Xiaomi scooters get crypto protection: third-party OTA firmware cannot be installed

Programmer Daljeet Nandha studied a recent firmware update for his Mi 1S electric scooter and found out that it has a hash signature using the SHA256 cryptographic protocol and its verification. As soon as a new version of the system is installed, the electric scooter stops accepting any OTA updates that are not signed by Xiaomi (that is, all third-party ones). This means that it will no longer be possible to reflash the gadget using a hacker application on a smartphone (at least if there is no loophole). It is reported by Hackaday.

Most often, owners reflash Xiaomi electric scooters in order to remove software speed limits set in accordance with the laws of some countries. However, protection against illegal flashing can also prevent the modification of scooters.

There were also mentions in the update code that in the future Xiaomi could also protect the firmware of the ESC board (an electronic speed controller responsible for controlling the engine) with cryptography – if this happens, it will not be possible to reflash electric scooters in order to remove the speed limit by any existing methods.

Source: Trash Box

You may also like