The firmware updating has been one of my concerns with android head units. I even brought it up with Eonon support a few times, advising that even though it is a car, due to it being full android, there are security risks. Their standard answer was "It's a car stereo and no one updates firmware on them." So that is a very valid point. The unsecured in the car, in case of break in or theft, is also another good point. I hope the many people buying Android head units get to see this video as I can guarantee a lot of them don't think of the things you've mentioned.
@SirBrass Жыл бұрын
Aren't security updates handled by updates to the Google services which happens with software updates through the play store and not through base firmware?
@jongittus2279 Жыл бұрын
100% agree, a 2nd account is the best idea for peace of mind. However it is possible to set a screen lock on most units, even if the option isn't visible in the security settings using a third party app. That way all a potential thief could do is wipe the headunit in which case all your accounts are gone.
@Tsiqara Жыл бұрын
Valid point regarding screen lock. It would be interesting to know an opinion of an autor of the video about screen lock effectiveness on HU's in protecting our privacy.
@stevebusch1205 Жыл бұрын
Great eye opening video. I started thinking about the security issues when I got into AI boxes. I am on my third AI box because of multiple issues. Mostly because of their glitchy nature and support from the manufacturer. My first worry was when I would sign into my G account, I would get the security email warning of “did you sign into this device”. What threw me was the device that was listed. They were all older Android phones, not the AI box name. Made me think. Then I started returning the boxes that I did not like and hoped that I factory reset the device and wiped all my personal data. Your video brings up the many security issues we all need to be aware of. Great job
@bobcar82410 ай бұрын
Thank you for your excellent advice. I really appreciate all the good information you put online. Cheers from Arizona!
@ps2-one Жыл бұрын
Important message, well done. I'd like to add that it's also not a good idea to add your (main) home Wifi connection, use your guest Wifi connection instead. Allot of android devices from unknown brands contain malware, so be cautious.
@krecikowi9 ай бұрын
any way to scan for this malware?
@willehuuskonen2 ай бұрын
Thank you for pointing out this issue. I wonder however is it that if your main source for music is KZbin and you have a KZbin premium subscription on your main Google account, then logging in with a second account will make you listen to all the annoying ads again. So is there a way to securely access KZbin premium on your car stereo without logging in with your main credentials and exposing all your data?
@ModeratelySpeaking19 күн бұрын
Fantastic Video! This now brings up a concern for me, having implemented my newly exclusive Android head unit gmail account. Please provide advice and apologies if this was already covered- How would I go about buying and installing paid apps from Google App store, onto this head unit when you have to associate a payment method in the play store account? There is no purchase as "guest" option which I believe would help alleviate this issue. What are our thoughts here? Thanks!
@lezbriddon Жыл бұрын
Security made me think of theft prevention. In all your experience with head units have you ever seen a quick release slide out/pull out caddy? We had them many years ago for CB radios etc to help prevent theft? While I would be worried of a high value unit being stolen my main reason would be that on our camper van it could be pulled from the dash and slid into a duplicate mounting 'station' at the back in the sitting/living area, we have had the van a while now and I keep putting off buying incase there's a next best thing!
@HaddaClu Жыл бұрын
Thats the nice thing about the Boss floating screen head units; they have quick release screens. Granted they aren't running android, but its still something nice.
@roadie312411 ай бұрын
My 1984 Saab 900 TU5M came with an Alpine single DIN stereo with a removable "head unit". There was a button on the side that released the front part. Saab/Alpine even provided a carry case to protect your precious device. It became a meme in the 1980s with uncool engineer/architect/accountant types telling their friends about them.
@SethBerry79Ай бұрын
One of my favorite features of my Eonon is that I get automatic software updates from Eonon every couple of months. Though I have no idea what these updates consist of (likely features and bugs only), it gives me a little more confidence that they care and are looking out for their customers. Do you know if security would be an aspect of the updates?
@Croi_Fiain Жыл бұрын
On a similar note... I have only just come across your very useful channel and have only really discovered that what I would refer to as non-standard head unit brands that I've used for decades (Alpine, Kenwood, Sony, etc) even exist, let alone being actually very good. This may be a ridiculous question so please bear with me.... Or scoff and laugh :) My "discovery" has come at a time when there is increasing suspicion about tech manufacturers which may or may not be directly or indirectly funded and monitored by certain governments (for example TikTok) and the outright banning of such apps etc on government officials' devices. Also there's the recently news about Tesla employees sharing video footage from parking cameras installed in customers' cars even when the cars are apparently switched off.... So your note here on security is a timely one. I am fully aware that our phones are effectively listening to us and monitoring conversations on apps which lead to suspiciously well timed adverts for whatever products we talk about with friends - so there is an argument that we can't stop our privacy being invaded anyway. Where do we balance paranoia with a desire for shiny functionality...? Can we protect our privacy when installing kit in our cars made by brands plenty of people have never heard of? How can we reassure ourselves our data, be it driving data, app usage, routes driven, camera footage etc etc is "safe"? Or shall I just stick with a 15yr old FM radio with an AUX IN connection? I'm almost thinking of whether anyone will write a user friendly packet sniffer/firewall app!
@SaabUnleashed Жыл бұрын
There lies the main point. These are car head units at the end of the day, why give them access to anything that they simply do not need? Ultimately, the data collected by navigation and media apps is only relevant if it can be alligned with with your larger data footprint. So avoiding using key accounts on these will help with that. But in the grand scheme of things, that location data is also on your mobile phone which effecitvely doubles as a GPS tracker. To be honest, we're pretty much at a point now where we just have to accept that we are pawns :)
@Croi_Fiain Жыл бұрын
@@SaabUnleashedThank you for the considered reply 👍🏻
@krecikowi9 ай бұрын
What about software installed on those units? How to know if malware is not hidden?
@whoarewenow Жыл бұрын
is there any apps to add lock screen on head unit?
@Ryzza5 Жыл бұрын
Another suggestion for any car satnav is to enter a nearby but inaccurate saved home/work address.
@EKUL34 Жыл бұрын
I feel this video is directed directly at me given I asked about this topic 2 weeks ago in a comment 😅
@SaabUnleashed Жыл бұрын
Lots of people asked me about this haha
@GoaWay... Жыл бұрын
Yep, im one of the people who asked about the Google sign in. 😊
@ronnielloyd4676 Жыл бұрын
Great advice and information Stu!
@DarnGood13 ай бұрын
Thank you! Great info
@SirBrass Жыл бұрын
I just got my Atoto A6 PF and I definitely like the basic security it has. It's locked unless my phone is in range and if not, a PIN I set must be entered. Of course there's cyber concerns, but I don't have wallets or banking apps installed, except for play store. And I'm not inviting any more risk than I already have without the headunit linked.
@PiyathPamuditha4 ай бұрын
How to set it to lock if your phone is not in range? Can all android head units do this?
@CyNinjaNikka Жыл бұрын
Found your videos from doing a head search for the right screen for the right price. I figure what I’m going to do with the tablet and sound driver in eg v4a driver For a 2is Lexus what would you recommend? Have you tried the AOstr as a brand
@paulgoodchild3482 Жыл бұрын
Interesting, if you connect your phone to the head unit, assuming your phone is logged in to your main google account is there a risk with that? I'm thinking about an Atoto for Android Auto
@SaabUnleashed Жыл бұрын
No, there's no risk in that. You phone protects all data
@quincynufc Жыл бұрын
@@SaabUnleashedSimilar question: I’m thinking about getting an AI box which also provides wireless CarPlay (my car is wired only). Is there any security risk in connecting my phone to CarPlay via the AI box? I’m thinking in terms of the box having been produced by some random manufacturer / having been tampered with during shipping as you describe in the video. Thanks.
@DTADKT10 ай бұрын
@@SaabUnleashed these would be the same case for the add-on units that plugs into the OEM head units and provide Apple Carplay to the car OEM screen right? For example: Grom VLINE or CARabc wireless carplay adapter? It's just a remote access from your phone and your phone would protect all the data, don't need to worry about a security risk? Thanks
@D1ndo5 ай бұрын
@@SaabUnleashed That's just blatantly false. The Chinese brand head unit may be compromised, or some component along the supply chain. It may be loaded with a 0day that executes as soon as you plug your phone in with a USB cable. BadUSB anyone? There are unpatchable flaws in USB. Also it might not even be a 0day (those are expensive), rather the chinese head unit may rely on the fact that many people are still using EOLed android smartphones with unpatched security holes.... TLDR, I'd never buy a chinese no name head unit. Also, never connect random USB devices to your PC or phone, and do not use public USB ports to charge your phone without extra protections to avoid juice jacking.
@tstrandv1232 ай бұрын
Is it safe to log into own spotify account and other apps as well?
@Thereviewerman510 ай бұрын
Such a great video. Thank you.
@Necrotic99 Жыл бұрын
Have you used a secondary account but linked to your main account as a family member? I am trying to figure out if this is how I can share apps and such without compromising my main account.
@marko117013 ай бұрын
Great question. Thinking about doing the same. Is it safe to do so?
@billfollette8697 Жыл бұрын
Thanks for the info stu
@R3B3LMD3 ай бұрын
Is idatalink Maestro compatible with any android unit?
@carlb86 Жыл бұрын
One correction. Chrome passwords are encrypted to a keyring.
@robinramos1407 Жыл бұрын
I'm looking to upgrade my headunit from stock in my saab 9-3 vector sc biopower 2008. Honestly the only functions I'm interested in is wireless android auto/apple carplay.`Doubt I will install rearview camera or other addons like that. And the HU need to be relatively fast to boot up from start. Would ya'll still recommend going a android headunit over linux based one from "legacy brands" considering what functions I'm mainly interested in?
@ricardoharewood775 Жыл бұрын
Remember to remove your google account whenever your car goes in for service, detailing etc.
@zhodge0 Жыл бұрын
Thanks for the info
@9josealfonso263 Жыл бұрын
Is a TS 10 android head unit any good? .thanks
@georgepatrick4135 Жыл бұрын
I am in the USA and I am looing for a android unit 2008 Toyota Highlander I am looking at the EKIY T8 8G 256G I want to spend around $300.00 US what Android unit do you recommend?
@RC-ic1co10 ай бұрын
Honest, but maybe dumb question: If an aftermarket headunit offers Apple Carplay and/or Android Auto and I use this feature with my smartphone - would that theoretically open attack vectors of the headunit towards my phone? (Or is Apple Carplay/Android Auto more of a pass-through functionality, where I don't really need to think about such?) Because I was thinking: If I was e.g. just buying an aftermarket headunit to use Apple Carplay/Android Auto, that wouldn't even provide my phone's internet connection to the headunit itself, right?
@SaabUnleashed10 ай бұрын
Carplay and Android auto are just apps streaming from the phone, there is no risk with them, but they're just very limited and obviously require a phone
@vbmdsm Жыл бұрын
That's what I've done for my Android TV - created a specific Google account just for the TV...
@Yeh-Feng Жыл бұрын
Hi, thanks for reviewing Joying head unit, and I have got one myself. But upon running antivirus in the brand new android system, it gave me several malware warnings. I contacted the customer support, and he told me he did not understand antivirus warnings, and the system did not need antivirus. Should I remove the files of malware warnings? I don't know how it will affect the system.
@SaabUnleashed Жыл бұрын
It depends what the malware software is flagging up. Android head units are different from phones / tablets and have several control features that might be considered malware by some software. What are you using to scan?
@Yeh-Feng Жыл бұрын
@@SaabUnleashed I used Avast Security and it came up with 5 files contain malicious code: "SubServer, Launcher4, and Launcher3 *3" there were news about millions of pre-infected android devices with malware.
@spec1923 Жыл бұрын
Can you do a review of maXpeedingrods unit? Price seems reasonable and quality seems exceptional.
@SaabUnleashed Жыл бұрын
I'll see what I can do
@spec1923 Жыл бұрын
@@SaabUnleashed Thank you. Looking at Xtrons also. I want a volume knob because the vehicle does not have steering wheel controls, so I feel it is important. Thanks again.
@nicd54399 ай бұрын
If you only mirror phone. Would there be security issues? Or is information bi-directional? Malware could be transferred from head unit to phone via wireless connection or hard connection.
@SaabUnleashed9 ай бұрын
Streaming services, such as screen mirroring, android auto and apple Carplay do not share account data with the head unit. Screen mirroring is very outdated these days.
@nicd54399 ай бұрын
I suppose what I’m getting at. Can malware or the like be transmitted to phone via mirror link Bluetooth WiFi usb etc… you mentioned unsealed packages could have 3rd party malware. Different category. Remember when vw was cheating emissions only when plugged into obd2 at smog station? Apparently onboard system can transfer data bi directionally. I wonder if the bigger companies will ever offer “component” style head units. Such as mixing and matching universal screens to what ever chassis you like. For now it appears to be proprietary to that specific model
@tabous26 күн бұрын
the bigger problem with Android devices isn't the security per se. It's more the fact that many are already infected and used by bad players as part of ddos attacks, if connected to the internet that is.
@bartoszriАй бұрын
second account but what about some functionality like emails?
@SaabUnleashedАй бұрын
The question is, why do you want emails on your car head unit? Set up a forward if this is required
@bartoszriАй бұрын
@@SaabUnleashed or change password immedlty after decice stollen .
@SmilodoOon Жыл бұрын
the atoto has an option to lock it
@JUSTAGUY93510 ай бұрын
Quick question, is it save to use android auto and apple carplay on stereos that have the feature?
@SaabUnleashed10 ай бұрын
I should have answered this in the video. Android Auto and Carplay do not share any sensitive data, they're providing remote access to the apps installed on your phone.
@JUSTAGUY93510 ай бұрын
@@SaabUnleashed thank you for the info! Ive been going through your videos (which are great btw) and trying to see if there's any big screen with a physical volume knob. hopefully i find "the one"
@jacobsmith30109 ай бұрын
@@SaabUnleashedso would that mean it’s even safer than using a second google account? I’d imagine, as a layperson, that using a second google account is only securing your accounts because it’s not directly related to any other account you own. But if you wanted to listen to music through Spotify, you’d need to log in directly to the head unit thus subjecting the account to potential nefarious actors - is that correct? Sorry to the person who’s comment I’ve hijacked lol
@SaabUnleashed9 ай бұрын
@@jacobsmith3010 Apple CarPlay and Android Auto are safer by default simply because you are keeping any data on your phone, and not on the secondary device (head unit). Your Spotify account is not really sensitive data (unless you use the same password for everything). And I want to be clear that it is highly unlikely that you will be subject to anything malicious. For such a thing to happen, there would need to be tracking / keylogging software on your head unit and that is simply not going to be put there by any business who want to retain the respect of their brand
@krecikowi9 ай бұрын
@@SaabUnleasheddo you mean those respectful Chinise buisenesses?
@iainansell59303 ай бұрын
what if you just plug your phone in and use android auto from your phone?
@ChrisBeenRaw5 ай бұрын
Google provides the option to secure your device in which it locks it with a passcode and also signs you out of it. From there you can track it. You can also factory reset it if necessary. My head unit shows as "trinket" lol.
@JWard2 Жыл бұрын
Yea, throwaway account is what I do
@Jaspa42 Жыл бұрын
You beat me to the throwaway account comment ;)
@TechGorilla. Жыл бұрын
also i get a alert on my phone if someone is trying to get into my account saying do you allow this change say no then google locks account till you login your self from a device that google know like your phone in your hand stu you are wrong about this
@SaabUnleashed Жыл бұрын
Again, not wrong. If your account was compromised, yes you'd recieve notification of new device. But what if you're driving or at work or otherwise unable to read messages? That person already has access and is having fun on your account until you revoke his access. The only exception to this is if you have two factor authentication activated
@SakakiDash Жыл бұрын
@@SaabUnleashed no they don't you need to authorize the new device.
@SaabUnleashed Жыл бұрын
@@SakakiDash do you see the 30 Android head units behind me in this video?
@toastranger7210 ай бұрын
I'm also concerned with spy wear built into the unit. You connect your phone to use android or car play, and they got everything. Same goes for connecting it to home wifi to set it up.
@SaabUnleashed10 ай бұрын
Carplay and Android auto do not share data with the head unit. It's just a streaming function
@lilmario03 ай бұрын
Wait... My passwords in google chrome arent encrypted? Wtf.
@ghost76211 ай бұрын
What about reloading them with GrapheneOS?
@bolm-us6yb10 ай бұрын
GrapheneOS does not support anything other than Google Pixel phones, and it probably never will. And as far as I know there aren't even custom ROMs. Even if there was someone to port over a custom ROM for a specific head unit who would make sure that they don't put anything malicous in it? This is a bit far stretched but if they did put something malicous on it then you wouldn't be able to do anything about it.
@akira5982 Жыл бұрын
& this is why we cant have nice things 😮💨
@Oette Жыл бұрын
Can I use an alternative account on the headunit and then use Android Auto and have access to KZbin premium from my main account?
@SaabUnleashed Жыл бұрын
Yes, and Android Auto is irrelevant from this video as you are signed in using your phone not the head unit
@g_unit6773 Жыл бұрын
💯 AGREE.....I've been doing this for a few years now and no problems
@daphoenixto Жыл бұрын
What about those that aren't on the Alphabet Big Brother Control grid and drive a Saab 9-7X? this is my problem I don't use Windows or Google I use Linux and FOSS
@SaabUnleashed Жыл бұрын
You can side load apps if you don't want to sign in to Google
@SaabUnleashed Жыл бұрын
Also, awesome car
@stevesalvatore Жыл бұрын
That's why I have about a million Gmail accounts 😂.
@shLowKey Жыл бұрын
I created a throwaway account today to setup my Android head unit. Just one issue, I use KZbin music to play music and my original account has KZbin premium 😂 so I just use Android auto🤭
@FreakyBeanie11 ай бұрын
Same with me 😮
@androidcarnavi6144 Жыл бұрын
Hello, boss. I am a Chinese Android screen manufacturer. Source factory. I watched your videos. You're a professional. I have a team working on Audi, Porsche. Land Rover Jaguar android screen development and sales, so we can carry out more in-depth communication and cooperation, price and service advantage!! Look forward to cooperating with you
@ultraviesonic Жыл бұрын
The future is quite scary with ai and quantum computing. Pretty much no password will be safe, not even google.😢
@BenRitchie Жыл бұрын
I guess CarPlay isn't a threat because it's just mirroring your phone?
@SaabUnleashed Жыл бұрын
Correct
@andrewchristiansen83119 ай бұрын
I used my junk email google account to download everything & dealt with resubscribing to what I like on YT. I wont do any shopping/cash app & the wifi network it connects to at home is a VLAN wireless guest network. My phone only uses that guest network too for wifi in case it sniffs out wifi credentials. Being as I use my hotspot too for the head unit. My car is a 17 y.o Toyota Camry so nobody will steal it.
@jaromor8808 Жыл бұрын
Does anyone please have experience with running a head unit outside of a car? Mine does work when connected in car, but I would like to be able to boot the head unit on my desk (so I can try to figure out why the mic is so quiet.) I connected black GND and yellow Battery wires, no luck. Some people also connect the red ACC wire, but on my head unit the red wire does not lead from the quad-lock port to the head unit, but rather from the head unit to the physical controls of the A/C, which is a separate piece of the product. (My head unit is UNISOC UIS7862A 4G LTE QLED, version M700S, by Mekede.)
@SaabUnleashed Жыл бұрын
There are three wires required to power a head unit. Ground (black) , permanent live (yellow) and ignition live (red). It's the ignition live that actually controls the power state, so you need to find that.
@jaromor8808 Жыл бұрын
Thank you sir, I will try to figure out the red wire or why it's not where it should be
@samle8260 Жыл бұрын
hello im from denmark,i juzt got a 9-5 with navi, and want to put all new audio in my car, new speakers,new amplifiers,and android head unit,but its hard to find the wiring harness i need, can u help me to fnd out what i need,to go auround the factury install. its a 9-5 from 06 and denso navi..
@JRPW Жыл бұрын
Make a 2nd Google account!
@Ali-jabbar11 ай бұрын
The radio reception for this is very bad, even the DSP is bad across all android head unit due to limited DAC resolution? Don't recommend it
@TechGorilla. Жыл бұрын
stu you are wrong!!! google has the very best security anyone try to get into your account i get notified also if my car got stolen i can't reformat the radio from my phone 100% wrong stu
@SaabUnleashed Жыл бұрын
I am not wrong. The warnings you are referring to are based on someone accessing your account with a new device. If they have access to the head unit, either via theft or by backdoor access whilst it is online (because no security updates) you'll be none the wiser. But yes, there are available options if you are aware
@donttasemebroseph Жыл бұрын
Any quality Android head units with 5 Channel digital out that you don't have to sign into? It's easy enough to use F Droid or Aurora to get FOSS apps on an Android device. Honestly I'd just like to have a nice device that will screen mirror my android phone and integrate with aftermarket amps and speakers. Easier said than done apparently
@SaabUnleashed Жыл бұрын
Screen mirroring is really counter productive if you buy an android head unit. Regarding logging in, you don't need to, but you should
@donttasemebroseph Жыл бұрын
@@SaabUnleashed been doing a lot of reading and I agree with you. Was trying to pull the trigger and buy the navifly m6pro but I can't make payment on aliexpress without giving every shred of my personal information to include pictures of my driver's license to them. Anybody else having this problem? Aliexpress the only place to buy a new navifly M6?
@SaabUnleashed Жыл бұрын
@@donttasemebroseph can't say I remember ever having to supply them with photo ID