Hi, there is some very useful information here.
However I still have some few questions I hope you can answer.
I have not yet figured out how to actually get any permissions to read data from the vehicle.
-
Does the combination of FordPass and 2857375093 actually spoof the FordPass app with all privileges to the vehicle?
From the examples provided at experiments/try_vehicle_data.py it was not really that clear if that's the case or whether those examples are just PoCs.
-
Have you been able to figure out - if the above is the case - whether or not any of the AppIDs provide any kind of different permissions and do you happen to have a documentation for that on hand?
-
How does the vehicle receive the Information whether or not any app_name - app_id combination is actually valid?
I would guess they would query some Ford endpoint, however, AppLink is EOL and most Sync3 - 4 vehicles probably haven't seen the internet for about 10 years now.
-
The SDL-Documentation provides hints at "security". Would I have to set any specific security level to spoof an official app?
Hi, there is some very useful information here.
However I still have some few questions I hope you can answer.
I have not yet figured out how to actually get any permissions to read data from the vehicle.
Does the combination of
FordPassand2857375093actually spoof the FordPass app with all privileges to the vehicle?From the examples provided at experiments/try_vehicle_data.py it was not really that clear if that's the case or whether those examples are just PoCs.
Have you been able to figure out - if the above is the case - whether or not any of the AppIDs provide any kind of different permissions and do you happen to have a documentation for that on hand?
How does the vehicle receive the Information whether or not any
app_name-app_idcombination is actually valid?I would guess they would query some Ford endpoint, however, AppLink is EOL and most Sync3 - 4 vehicles probably haven't seen the internet for about 10 years now.
The SDL-Documentation provides hints at "security". Would I have to set any specific security level to spoof an official app?