The OpenOtto Project is doing more presentations. We had/have a lot of conference presentations this summer. The photos (photos by Brian Turnbull) are from Intridea’sHackOn (un)conference that was held June 18-20th in Portland, Maine. After co-working with Intridea on Friday, Nothingface and I did a presentation about the current state of the OpenOtto Project on Saturday.
We also just secured presentations at Black Hat USA 2009 and DEFCON 17 in Las Vegas. Our Black Hat talk will be with me and Travis Goodspeed. Travis is working on the layout so we can progress toward releasing the schematics, source code and producing the first demo. We're doing a presentation at Black Hat in the open source project break-out session on Wednesday, July 29, 10:00 AM, Genoa room, 3rd floor at Caesar’s Palace.
The DEFCON talk will be on Saturday, August 1, with Skytalks, skybox 303 at 10 AM, The Riviera.
Please come see us and talk with us about hacking your car! We’re looking for funding and developers.
Rob T Firefly suggested we get a DeLorean for the OpenOtto demo. Awesome idea! Love it. If we come across one, we'll make a go for it.
However, here are some suggestions of what the demo should NOT be. Although they might attract more girls to the computer hacker scene, these cars are not cool.
Even though the guy with the 89' Oldsmobile Cutlass Sierra Louis Vuitton Limited Edition looks pretty fly, this doesn't quite say, "Give us VC funding, please" but, instead, "I'm a bad knock-off."
The Ferrari...it's just so wrong. This doesn't say, "I'm so hot, give me a speeding ticket," as Ferrari's should, but, "This is my teenage daughter's car." Instead, this is the Ferrari OpenOtto would be willing accept as a donation to the open source project. If you've ever ridden in a Ferrari and driven so fast along winding mountaintop roads in Italy that there is FIRE coming out of the tailpipe and you're pinned into the racing seat, you'd understand why my vote is for a sports car. I like fast cars that go boom.
The last picture is one I took of a wimpy Jeep Liberty on my driveway during mud season. Indeed, it took TWO Land Rovers to tow out the Liberty. No wimpy SUVs--this is a going-to-the-mall car. Thank goodness it was a rental. It had mud coming in the doors by the time we got it out of there. I was told that, when it was returned to the Portland, Maine airport car rental office, the guys receiving the car stood in disbelief as they saw the mud on and in the car. Instead, we vote for an H1 as our off-roading vehicle demo car. If we can't have that, we'll stick with the 2003 Land Rover Discovery it's in now because it really can go anywhere. In fact, we've taken it there and back.
We’ve been watching Knight Rider. (Actually, we have been since the 80s, so that probably dates us.) We’ve recently been having some fun debates about a dream demo car for OpenOtto. Of course, we’re just scraping by now and absconding with junk parts from cast-offs and running OpenOtto on a 2003 Land Rover, but if a dream could come true, what would be the coolest car OpenOtto’s software and hardware could control? Would it be an off-roading SUV, a sports car, or a muscle car?
Because Knight Rider was an inspiration, one of the demos has to be an American muscle car. There will always be some who believe the original Knight Rider¸ a 1982 Pontiac Firebird Trans Am, will be the only true KITT. If you ever wondered if KITT really had a blood analyzer, Ski Mode, or an electromagnetic field generator, here are all of the technical specs for KITT from the 1980s series. We should have attended the Knight Rider Festival last week in Las Vegas. Both the new and old KITTs were demoed along with hobbyists displaying their tribute cars.
The new Knight Rider series features a Ford Shelby GT 500 KR Mustang. With Val Kilmer as the new KITT voice, the car sounds and looks HOT. If you want to keep watching the new Knight Rider TV series, you must be proactive and sign a petition to keep the show going. Why not? It’s cooler, hacker-ish, and more techie than the dozens of boring doctor and lawyer shows now on prime time TV.
But one thing is for sure, when we do professionally demo a car controlled by OpenOtto, the developers must wear their Michael Knight costumes. (Sorry, these hokie things are part of what start-ups make their employees do). But I think I’ll opt for Daisy Duke’s outfit even though the 1969 Dodge Charger General Lee always seemed to be broken down, didn’t it? KITT would leave General Lee in the dust and then go on to hack some wicked encrypted world computer networks any day! Hack on, KITT!
The second day started with getting up “early” so I could see Christofer Hoff discuss the vulnerabilities associated with outsourcing your prized possessions to cloud computing networks. It was definitely worth dragging myself out of bed. Chris is another AWESOME presenter. Peppered with a few early morning f-bombs (which, according to one of my students, is KEY to getting venture capital financing [?]), it was a riveting presentation and had visually appealing slides. I can take guidance from his method of presenting when he spoke to Twitterers in the crowd declaring that none of his 75 slides contained more than 160 characters per slide (and eerie, cool pictures of frogs). Most significantly, what I took from his presentation were some ideas about securely storing and accessing intellectual property from cloud computing networks. Some of those ideas I abstracted into search and seizure principles and incorporated some new research ideas into the CFP abstract for Brucon which, incidentally, was submitted at a witching hour Sunday night by me and my research partner, Myrcurial, in Toronto. Thanks for the inspiration, Chris!
Later that day, the disclosure panel was one of the talks I really wanted to see at Source. I have done research on this topic and was delighted to hear Ryan Laraine asking Dan Kaminsky, Ivan Arce, Dino Dai Zovi, Alexander Sotirov, and Katie Moussouris debatable topics such as:
·What’s enough time to give the vendor?
·Should there be a partial disclosure committee to prevent the purgatory Kaminsky endured with his DNS bug?
·Should there be civil liability for companies putting out insecure products?
·What about disclosing security vulnerabilities that effect devices where lives could be at stake?
·What if people discover vulnerabilities in safety-critical software such as in cars?
oWhat if someone reverse engineers the protocols in cars and hacks car computer networks? (gasp!)
These are all topics I have researched and debated with my colleagues. That’s another blog posting, but I was delighted to see some independent researchers debating this issues along side representatives from large companies. The resources and vulnerability response time small and large companies can respectively allocate toward patching a vulnerability is significantly different and was evident in the way the panelists answered these questions.
I left the panel after an hour into it so that I could show off OpenOtto’s hacked car computer that was in the garage of the Seaport. (I had to silently laugh and saw Dan steal a glance at me in the crowd during all of the hacked car computer discussion during the disclosure panel when, all along, there was one sitting in the hotel’s garage! The “what if” discussion is now moot.) I drove the hacked Land Rover to the Source conference to share this open source project with some like minded hackers like Joe Grand and Travis Goodspeed and demoed it before Joe left for the airport.
I showed Joe and Travis how the OpenOtto team reverse engineered the protocols in car computers allowing us to access any car’s computer. Automotive networks follow an OSI model, so OpenOtto was designed to be like an operating system for the car—all developers have to do is write high-level applications on top of the stack and they will operate with the car’s computer using OpenOtto hardware and software.
Source was the debut of OpenOtto’s prototype board which successfully outputted a handful of performance characteristics to a laptop connected, via the prototype board, to the OBD 2 port. This is more than a scan tool and can be used to tweak performance and output A LOT of real-time parameters about the performance and error codes for all cars. This particular prototype board could output 1 of 4 of the ISO 9141 physical layer. In a couple of weeks, a device will be complete that will run all 4 physical layers using an ARM processor. (Note: At the conference, it was MOST car computers except for GM, Ford, Chevy and cars newer than 2008, but soon it’s EVERY car. Only 1 of 4 physical layers were done at the conference, but all are being done now).
After the disclosure panel, I dumped my computer equipment in Dan Kaminsky’s room and went to join him, Travis, Ian Robertson and a co-worker from RIM for dinner at the AtlanticBeerGarden. I/O Active’s party with free drinks and food immediately followed, so we stayed there until almost closing time. From there, we went to Lucky’s Bar until that place closed. At that late hour and with the Rover on almost “Empty”, I doubted I could safely find a gas station open at that hour, so I decided to stay in Boston until dawn.
We didn’t get to see Dan Kaminsky, savior of the Internet…in his super hero tights, but we did finish the night by getting my computer equipment and busting in on Dan in his hotel room while he was dorking out on his computer just a few hours before he had to catch a flight somewhere. From there, I was happy to crash for an hour of sleep on a couch in a suite before I had to drive back to Maine at the ungodly hour of 5 am. (Thank you, suite host, for your hospitality, your pillows, and your duvet.)
Until next year, thanks SOURCE Boston organizers for making it such an interesting, informative, and fun conference!
(Picture, by Travis Goodspeed, is of OpenOtto's demo board on the upper left corner on console. Toy Story Alien is not part of OpenOtto)
The venture capital pitch competition was held last Thursday night at Pace University’s Business School in NYC. What a fun event! I started the pitch about something that most people like, fast cars and computers. I used Knight Rider as a theme for the pitch. I then briefly outlined the technical capabilities about what it can do now and what it will do with some VC money when the prototype is built-out. Slides with more technical info. were shown behind me as I described how the team did it and what we’d like to do with it in the future. During the Q&A, I addressed how much money we’re looking for ($30K just to build-out the prototype).
The majority of the judges were VCs and one like it. I met with him the following evening along with the President of a car computer company that has related, but not similar, products. They liked the idea and said the market is huge, but didn’t like the reverse engineering and brute forcing the protocols that we’ve done. Although that has been a valid and legal business model in the past (Compaq did it to IBM), the VCs want it done with licenses and defensive patenting. We might be able to do it like that as long as we don’t lose the open source/free software platform. We’re talking.
We made it! OpenOtto is a finalist in a competition for venture capital financing of a new product. I'm off to NYC for the Thursday night presentation. I've been busy working on the presentation, but here is the winning pitch that got OpenOtto into the finals:
"You don’t have to be David Hasselhoff in Knight Rider to have your car talk to you. OpenOtto is a platform for developing vehicle aware products for the consumer and industrial markets. While it will not ask you how you’re doing this evening, most people don’t realize how much information your car’s computer can tell you. OpenOtto consists of a hardware interface to your car's OBD II connector as well as an extensible software platform for communicating with all networked electronic devices in the car. Designed for flexibility and scalability, it is easily expandable to future vehicle capabilities.
OpenOtto consists of two products targeted to different markets. The first is a car computer that acts as an interface between your car's computer and a 4" x 8" touch screen display that attaches to your dashboard. The interface shows easy to understand graphical output from your car's computer including, but not limited to, standard OBD II output: coolant temperature, engine speed, oxygen sensor readings, and emission related trouble codes. Advanced features include outputting suspension control, anti-lock/traction control, and air bag status.
Additional safety and security features include a remote start and kill feature for anti-theft or convenience, display warnings to users when the transmission begins to fail, individual wheel speed indicating wheel slippage, and real-time engine performance monitoring.
The second product is priced lower for the general consumer. It includes the ability to attach any cell phone with GPS to OpenOtto. Once attached, the car's computer will text message someone (e.g., a parent) if the car exceeds a certain speed and GPS coordinates will be texted, and call 911 if airbags deploy (no proprietary subscription necessary).
Safety and security is important and built into the computer engineering designs. Some features will be access controlled and transmission of all sensitive data transmitted by OpenOtto will be encrypted using industry standard best practices to ensure safety, security, and privacy of the user.
The software and hardware designs will be released as free and open source designs to encourage adoption and adaptation of the features.
For consumers, a complete dashboard mounted display with computer will cost between $300-$500.00. The closest product currently on the market costs between $1000.-$5000.000 and does not include open software and hardware platforms, graphical dash board mounted displays, or customizable features. The low cost consumer device will target a retail cost of $100-$200.