Do Not Sell My Personal Information Jump to content


Lexus IS 300h not vulnerable to CANbus theft


Recommended Posts

I asked on the Lexus mag forum about the vulnerability of the IS 300h to CANbus vulnerability through the headlights as it wasn't in the list of cars due for any retrofit, both for my current 2014 model (which shouldn't be vulnerable) and if I purchased a post face-lift 2017 model (which I thought might be) - this is the reply they posted:

Hello Phil,
Thanks for your question.
Your current IS 300h is not impacted as the technology that enables CAN bus theft isn’t in those vehicles.
While no car can be considered 100% immune to criminal intent, our Product Technical team have also advised that the IS 300h from October 2016 to September 2020 Production is not affected by CAN bus theft due to the platform of the vehicle.
We hope this helps.
Thanks.

  • Like 3
  • Thanks 2
Link to comment
Share on other sites

That’s correct. Whilst the facelift model has CAN bus controlled headlights, they are on a separate bus to the one the central locking system is connected to so you cannot directly inject a signal. 

  • Like 2
  • Thanks 1
Link to comment
Share on other sites

Does that apply to the pre-facelift GS300h, as I see that is also not on the list of cars for the security fix?

Link to comment
Share on other sites

2 hours ago, johnatg said:

Does that apply to the pre-facelift GS300h, as I see that is also not on the list of cars for the security fix?

Pre-facelift GS300h is unaffected.

Link to comment
Share on other sites

On 3/17/2024 at 8:36 AM, ColinBarber said:

That’s correct. Whilst the facelift model has CAN bus controlled headlights, they are on a separate bus to the one the central locking system is connected to so you cannot directly inject a signal. 

What a relief! thanks to the OP for clarifying! 💙

It's a shame that this is all it would have taken the designers/engineers to avoid such a wave of thefts and disappointments (and insurane hikes!) for so many people
Next time someone at work tells you "design is ancillary/secondary" think of this...  (yes im a designer myself)

  • Like 1
Link to comment
Share on other sites

On 3/20/2024 at 10:56 AM, Mr_Groundhog said:

What a relief! thanks to the OP for clarifying! 💙

It's a shame that this is all it would have taken the designers/engineers to avoid such a wave of thefts and disappointments (and insurane hikes!) for so many people
Next time someone at work tells you "design is ancillary/secondary" think of this...  (yes im a designer myself)

More than separate buses, the simple thing to do would have been to apply encryption to the bus. 

Maybe posted elsewhere in the thread but an interesting read: https://kentindell.github.io/2023/04/03/can-injection/

Link to comment
Share on other sites


13 hours ago, matt8 said:

Maybe posted elsewhere in the thread but an interesting read: https://kentindell.github.io/2023/04/03/can-injection/

Interesting article with lots of tech depth and CANbus history.

I deal with Zero Trust systems in the world of computing, using a system invented by the CIA 16 years ago, and Zero Trust is a bit of a b*gger to do easily. 

I suspect will be a while before we see car manufacturers do what the kentindell link says.  Even doing Zero Trust in the PC world you need to deal with what is called a 'Living Off The Land' attack, which tells me even if the car tech is upgraded the hackers will eventually suss it out with a LOL attack.

Don't forget crims are not nice people with nothing better to do than work out how to nick things that are not theirs, by using tools developed by (usually) highly autistic geeks.

Link to comment
Share on other sites

Latest Deals

Lexus Official Store for genuine Lexus parts & accessories

Disclaimer: As the club is an eBay Partner, The club may be compensated if you make a purchase via eBay links

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share







Lexus Owners Club Powered by Invision Community


eBay Disclosure: As the club is an eBay Partner, the club may earn commision if you make a purchase via the clubs eBay links.

DISCLAIMER: Lexusownersclub.co.uk is an independent Lexus forum for owners of Lexus vehicles. The club is not part of Lexus UK nor affiliated with or endorsed by Lexus UK in any way. The material contained in the forums is submitted by the general public and is NOT endorsed by Lexus Owners Club, ACI LTD, Lexus UK or Toyota Motor Corporation. The official Lexus website can be found at http://www.lexus.co.uk
×
  • Create New...