Modern Day Automobile Safety: Rescue Ops using CanBus
Checco (Fire Instructor), Kat Delorean
BSides NYC 2023 (0x04) · Day 1 · Talk - Other
Overview
In an era where vehicles are increasingly sophisticated computers on wheels, the security implications extend far beyond protecting personal data or preventing theft. This talk, "Modern Day Automobile Safety: Rescue Ops using CanBus," presented by veteran fire instructor Checco and automotive safety advocate Kat Delorean, delves into a critical yet often overlooked aspect of automotive cybersecurity: leveraging vehicle systems for enhanced emergency response and occupant safety during severe accidents. The speakers highlight the growing challenges faced by first responders in extricating individuals from modern, technologically advanced vehicles and propose an innovative solution rooted in the very systems that make these cars complex.

Key moments
- 0:00 Speaker introduction and unique background
- 1:40 Understanding Drive-by-Wire, CanBus, and Drive-by-Command
- 3:30 Past CanBus exploits and car hacking examples
- 4:40 Proposing CanBus for rescue; defining auto extrication
- 5:40 Rescue challenges: electronic door handles and hidden overrides
- 6:50 Airbags and seatbelt pretensioners as extrication obstacles
Modern Day Automobile Safety: Rescue Ops using CanBus
Speakers: Checco (Fire Instructor); Kat Delorean
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=ZX4MqLx3Lew
Overview
In an era where vehicles are increasingly sophisticated computers on wheels, the security implications extend far beyond protecting personal data or preventing theft. This talk, "Modern Day Automobile Safety: Rescue Ops using CanBus," presented by veteran fire instructor Checco and automotive safety advocate Kat Delorean, delves into a critical yet often overlooked aspect of automotive cybersecurity: leveraging vehicle systems for enhanced emergency response and occupant safety during severe accidents. The speakers highlight the growing challenges faced by first responders in extricating individuals from modern, technologically advanced vehicles and propose an innovative solution rooted in the very systems that make these cars complex.
The core premise of the presentation is to adapt the principles of Controller Area Network (CAN bus) exploitation, traditionally associated with malicious hacking, for life-saving purposes. By envisioning a "fire service mode" that emergency personnel can activate, the talk explores how automated commands could stabilize a vehicle, improve access to trapped occupants, facilitate egress, and even aid in fire suppression. This paradigm shift, moving from brute-force extrication to software-assisted rescue, promises to significantly reduce critical rescue times and mitigate risks for both victims and responders, ultimately underscoring the profound impact that thoughtful cybersecurity integration can have on public safety.
Background
▶ Watch: Speaker introduction and unique background (0:00)
The evolution of automotive technology has dramatically altered vehicle design and functionality, introducing both advanced safety features and unforeseen challenges for emergency services. Checco begins by defining key terms: Drive-by-Wire (DBW), an electronic system where physical controls (like a steering wheel) send electrical signals instead of direct mechanical connections; Controller Area Network (CAN bus), the internal communication network for electronic control units (ECUs) within a vehicle; and Drive-by-Command (DBC), which builds on DBW by routing commands through the CAN bus, akin to "infrastructure as code" for vehicles. A crucial point is the lack of standardization in DBC definitions across manufacturers, leading to interoperability issues.
The history of CAN bus vulnerabilities is well-documented within the cybersecurity community. Notable incidents include Chris Roberts' claims of airline system manipulation (though disputed at the conference where he was denied boarding) and the seminal 2015 Jeep Cherokee hack, which demonstrated remote control over critical vehicle functions like steering and braking. More recent exploits, such as accessing the CAN bus via the headlight port to manipulate systems, further illustrate the pervasive insecurity. Checco points out that over 16 car manufacturers have similar CAN bus vulnerabilities, hinting at systemic issues.
From a firefighter's perspective, modern vehicles present formidable obstacles. The traditional extrication playbook involves three stages: stabilization of the vehicle, EMS access to the patient, and patient egress. However, contemporary designs complicate each step:
- Electronic Door Handles: Vehicles like Teslas, with handles that retract or rely on electrical power, can trap occupants if the electrical system is compromised in a crash. Manual overrides are often hidden, making them inaccessible in panic situations.
- Airbag Deployment: While life-saving, deployed airbags create "brick walls" for rescuers. The force of inflation is significant, and seatbelt pre-tensioners exist specifically to pull occupants back to prevent them from hitting inflating airbags.
- Vehicle Stability: Keyless entry systems and fobs can inadvertently restart vehicles, causing them to roll post-crash, as seen in an FDNY incident where a firefighter broke his leg. Modern cars with crumple zones (designed to collapse) often place fuel tanks in these areas, leading to more post-collision fires.
- Ultra-High Strength Steel (UHSS): Widely used in modern vehicle cabins, A-posts, B-posts, rocker panels, and roof panels, UHSS significantly enhances occupant safety. However, it poses an immense challenge for extrication tools. Spreaders can fracture it, and cutters often fail before the metal does, making cutting open a car a "hit or miss operation." Checco recounts an incident with a Honda Pilot where the UHSS protected children in car seats but made extrication extremely difficult.
- Electric Vehicle (EV) Hazards: EV battery platforms, often forming the vehicle's undercarriage, operate at high voltages (e.g., 700 volts DC). While systems automatically disconnect from the battery during a crash, the platform itself remains a live energy source. Furthermore, the thinnest part of the battery platform is often the shroud between the battery and the passenger cabin floorboards, meaning EV fires can rapidly spread upwards into the cabin.
These challenges highlight a growing disconnect: while automotive technology prioritizes occupant safety during impact, it often inadvertently creates new dangers or inefficiencies for emergency responders tasked with post-crash rescue.
Key Findings
▶ Watch: Past CanBus exploits and car hacking examples (3:30)
The central finding and contribution of this talk is the innovative proposal for a "fire service mode" within modern vehicles, leveraging the existing CAN bus system to facilitate safer and faster rescue operations. Instead of viewing vehicle electronics solely as a security vulnerability or a post-crash hazard, Checco and Delorean advocate for their deliberate integration into emergency protocols. This mode would automate critical functions during a crash, transforming the vehicle from an obstacle into an aid for first responders.
The speakers estimate that implementing such a system could save anywhere from five minutes to an hour in typical extrication scenarios, with even a conservative estimate of 15 minutes being potentially life-saving. This time reduction is crucial, as every minute counts in severe trauma cases. The "fire service mode" would be triggered automatically by crash sensors or manually by responders using a universal remote, similar to a firefighter's elevator key. Critically, this mode would only activate if a crash sensor has already been triggered, preventing its misuse on undamaged vehicles.
The proposed system addresses the three core phases of extrication—stabilization, access, and egress—along with enhanced fire control, by automating specific vehicle functions:
- Stabilization: Turning off the engine and accessories, engaging the parking brake, cutting fuel flow, activating high-voltage disconnects in EVs, and deflating tires to prevent vehicle movement.
- Access: Disabling airbags (post-crash), unlocking all doors, rolling down windows, exposing manual door handles (where electronic ones exist), and unlatching rear doors/hatches.
- Egress: Automatically raising the steering column, reclining seats, and spreading seats to create more space for victim removal.
- Fire Control: Integrating onboard sprinkler systems or fire retardant capsules, particularly crucial for EV battery fires.
This proactive approach represents a significant shift from current reactive, often destructive, extrication methods. It posits that the same digital control that makes modern cars complex can, with intentional design, make them safer for post-crash rescue.
Technical Deep Dive
▶ Watch: Proposing CanBus for rescue; defining auto extrication (4:40)
The technical foundation of this proposal rests entirely on the Controller Area Network (CAN bus), a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other in applications without a host computer. Modern vehicles are essentially distributed networks of ECUs communicating over the CAN bus, controlling everything from engine management to infotainment to safety systems.
The concept of Drive-by-Command (DBC), as defined by Checco, is key. Instead of direct physical connections, commands are sent digitally over the CAN bus to actuators. This digital control is what hackers have exploited, and what the speakers propose to harness for rescue. A significant technical challenge highlighted is the lack of standardization in DBC definitions across different car manufacturers. Each manufacturer uses proprietary DBC files, meaning a command for "engine speed" in one car might correspond to "brakes on" in another. This proprietary nature complicates the development of a universal "fire service mode" remote.
The proposed "fire service mode" would involve specific CAN bus commands to manipulate various vehicle systems:
Stabilization Operations via CAN bus:
- Engine/Accessory Shutdown: Sending a command to the engine control unit (ECU) to power down the engine and non-essential electrical accessories. Many modern cars already have automatic fuel flow cut-offs during a crash.
- Parking Brake Engagement: Activating the electronic parking brake system through a CAN command, which is often standard in newer vehicles.
- High-Voltage Disconnect (EVs/Hybrids): While some EVs automatically disconnect high-voltage systems post-crash, a dedicated command could ensure this or manage the 12-volt system, which often remains energized even after a crash.
- Tire Deflation: A more advanced concept, requiring integration with tire pressure monitoring systems or dedicated actuators to rapidly deflate tires, preventing vehicle movement on inclines.
Access Operations via CAN bus:
- Airbag Disablement (Post-Crash): This is a critical safety feature. After initial deployment, airbags can still pose a hazard if they re-engage or if non-deployed airbags are inadvertently triggered by rescue operations. A CAN command to disable all airbag triggers after a crash would require significant vendor support and regulatory changes, as airbag systems are heavily regulated.
- Automatic Door Unlocking/Window Rolling Down: Many vehicles already have features like holding a key fob button to roll down windows (e.g., Honda), demonstrating the existing software capability. Extending this to all doors and windows via a "fire service mode" command is technically feasible.
- Exposing Manual Door Handles: For vehicles with electronic handles (like Tesla), a command could cause the manual override handles to pop out, making them immediately accessible.
- Rear Door/Hatch Unlatching: For SUVs and hatchbacks, a command to unlatch the rear cargo area could provide an alternative access point.
Egress Operations via CAN bus:
- Steering Column Raise: Electronically adjustable steering columns could be commanded to move to their highest position, creating more space for patient removal.
- Seat Recline/Spread: Electronically controlled seats could be commanded to fully recline or even spread outwards, aiding in freeing trapped legs or creating space for spinal immobilization. This would require careful consideration of the victim's position to avoid further injury.
Fire Control Operations via CAN bus:
- Integrated Sprinkler Systems/Fire Retardants: While not commonly implemented due to weight and cost, a CAN-controlled onboard fire suppression system (e.g., water mist for passenger cabin, dry chemical for engine compartment) could be activated automatically or by command. This is particularly relevant for managing rapidly escalating EV battery fires.
Implementation Challenges and Technical Hurdles:
Kat Delorean, drawing on her automotive manufacturing background, highlights significant obstacles:
- Regulatory Compliance and Testing: Any modification to a vehicle's safety-critical systems, even a software change, typically requires a 50,000-mile road test for homologation (safety certification). This process is incredibly expensive and time-consuming. Even minor changes, like automatic parking brake engagement or self-deflating tires, would likely necessitate full re-testing, including crash tests, to ensure they don't inadvertently trigger at the wrong time (e.g., parking brake engaging while driving).
- Vendor Support for Airbags: Airbag systems are highly regulated. Disabling airbag triggers post-crash would require the cooperation of airbag system vendors and changes to existing regulations, a complex and protracted process.
- Cost vs. Capitalism: The "25 cents more" anecdote from John DeLorean's "GM Repair Manual" illustrates that even small per-unit costs, when multiplied by millions of vehicles, become a massive barrier for manufacturers unwilling to absorb them unless mandated. This often means that safety enhancements are not implemented until required by law.
- Security vs. Usability: Implementing CAN bus encryption to prevent malicious hacking raises a usability dilemma. While encryption would secure the bus, it could force vehicle owners to go to authorized dealers for even basic servicing, as independent mechanics might not have the decryption keys. The speakers propose a solution: encrypt the CAN bus during normal operation but automatically decrypt it in "crash mode" to allow universal access for emergency responders.
- Victim Stabilization: For features like automatic seat recline or steering column adjustment, responders need control. If a victim has a spinal injury, automatic movements could worsen their condition. This suggests that some "fire service mode" functions should be manually initiated by responders after an initial assessment, rather than fully automated.
The technical vision is clear: leverage existing vehicle intelligence for rescue. The challenge lies in overcoming the regulatory, economic, and security complexities inherent in the automotive industry.
Demo / Proof of Concept
▶ Watch: Rescue challenges: electronic door handles and hidden overrides (5:40)
The talk did not feature a live technical demonstration or proof of concept of the proposed "fire service mode" system. Instead, the speakers utilized extensive video footage and detailed explanations of real-world extrication scenarios to illustrate the current challenges faced by firefighters and to highlight precisely where their proposed CAN bus-controlled solutions would yield significant benefits. The videos showcased the manual, labor-intensive, and often dangerous techniques involved in stabilizing vehicles, gaining access, and removing victims, thereby serving as a compelling backdrop for the theoretical discussion of software-assisted rescue.
Defensive Implications
▶ Watch: Airbags and seatbelt pretensioners as extrication obstacles (6:50)
The "fire service mode" concept, while framed as an offensive capability for first responders, carries significant defensive implications for public safety and automotive design. The primary "defensive" action is to proactively design vehicles to be safer and more accessible during post-crash rescue, mitigating the inherent dangers that modern automotive technology inadvertently creates.
- Mandate "Fire Service Mode" Features: The most impactful implication is the call for regulatory bodies (like NHTSA) to mandate the inclusion of a "fire service mode" in all new vehicles. Just as seatbelts became mandatory, integrating software-driven rescue capabilities could become a standard. This would overcome the economic disincentive for manufacturers (the "25 cents" problem) and ensure universal adoption.
- Standardize CAN Bus Commands for Emergency Services: To enable a universal remote for firefighters, the automotive industry would need to standardize a subset of CAN bus commands specifically for emergency functions during a crash. This would allow a single tool to interact with vehicles from different manufacturers, much like the universal fire service elevator key.
- Prioritize Post-Crash Accessibility in Design: Manufacturers should consider the "fire service mode" during the initial design phase, rather than as an afterthought. This includes making manual overrides for electronic systems (like door handles) easily discoverable and accessible in a crash, or designing for automated deployment of these overrides.
- Enhance Onboard Diagnostics for Responders: Vehicles could transmit crash status signals (e.g., vehicle orientation, deployed airbags, high-voltage system status) to emergency services automatically, providing critical intelligence before responders even arrive on scene. OnStar already provides some similar notifications.
- Personal Vehicle Kill Switches: While the talk focuses on institutional rescue, the discussion of kill switches (often used as anti-theft devices) also applies to personal safety. A personal kill switch can immediately disable a vehicle's electrical systems, preventing accidental restarts or further damage post-crash, and could be integrated into a "fire service mode" for the owner's benefit.
- Secure CAN Bus with Crash-Mode Decryption: The proposed approach of encrypting CAN bus communications during normal operation but automatically decrypting them in a verified "crash mode" offers a balanced solution to security and emergency access. This prevents malicious actors from exploiting the CAN bus in an operational vehicle while ensuring that first responders can access critical functions when a life is at stake.
- Invest in EV Fire Suppression: Given the unique challenges of EV battery fires, manufacturers should invest in integrated fire suppression systems within the battery platform or passenger cabin, which could be activated via the CAN bus.
Ultimately, the defensive implications extend beyond protecting the vehicle from attack to protecting human life from the unforeseen consequences of advanced vehicle design. By embracing the capabilities of the CAN bus for rescue, the automotive industry can significantly enhance real-world safety.
Key Takeaways
- Modern vehicles pose increasing challenges for emergency extrication: Advanced materials like ultra-high strength steel, complex electronic systems like drive-by-wire, and features such as electronic door handles and high-voltage EV batteries make traditional rescue operations slower, more dangerous, and less effective.
- The "fire service mode" concept leverages CAN bus for rescue: By adapting principles of CAN bus manipulation, vehicles could enter an automated "fire service mode" during a crash to stabilize, improve access, and facilitate egress for trapped occupants, significantly reducing rescue times.
- Proposed automated functions cover all rescue phases: This mode would include actions like engine shutdown, parking brake engagement, airbag disablement (post-crash), automatic door unlocking, window rolling down, steering column elevation, and seat adjustments.
- Significant time savings are possible: Even conservative estimates suggest that software-assisted rescue could save 15 minutes or more in critical situations, potentially making the difference between life and death.
- Regulatory and economic hurdles are substantial: Implementing such a system faces major obstacles, including stringent 50,000-mile road testing requirements for safety certifications, the high cost for manufacturers (even for minor changes), and the need for vendor support and regulatory changes for critical components like airbags.
- Balancing security and usability is crucial for CAN bus encryption: While encrypting the CAN bus can prevent malicious hacking, a "crash mode" decryption mechanism is proposed to ensure universal access for emergency responders when lives are at stake.
About the Speaker(s)
Checco is a seasoned professional with a dual career spanning over 40 years. He is a highly experienced volunteer firefighter and fire instructor, specializing in vehicle extrication and EV fire safety. Parallel to his emergency services career, Checco has a robust background in cyber security and technology, allowing him to uniquely bridge the gap between these two seemingly disparate fields. His passion for this topic stems from his extensive experience on accident scenes and his desire to apply technological solutions to real-world safety problems.
Kat Delorean brings a unique perspective as the daughter of automotive legend John DeLorean, a staunch advocate for vehicle safety who famously testified before Congress to mandate seatbelts. Kat herself has a strong background in cybersecurity, having spent 20 years working at Bank of America. She is now involved in building a car company focused on automotive engineering and safety research, continuing her father's legacy. Her expertise provides critical insight into the manufacturing, regulatory, and economic challenges of implementing advanced safety features in the automotive industry.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A genuinely interesting cross-disciplinary concept — using CAN bus command injection as a rescue tool rather than an attack vector — delivered by speakers with real credibility in their respective lanes. The idea has merit and the problem framing is honest, but the talk stays conceptual throughout: no PoC, no actual DBC reverse engineering, no vendor engagement, and the 'fire service mode' remains a napkin sketch rather than a tested proposal.
Heather Calloway (CISO) — SOLID
A genuinely novel cross-domain pitch — fire service meets CAN bus — with real operational grounding from a working fire instructor. The concept is interesting and the problem statement is credible, but it stays at the proposal stage throughout, with no proof of concept, no regulatory path, and no clear owner for the next step.