ELI5 state of global B

E38 E92 and many others. Approximately 2007 and newer
User avatar
andbel
Posts: 7
Joined: Mon Nov 04, 2024 1:39 am
cars: 2010 Tahoe
2011 HHR
2018 ATS
Location: JC, NJ, USA

ELI5 state of global B

Post by andbel »

What's the state of relatively common knowledge global B unlocking? Specifically my interest is replacing say E99 with a standalone.

* back in say E38 or E92 times, as long as one spends enough time with man-in-the-middle, one can totally replace E38 or E92 with their own ECU and rest of the vehicle would not know
* what's the E99 status? is it that all traffic is encrypted or is there some authentication similar to VAG component protection?
* T87A could be accessed without opening it. T87A is used by both global A and global B? Are they using different security mechanism depending on which global? could T87A vector be repeated on E99?
* does only have CANbus traces of any of these security mechanisms?
* what are relevant keywords, hints and tricks in general?
User avatar
Gatecrasher
Posts: 435
Joined: Fri Apr 24, 2020 8:09 pm

Re: ELI5 state of global B

Post by Gatecrasher »

Everything I've read about Global B leads me to believe the CAN messages are signed with message authentication codes and freshness values. The actual data doesn't seem to be encrypted. You should still be able to read the data once you're behind the gateway. You just can't modify it because you can't sign the content.

I don't know if every single module uses signed firmware, but everything we'd care about seems to.

HP Tuners has a way into multiple Global B ECMs, but I don't know for sure how it works. I strongly suspect they're replacing the processor with one that has their own code signing keys on it.