing transactions.

 
  #18  
Old 01-09-2019, 01:20 AM
2009kr's Avatar
2009kr
2009kr is offline
Posting Guru
Join Date: Aug 2015
Posts: 2,399
Likes: 0
Received 9 Likes on 6 Posts
Originally Posted by Tricon
It looks like they actually have MD5 sums for the individual files that are loaded in their .der certificate files. But....this just seems to easy to circumvent? 2009kr, how did you come to the conclusion on the HMAC system, did you alter something and try to install it?

Here's a snippet from one of the image certificates:

Type = Utility
Post-Script = GB5T-14G386-AB.sh
File1 = GB5T-14G386-AB.sh
File1 Hash Value = 01bced7dc9f78d69a35ce5c3f0712b8516330e827c1a97b658 3ab1d2fbb01dbf
File1 Size = 2231
File2 = utloggingutility
File2 Hash Value = d2a94381cdda68004ee55bd0c437f3f0148cd489733f8c4469 ad63b52df675e1
File2 Size = 85628
File3 = Decoded_ODL.xml
File3 Hash Value = 9d23e743e31f7075f06d88f198297122e82a2f851fac53adab f761a5c6dd731c
File3 Size = 9478
Save Location = /tmp/
For my 2009, there was a field in the image called HMAC. Did any of the files you loked at contain a signature or HMAC? If there is a signature, it be at least 1024 bits long, likely 2048.

it's fairly straightforward to verify that some authentication is used in addition to the hash's integritity function. First see if you can generate the the same hash for one of the files. The hash values you show are 256 bits long, so I'd try SHA256 first. (MD5 is half that length.) Once you can do that, you have verified that you have the right algorithm, the file is just hashed in its entirety, and there isn't a salt (or the hashes aren't HMACs).

With this information, change one of the internal files (the .XML one is a nice candidate), recalculate the hash, put the changed file and new hash back in and see if the truck will accept it. I'm not optimistic though.
 
  #19  
Old 01-09-2019, 06:28 AM
kry226's Avatar
kry226
kry226 is offline
Fleet Mechanic
Join Date: Dec 2016
Location: Pennsylvania
Posts: 1,567
Received 385 Likes on 215 Posts
I'm sorry. I've apparently stumbled into the wrong thread.
 
  #20  
Old 01-09-2019, 06:34 AM
2009kr's Avatar
2009kr
2009kr is offline
Posting Guru
Join Date: Aug 2015
Posts: 2,399
Likes: 0
Received 9 Likes on 6 Posts
Originally Posted by kry226
I'm sorry. I've apparently stumbled into the wrong thread.
Changing embedded software isn't as easy as it used to be. As our vehicles get more and more complex, mod discussions will look more and more like this.
 
  #21  
Old 01-09-2019, 09:44 AM
wicked 2018's Avatar
wicked 2018
wicked 2018 is offline
Posting Guru
Join Date: Mar 2018
Posts: 1,055
Likes: 0
Received 7 Likes on 5 Posts
a little off subject, but how do you access the Sync diagnosis screen on the SD's? I know you can plug in Forscan to change the startup images, but seems easier to do it through the diagnosis screen
 
  #22  
Old 01-09-2019, 10:44 AM
h20camper's Avatar
h20camper
h20camper is offline
Logistics Pro
Join Date: Apr 2017
Location: Lost in the Ozone....
Posts: 3,891
Received 273 Likes on 188 Posts
Originally Posted by wicked 2018
a little off subject, but how do you access the Sync diagnosis screen on the SD's? I know you can plug in Forscan to change the startup images, but seems easier to do it through the diagnosis screen
  • On newer trucks without a CD player, you press and hold the steering wheel right menu button, then press and hold the dash's right menu button.
  • On trucks with CD player, you press and hold eject and scan at the same time for up to 20 seconds. (I've never actually tested this as my truck is 2019 without CD player.)
Remember, through the diagnostics menu, the image changes are not permanent.


 
  #23  
Old 01-09-2019, 11:52 AM
Alaskan_Warbird's Avatar
Alaskan_Warbird
Alaskan_Warbird is offline
Posting Guru
Join Date: Mar 2018
Location: Fairbanks, AK
Posts: 1,962
Likes: 0
Received 6 Likes on 6 Posts
Originally Posted by 2009kr
Changing embedded software isn't as easy as it used to be. As our vehicles get more and more complex, mod discussions will look more and more like this.
That's a fact. Personally, I'm glad they've made it more secure, even if it is more difficult for us to ethically hack our own vehicles.
 
  #24  
Old 01-09-2019, 03:30 PM
kry226's Avatar
kry226
kry226 is offline
Fleet Mechanic
Join Date: Dec 2016
Location: Pennsylvania
Posts: 1,567
Received 385 Likes on 215 Posts
Originally Posted by 2009kr
Changing embedded software isn't as easy as it used to be. As our vehicles get more and more complex, mod discussions will look more and more like this.
No, you're absolutely correct. I was just joshing, but I actually was able to follow most of the discussion.
 
  #25  
Old 04-08-2019, 02:06 PM
alabamatoy's Avatar
alabamatoy
alabamatoy is offline
Mountain Pass
Join Date: Jul 2002
Location: Madison USA
Posts: 191
Received 1 Like on 1 Post
Originally Posted by 2009kr
Changing embedded software isn't as easy as it used to be. As our vehicles get more and more complex, mod discussions will look more and more like this.
And we need to stand up to the OEMs and corporations for the Right to Repair. I believe that I own my truck, not Ford, and if I want to replace the code in it, I should be able to do so. Ford should have to allow its code to be reviewed for security purposes etc and we should be able to purchase all the same tools and parts and info that the dealers can purchase.

See https://repair.org/ Support if you agree.
 
  #26  
Old 04-08-2019, 04:22 PM
Tricon's Avatar
Tricon
Tricon is offline
Logistics Pro
Join Date: Apr 2017
Location: SoCal
Posts: 3,674
Likes: 0
Received 44 Likes on 35 Posts
Originally Posted by alabamatoy
And we need to stand up to the OEMs and corporations for the Right to Repair. I believe that I own my truck, not Ford, and if I want to replace the code in it, I should be able to do so. Ford should have to allow its code to be reviewed for security purposes etc and we should be able to purchase all the same tools and parts and info that the dealers can purchase.

See https://repair.org/ Support if you agree.
I agree with the right to repair, but not that you should be able to change the code of your truck. You don't own the patents, and they certainly shouldn't warranty your truck for anything you change on it. I can only imagine the lawsuits they would have to fight if you changed the drive by wire code and it borked at went full throttle at a school crossing or something. I totally understand that need in vehicles...in Android or iOS phones not so much.
 
  #27  
Old 04-08-2019, 07:16 PM
alabamatoy's Avatar
alabamatoy
alabamatoy is offline
Mountain Pass
Join Date: Jul 2002
Location: Madison USA
Posts: 191
Received 1 Like on 1 Post
Well, I believe I should be able to change my own product, but in so changing it that should relieve Ford of responsibility....unless their design is found to be at fault. I can put different wheels and tires or change the engine program (Banks etc), why shouldn't I be able to change other aspects of the code? I hate all these nagging safety things that are designed to protect stupid people from themselves.
 
  #28  
Old 04-08-2019, 09:00 PM
h20camper's Avatar
h20camper
h20camper is offline
Logistics Pro
Join Date: Apr 2017
Location: Lost in the Ozone....
Posts: 3,891
Received 273 Likes on 188 Posts
Originally Posted by alabamatoy
to protect stupid people from themselves.
Stupid people need to be protected from themselves.
 
  #29  
Old 04-09-2019, 02:02 AM
Favored's Avatar
Favored
Favored is offline
Junior User
Join Date: Mar 2019
Posts: 71
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by h20camper
Stupid people need to be protected from themselves.
People need to be protected from stupid people.
 
  #30  
Old 04-09-2019, 06:46 AM
h20camper's Avatar
h20camper
h20camper is offline
Logistics Pro
Join Date: Apr 2017
Location: Lost in the Ozone....
Posts: 3,891
Received 273 Likes on 188 Posts
True that!
 


Quick Reply: Custom Screen Animation



All times are GMT -5. The time now is 08:30 PM.