Modern eBike on-board computers are basically small PCs that not only offer motor control, navigation, and performance monitoring, but also store lots of sensitive user data. The Bosch Nyon series of board computers are cutting-edge devices from one of the market leaders in the eBike business, which is why they are especially interesting for forensics. Therefore, we conducted an in-depth forensic analysis of the two available Nyon models released in 2014 and 2021. On a first-generation Nyon device, Telnet access could be established by abusing a design flaw in the update procedure, which allowed the acquisition of relevant data without risking damage to the hardware. Besides the user's personal information, the data analysis revealed databases containing user activities, including timestamps and GPS coordinates. Furthermore, it was possible to forge the data on the device and transfer it to Bosch's servers to be persisted across their online service and smartphone app. On a current second-generation Nyon device, no software-based access could be obtained. For this reason, more intrusive hardware-based options were considered, and the data could be extracted via chip-off eventually. Despite encryption, the user data could be accessed and evaluated. Besides location and user information, the newer model holds even more forensically relevant data, such as nearby Bluetooth devices.
翻译:现代eBike车载电脑本质上是小型个人计算机,不仅提供电机控制、导航和性能监控功能,还存储大量敏感用户数据。作为eBike行业市场领军者的尖端设备,博世Nyon系列车载电脑对法证分析具有特殊价值。为此,我们对2014年与2021年发布的两款Nyon型号进行了深度法证分析。在第一代Nyon设备上,通过利用更新程序的设计缺陷可建立Telnet连接,从而在不损坏硬件的前提下获取相关数据。除用户个人信息外,数据分析还揭示了包含用户活动(含时间戳与GPS坐标)的数据库。此外,可伪造设备数据并传输至博世服务器,使其在在线服务和智能手机应用中持续留存。对于当前第二代Nyon设备,未能通过软件途径获取访问权限,因此需考虑更具侵入性的硬件方案,最终通过芯片剥离技术提取数据。尽管存在加密机制,用户数据仍可被访问与解析。相较于旧型号,新型号除了位置和用户信息外,还存储着更多法证相关数据(如邻近蓝牙设备)。