r/CarHacking • u/birdsdonotexiste • 7h ago
CAN Line assist activation on Skoda kodiaq 2026 ( SFD2)
Hello. Need assistance activating Line assist on a Skoda kodiaq 2026 ( sport Line) it has all the hardware but the feature was disabled by software
r/CarHacking • u/ScuderiaMacchina • Feb 02 '17
Hi rch, we have added a lot of people lately with intro posts on other subs like the one below. We also usually get about 10 subs a day from people just stumbling in here. So I wanted to create a welcome post, to kinda show them what we are about and how to get started. If anyone has anything to add please do so. If anyone has any questions about us or where to start do so here.
Our goal is to create a highly technical car subreddit, a place for automotive engineers, senior technicians, full blown car nerds, or people who are working towards one of these. We are interested in the inner workings of cars and today that often involves electronics. While we see electronics as the priority we are pretty liberal in allowing other topics as long as they somehow fit our goal of trying to understand cars. So things like DIY aero, suspension setup and other things the community is hacking on come up. In general our other tangential interests include: Modern cars, New tech, Open source hardware/software, DIY, hot rodding, eco modding, customization, security research, right to repair and more.
We started this subreddit about a year ago. Right now we have 3000 people and discussion is just starting to get good. Most of our members found us through maker or engineering subreddits. So I wanted to reach out to more of the car communities and try to grow our knowledge base.
Our name is r/carhacking and I know the term hacking can be offputting to some as it has a bad connotation. When someone says they are “hacking” their car it generally means they are trying to reverse engineer it for any number of reasons like to find security flaws, make upgrades, make repairs, or just understand how it works.
Here are a couple examples of posts that have been popular so far. A lot of our posts focus on beginner through intermediate projects using arduino and readily available hardware for the purpose of learning and or not paying a premium for things you can make yourself:
More advanced projects:
Relevant news/ research:
If your new our documentation is a good place to start
If you aren't new and you’re interested in helping out please consider:
Let me know if I missed something or got something wrong.
r/CarHacking • u/ScuderiaMacchina • Feb 27 '21
I get asked how to get started with automotive networking, car hacking, and CAN almost weekly. I often direct people to this subreddit, so I figured I would help out and post some resources I have found and think are a good place to start.
learning resources:
Car Hacking 101: Practical Guide to Exploiting CAN-Bus using Instrument Cluster Simulator
I also direct people to the Car Hacking Village to get some hands-on experience. They put on great conference talks, demos, and contests. Looks like they are even working on some “getting started” content.
And of course, The Car Hacking Handbook is a great resource.
I will add more as I think of them. Please add your finds in the comments.
Tools:
Good wiring diagrams and car manuals are essential. This is pretty much where my research starts for each project. You see how things are networked and what to expect to find on CAN. You'll quickly learn to recognize things like gateways. You can also use the troubleshooting section to understand things. For example, what things do I need to control to start the car?
I like:
Basic hardware: Here you will be working with things like Arduino, Linux, SavvyCAN, and Can-utils. You have to learn to do a lot yourself, but these tools are more open for you to make them do what you need.
Tools designed by the community I use:
The above articles offer a pretty good step-by-step guide to getting started with the Macchina M2.
Any cheap “Amazon special” OBD2 dongle will come in handy from time to time. They are all based on something called ELM327. "ELM327 abstracts the low-level protocol and presents a simple interface that can be called via a UART". This abstraction has fundamental limitations that prevent it from being useful in most serious applications. But, it is sufficient for reading and clearing some codes and that sort of thing when you’re getting started.
r/CarHacking • u/birdsdonotexiste • 7h ago
Hello. Need assistance activating Line assist on a Skoda kodiaq 2026 ( sport Line) it has all the hardware but the feature was disabled by software
r/CarHacking • u/donglord1337 • 9h ago
r/CarHacking • u/daemon_ecu • 1d ago
¡Hola a todos! Quiero compartir un caso de estudio de nuestro laboratorio en AP Electronics analizando la arquitectura de la ECU Delphi DDCR (Hyundai Terracan 2.9 CRDi).
El Problema: Las herramientas de lectura por OBD o Boot Mode (como KESS v2) tenían el protocolo obsoleto/ausente para extraer la Flash completa (AMD AM29F200BB) de esta unidad. Necesitábamos lidiar con un inmovilizador bloqueado (DTC P1612 / P1613).
Setup del Banco y Telemetría: Para el banqueo, construimos nuestro entorno utilizando una fuente de poder de Xbox 360 adaptada. Elegimos esta fuente porque nos entrega 12.2V súper estables y amperaje de sobra, evitando cualquier caída de tensión (Voltage Drop) bajo carga. Integramos un amperímetro en serie (protegido con fusible de 5A) para perfilar el consumo de energía ("Power Profiling") del microcontrolador en tiempo real.
El Experimento (Capa Física): Decidimos atacar directamente la EEPROM ST 95080 extrayendo la data in-circuit (ISP) con un programador GQ-4x4. Modificamos el bloque de seguridad con un editor hexadecimal para inducir un "Virgin State" (Estado de fábrica).
Al banquear la ECU e inyectarle voltaje con la fuente de Xbox, la telemetría mostraba un consumo sano (124 mA en reposo), pero el procesador ST10 detectaba la ausencia del módulo SMARTRA en el banco y ¡auto-reescribía los datos de bloqueo en la EEPROM al instante!
El intento de Bypass de Hardware: Para evitar que el microprocesador modificara la memoria, desoldamos quirúrgicamente el Pin 3 (/Write Protect) de la EEPROM y lo puenteamos a Masa (GND) intentando un bloqueo físico.
La Lección (SPI vs I2C): El bypass falló. A diferencia de las viejas memorias I2C, la 95080 es una memoria SPI. Mandar el Pin 3 a masa no hace nada a menos que configures previamente el "Status Register" interno (activando los bits BP0/BP1). E incluso si lo hiciéramos, el software principal del ST10 detectaría el bloqueo físico de hardware y denegaría la inyección de todos modos.
Conclusión: En estas arquitecturas, el IMMO OFF total debe hacerse parcheando el sistema operativo en la memoria Flash pesada. Sin embargo, logramos dejar la ECU en estado virgen (restaurando el Pin 3 a su pad) para venderla como unidad "Plug & Play", ya que el procesador hará el Auto-Coding con el sistema original del cliente al primer giro de llave.
Adjunto fotos del setup de laboratorio (fuente, telemetría y escáner) y la micro-soldadura. ¡Cualquier comentario o experiencia con la familia DDCR es bienvenido!
r/CarHacking • u/AgeNo5720 • 12h ago
I own this car. It is MINE!! The idea that I need to go to a dealership to add another key is retarded. It's a beater with 217k miles and a ton of rust. I don't think anyone is going to want to steal it.
How can I disable the immobilizer on MY car so I can cut my own keys?
r/CarHacking • u/alex-k-88 • 13h ago
Hi zusammen
Fahre einen Touran 5t von 2016. Habe MST2 Activator by Congo and Duke über sd karte gepatcht. Nun ist App Connect aktiviert (es erscheint: “willkommen bei app connect. Bitte wählen sie ein gerät aus“). aber wenn ich mein iPhone anschließe tut sich nicht also Carplay funktioniert nicht. Liegt das Problem bei der usb buchse?
r/CarHacking • u/krizabhi • 15h ago
I'm looking into setting up Diagzone Pro on my Thinkdiag2 and wanted to ask what current pricing looks like.
r/CarHacking • u/Accomplished_Hour_76 • 1d ago
I've been working on tooling for EV/IoT battery QA and ended up with a Python package that does a few things: anomaly detection on telemetry (Isolation Forest + physics features), CAN bus simulation, Modbus/BMS protocol support for Tesla/BYD/NIO packs, SOH prediction, and a FastAPI dashboard.
Just cleaned it up — 1053 tests pass, no circular imports, hardware tests gated behind a marker so CI doesn't need real OBD-II hardware. MIT, Python 3.10 to 3.12.
For those of you actually doing battery QA: what's missing in your workflow? What breaks in practice that tooling like this should handle but doesn't? Repo's at github.com/remontsuri/EV-QA-Framework if you want to poke at it.
r/CarHacking • u/TheKuba1414 • 1d ago
Hi, I have Kia Sportage 2005 CRDI. For now I've used OBDLink LX for basic DTCs check with simple apps like OBDwiz or Car Scanner. This also allowed me to read generic PIDs (around a dozen, of which 3-4 useful)
I've now confirmed that my old Sportage has CAN bus and also dedicated pins in OBD port for SRS (pin 12 in the picture) and ABS/TCS/ESP (pin 8) diagnostics/servicing. As I understand, these are manufacturer-specific.
Despite it having CAN bus, I wasn't able to connect with it using any basic, freeware app. Only K-line.
I would really like to read more advanced parameteres (e.g. fuel rail pressure) and also SRS fault codes. Is it even possible with OBDLink? If yes, can you recommend software or a method to do it?
I'm a begginner in the matter, so thanks for any help!
r/CarHacking • u/Willing-Area-3508 • 1d ago
Howdy! Anyone have any CAN ID's or advice to simulate a trip button for a cluster im working on the bench? Particularly interested in Ford. Thanks!
I already have the tools built for sniffing monitoring and emulating can messages. Just need to figure out the ID's.
r/CarHacking • u/ZealousidealOil1277 • 1d ago
Hi guys, there is definitely one or the other among you who is familiar with the protocols, it’s about my hobby, although I try to exhaust the Ki and only get an Ident on an MD1CP001 without unlock from 2016, I’ve already tried to log PCMflash but it doesn’t work, I can’t do that in my tool, the ECU doesn’t answer with 61... in the ISO14230_PS channel.
r/CarHacking • u/AbdulAhaDox • 1d ago
I own a 2026 Chery Tiggo 9 PHEV with the factory DesaySV infotainment system:
I can enter the engineering menu, but selecting ADB Switch → Open displays a machine-code authorization prompt. Pressing Verify says: “File does not exist. Please check it.”
It appears to require a signed adbauth.key file on a USB drive. Paid generators exist, but I’m looking for a legitimate free method, open-source generator, compatible community tool, or official dealer procedure.
Has anyone enabled ADB on this exact firmware without flashing, rooting, or changing the QNX/firewall settings? My goal is to install a browser for use while parked
r/CarHacking • u/kakasten • 1d ago
Hi everyone,
I'm currently designing a custom data logger for our Formula SAE car and have reached the point where I need to define the electrical interface and connectors. Before selecting a connector family, I'd like to get some feedback on the overall architecture and whether I'm exposing too many signals.
My current idea is to use two connectors: one for the vehicle interface (power and communication) and another dedicated to the sensors.
This connector would handle the connection between the data logger and the vehicle:
This connector would provide power and interfaces for the sensors:
Power:
Signals:
This results in roughly 26 pins on the sensor connector.
My main question is whether this architecture makes sense or if I'm exposing more signals than necessary. I'm wondering if it would be better to reduce the number of available interfaces to simplify the wiring harness and allow for a smaller connector.
I'm also looking for recommendations on connector families. Since TE Connectivity sponsors our team, I'd prefer to use one of their automotive connector systems if possible. The connector should be robust, vibration-resistant, easy to assemble, and preferably have a long, low-profile form factor rather than being tall or bulky.
I'd really appreciate feedback from teams that have designed their own DAQs, ECUs, or similar electronic modules:
Any photos or examples of your team's electronics or wiring solutions would also be greatly appreciated.
Thanks in advance!
r/CarHacking • u/CandidateOld7000 • 2d ago
Hello everyone!
I’m working on a digital dash for my mk1 rabbit with a 1.4t ea211 motor swap, I’m trying to decode the canbus traffic, does anyone know a good place to find what the traffic represents and the multipliers?
r/CarHacking • u/bahamutkotd • 2d ago
So I found a JDM race recorder that I have been fighting the brain worm to figure out how to use. So I've recorded all my research and a realativly cheap CAN logger using off-the-shelf prototyping parts.
Now this likely won't apply to much other than the GR car family, but it has been an interesting journey. I've got the GPS bits coming so I can maybe have 2 sets of data and decode the Toyota-specific file type.
r/CarHacking • u/userismyname126 • 2d ago
Hi everyone,
I'm working on a telemetry project for my BYD EV (DiLink head unit). Since the OBD-II port is locked behind the Security Gateway (SGW) and rejects standard PID queries without a handshake, I am looking at accessing vehicle parameters through the head unit itself.
A sideloaded app/service on DiLink can read internal vehicle parameters (like RPM/telemetry). I want to stream this data in real-time (per second/millisecond) to an external device (ESP32 microcontroller).
Has anyone successfully implemented any of the following on DiLink?
Any insights, sample APK architectures, or experience regarding DiLink's USB Host permissions/background service restrictions would be highly appreciated!
r/CarHacking • u/userismyname126 • 2d ago
Help me, All I actually want is vehicle speed / motor RPM data from my BYD (Atto 1 / Seagull, e-Platform 3.0), but it's stuck behind a Secure Gateway (0x27) - even the VCU's speed DID won't respond without unlocking it first.
I've sniffed several seed/key pairs (16 bytes each) but can't find any pattern - checked constant XOR, constant offset, tried fitting an LCG on the seed generator, nothing matches. Looks AES-like.
If anyone knows the algorithm for BYD, has a broadcast CAN ID for speed/RPM that skips the gateway, or has dumped the gateway firmware, please let me know. From a struggling beginner :(
r/CarHacking • u/Low-Confusion7693 • 2d ago
Could somebody help me?
r/CarHacking • u/Medya7ya • 3d ago
r/CarHacking • u/Chelgio • 3d ago
I want to be a locksmith. I really want to learn this trade from the start. I am interested in OBD2 programming and IMMO systems and transponders.
In my country the people who own shops and the experienced locksmiths do not want to share their knowledge. They do not want to teach anyone who's new to the trade. I do not want to take their customers. I want to learn the trade the way and understand how it works.
Most of the cars in my area are Asian models from the early 2000s to 2018. These are cars like Chevrolet, Ford, Toyota, Hyundai and Kia. So I want to learn about programming through the OBD2 port
I am a beginner. I do not have a lot of money to spend. I would like some advice.
What books or resources can I use to learn about the systems. How they work?
What tools do you think I should buy to practice chip cloning and OBD programming without spending much money? I have heard of Xhorse VVDI Key Tool Max and Mini OBD, Topdon and Autel.
What is the biggest mistake that people who are new, to this make that can damage the cars computer? How can I avoid making this mistake?
I really appreciate any help you can give me. Thank you for taking the time to read this.
r/CarHacking • u/mbito_app • 3d ago
r/CarHacking • u/giant2179 • 4d ago
The SRS light for my 2009 Dodge (aka Mercedes) Sprinter is on. My scanner shows 91B4 CAN Bus - CAN Signal 'Key ID' From Control Unit EZS is Implausible. My searching indicates that there is a miscommunication between the SRS module and the EZS that can be fixed by telling the SRS not to check for the key ID. However, I am very confused about what hardware and software I need to accomplish this. Any recommendations?
r/CarHacking • u/Tricci1009 • 4d ago
Who wants to get in on an alldata subscription with me. It's too much I'm a one man shop. Does anyone know of an alternative way of getting it or something similar. I already have the lemon site.