All posts

Emission cheating devices don't hack anything

Emission cheating devices don't hack anything.

An AdBlue emulator sits on a truck's CAN bus and sends valid sensor frames onto a bus that was built to trust whatever checks out as valid.

A hand holding a plug-in OBD2 AdBlue emulator for trucks, labelled 'Drive your truck without diesel exhaust fluid', with black smoke rising from its connector

It works for exactly one reason: the bus has no authentication.

The hacker is always drawn as a hooded stranger, but in reality, the attacker is the owner, or someone at the workshop that fitted it, with a financial reason to do it.

Then Euro 7 and UN R155 arrive: signed emissions data, sensor spoofing designed out, diagnostic access protections with real crypto.

The simple attacks will stop working. But demand does not vanish when you close the cheap door. The next defeat device will be fault injection: voltage glitching, EMFI.

Manufacturers call it expensive and rare. The tuning world has sold it over the counter for years.

I'm going to document two things: what we're actually doing about it right now, and what the next generation of attacks will look like.

Follow along. This one gets uncomfortable.