Bimmerpost
3
/
4 Series
BMW Garage BMW Meets Register Today's Posts
Technical Topics B58 6-Cylinder Turbo Engine / Drivetrain / Exhaust Modifications Mission Performance Presenting: World's First '21 DME Unlock paired with new Platform

Closed Thread
 
Thread Tools Search this Thread
      04-07-2022, 12:36 PM   #331
Banana Clipper
Jewel Runner
Banana Clipper's Avatar
United_States
331
Rep
911
Posts

Drives: G01///G20///I20
Join Date: Dec 2015
Location: Bay Area

iTrader: (2)

Quote:
Originally Posted by Jerrytarg6_m340 View Post
Waiting on them to make a decision on keeping the m340 or going into g80. I don't get why femto don't capitalize and team up with whomever and release it in the states especially when MP dragging there feet. I'm all for waiting on MP BUT 2 years. I feel like there losing business day by day. Idk just frustrated
Get the G80. G80 + DP + Intake + JB4 = 10's and tbh theyre not THAT much more than an M340i. I think apples to apples a G80 confirmed the same as my M340i is about 10k more
__________________

www.BHANANA.com
2009 335i - SOLD
2021 M340i - GONE
2024 iX - Yea, she fast
Appreciate 0
      04-07-2022, 08:16 PM   #332
Vmaxx
First Lieutenant
272
Rep
332
Posts

Drives: 2021 M340i xDrive
Join Date: Jun 2020
Location: Texas

iTrader: (0)

Quote:
Originally Posted by Banana Clipper View Post
Get the G80. G80 + DP + Intake + JB4 = 10's and tbh theyre not THAT much more than an M340i. I think apples to apples a G80 confirmed the same as my M340i is about 10k more
It’s more like 20k more. Plus you could also go M340i + DP + intake + Pure turbo + JB4 = 10s.
Appreciate 0
      04-17-2022, 02:27 AM   #333
Justagoodguy
Private
59
Rep
60
Posts

Drives: M340i Xdrive
Join Date: Oct 2021
Location: Kyiv

iTrader: (0)

Any updates ? Maybe someone went to them last week and knows at least newest info?
I dont wanna send DME to fucking russia after all the shit they've done in Ukraine.
Appreciate 0
      04-17-2022, 08:34 AM   #334
Scottycs
Banned
United_States
54
Rep
591
Posts

Drives: 09 335i
Join Date: Oct 2009
Location: Raleigh, NC

iTrader: (6)

Mission still isn't doing shit.

Secondly, I don't think that FEMTO attacked Ukraine....

Last edited by Scottycs; 04-19-2022 at 10:19 AM..
Appreciate 1
QZS589.00
      04-17-2022, 09:41 AM   #335
bm5bullit
Captain
bm5bullit's Avatar
United_States
239
Rep
978
Posts

Drives: 2021 BMW M340i
Join Date: Jun 2009
Location: Texas

iTrader: (0)

Front End

I gave up my 2021 M4 because I waited and waited to see if anybody could come up with an answer for the "catfish" front end on the car and sold it for my M340i. Not exactly the same car but the looks are more in line with the traditional BMW look.
__________________
2021 M340i
2020 X3 M40i - her car
2019 M5, AW, DP's, MSR CAI, BM3, SOLD
2020 Chev. ZR2 Bison truck, Daily Driver
Appreciate 0
      04-17-2022, 10:09 AM   #336
xnick101
Captain
651
Rep
818
Posts

Drives: 2021 BMW X3 M
Join Date: Oct 2019
Location: Florida

iTrader: (0)

Garage List
2020 BMW M340i  [0.00]
Quote:
Originally Posted by Scottycs View Post
Mission still isn't doing shit.

Secondly, I don't think the FEMTO attacked Ukraine....
To add to that, FEMTO is now located in Finland and the turn around time is faster now.
__________________
2014 BMW 335i M-Sport - SOLD
2020 BMW M340i - SOLD
2021 BMW X3M
Appreciate 0
      04-17-2022, 10:10 AM   #337
Justagoodguy
Private
59
Rep
60
Posts

Drives: M340i Xdrive
Join Date: Oct 2021
Location: Kyiv

iTrader: (0)

Quote:
Originally Posted by Scottycs View Post
Mission still isn't doing shit.

Secondly, I don't think the FEMTO attacked Ukraine....
Dude, femto pays taxes to russia, which contributes to the murder of innocent citizens. An fucking femto dont public any fucking post with a condemnation of the war.
You know, when you come to Ukraine and you hear the siren that warns of an air strike, you see bombed out houses and dead people in the street, you can well understand the hatred of all things russian.
After the third shelling of my city, I hated those bastards and want nothing to do with a country that kills civilians by the thousands.
That is why I am waiting for a decision from femtoevo after the war.
Btw, you still might not understand me, though.
Appreciate 3
      04-17-2022, 03:56 PM   #338
Vmaxx
First Lieutenant
272
Rep
332
Posts

Drives: 2021 M340i xDrive
Join Date: Jun 2020
Location: Texas

iTrader: (0)

Quote:
Originally Posted by xnick101 View Post
To add to that, FEMTO is now located in Finland and the turn around time is faster now.
They just have a remote location in Finland , they are still based in Russia.
Appreciate 1
xnick101650.50
      04-18-2022, 06:03 PM   #339
GD1981
Lieutenant
435
Rep
524
Posts

Drives: 2021 BMW M340i
Join Date: Sep 2015
Location: New Jersey

iTrader: (0)

Aside from the war aspect of it, I’m just apprehensive to ship out my DME overseas, period.
MP sucks btw.
Appreciate 1
      04-19-2022, 10:24 AM   #340
Scottycs
Banned
United_States
54
Rep
591
Posts

Drives: 09 335i
Join Date: Oct 2009
Location: Raleigh, NC

iTrader: (6)

Believing all russians support the war is ludicrous... but way to place judgement on 150+ million people. What is happening is ludicrous, but the people in Russia are NOT in control.

Joe Biden is an idiot, but that doesn't mean every US citizen is an idiot.

Quote:
Originally Posted by Youonlyliveonce View Post
Dude, femto pays taxes to russia, which contributes to the murder of innocent citizens. An fucking femto dont public any fucking post with a condemnation of the war.
You know, when you come to Ukraine and you hear the siren that warns of an air strike, you see bombed out houses and dead people in the street, you can well understand the hatred of all things russian.
After the third shelling of my city, I hated those bastards and want nothing to do with a country that kills civilians by the thousands.
That is why I am waiting for a decision from femtoevo after the war.
Btw, you still might not understand me, though.
Appreciate 0
      04-19-2022, 10:56 AM   #341
bese60
Lieutenant
232
Rep
519
Posts

Drives: 2021 M340i
Join Date: May 2018
Location: North Jersey

iTrader: (0)

Quote:
Originally Posted by Youonlyliveonce View Post
Dude, femto pays taxes to russia, which contributes to the murder of innocent citizens. An fucking femto dont public any fucking post with a condemnation of the war.
You know, when you come to Ukraine and you hear the siren that warns of an air strike, you see bombed out houses and dead people in the street, you can well understand the hatred of all things russian.
After the third shelling of my city, I hated those bastards and want nothing to do with a country that kills civilians by the thousands.
That is why I am waiting for a decision from femtoevo after the war.
Btw, you still might not understand me, though.
BMW uses Uyguir muslims in China.... yet to see a protest. We all eat the shit the media tells us. not to take away from what is going on but yeah. this is the life we live
Appreciate 1
      04-19-2022, 02:07 PM   #342
00dyb58
Private
77
Rep
80
Posts

Drives: 2022 BMW M340i
Join Date: Feb 2022
Location: NY

iTrader: (0)

Quote:
Originally Posted by MissionPerformance View Post
With that that being said, we have learned our lesson and will not be making this unlock available to public until either one of these 3 things happen:

1) We are able to fully secure the unlock process against data-loggers so no user can log traffic and reverse engineer our process. (Also applies to BMW engineers as that is how the tuning "locks" are created by BMW)
2) Any other major company puts in the hard work and unlocks these 2021 DMEs over OBD2 port with no need to Bench Flash.
3) You, the end users, group up together and force every public tuning company to sign a non compete agreement for the 06/2020+ DMEs. Yeah I know, that's a wishful thinking but worth a try.
What about doing the opposite of #3? Have every customer sign a non-compete? If you can control who uses the software, you can control who signs the agreement. You can accomplish this by requiring an identity and tie it to something they have, like the car or mfa device (NFC, phone, etc).

Account and Car setup
  • Customer signs up creating a username and password
  • Customer associates their Identity to the VIN of the car
  • Customer signs NDA/Non-Compete
  • Customer signs off on TOS

Security Controls

Customer will require multiple factors
  • What they have: The car sending VIN via ODB
  • What they have: NFC device and/or phone tied to a SAML 2.0 Identity controlled by Mission Performance
  • What they know: Username & Password tied to an Identity provider

Authentication workflow

Software will only deploy it's payload if the following controls are met
  • ODB transmits known VIN to MP software
  • MP Software successfully authenticates known VIN
  • Software sends a SAML 2.0 response to Mission Performance's IDP (Azure, Okta, etc)
  • User either has NFC device, or second factor on phone
  • Software sends it's payload after multiple factors are reached, data is sent unencrypted


This assumes a bit and is not easy to implement. Lots of service providers have this in place for their services already. If you can crack the DME, implementing an industry standard SAML 2.0 compliant authentication mechanism should be doable. You can argue a bad actor can simply sign up and then ultimately capture the unencrypted traffic after signing up (to reverse engineer), but so could every public tuning company who signs a non-compete agreement. This would accomplish one of your pre-requisites. It forces your competitor to be a known customer.

EDIT: Here's a general article on implementing SAML in your applications - https://developer.okta.com/docs/guid...on/saml2/main/

Last edited by 00dyb58; 04-19-2022 at 02:21 PM..
Appreciate 0
      04-19-2022, 04:02 PM   #343
kuzdu
First Lieutenant
97
Rep
313
Posts

Drives: 21 M240i
Join Date: Dec 2020
Location: NYC

iTrader: (0)

wonder if the same encryption that was on the TCU is on the ECU. If so i assume xhp can help.
Appreciate 0
      04-20-2022, 06:37 AM   #344
Justagoodguy
Private
59
Rep
60
Posts

Drives: M340i Xdrive
Join Date: Oct 2021
Location: Kyiv

iTrader: (0)

Quote:
Originally Posted by Scottycs View Post
Believing all russians support the war is ludicrous... but way to place judgement on 150+ million people. What is happening is ludicrous, but the people in Russia are NOT in control.

Joe Biden is an idiot, but that doesn't mean every US citizen is an idiot.
Quote:
Originally Posted by bese60 View Post
BMW uses Uyguir muslims in China.... yet to see a protest. We all eat the shit the media tells us. not to take away from what is going on but yeah. this is the life we live
Dudes, there's no use arguing with you.
I don't think I'm going to continue this conversation.
The only thing I want to do is to wish that no war comes to your house (as it did to me) and that you understand what I am talking about.
Appreciate 1
      04-20-2022, 08:18 AM   #345
bfiddy8
New Member
6
Rep
7
Posts

Drives: 2021 BMW M340i
Join Date: Feb 2022
Location: USA

iTrader: (0)

Quote:
Originally Posted by 00dyb58 View Post
Quote:
Originally Posted by MissionPerformance View Post
With that that being said, we have learned our lesson and will not be making this unlock available to public until either one of these 3 things happen:

1) We are able to fully secure the unlock process against data-loggers so no user can log traffic and reverse engineer our process. (Also applies to BMW engineers as that is how the tuning "locks" are created by BMW)
2) Any other major company puts in the hard work and unlocks these 2021 DMEs over OBD2 port with no need to Bench Flash.
3) You, the end users, group up together and force every public tuning company to sign a non compete agreement for the 06/2020+ DMEs. Yeah I know, that's a wishful thinking but worth a try.
What about doing the opposite of #3? Have every customer sign a non-compete? If you can control who uses the software, you can control who signs the agreement. You can accomplish this by requiring an identity and tie it to something they have, like the car or mfa device (NFC, phone, etc).

Account and Car setup
  • Customer signs up creating a username and password
  • Customer associates their Identity to the VIN of the car
  • Customer signs NDA/Non-Compete
  • Customer signs off on TOS

Security Controls

Customer will require multiple factors
  • What they have: The car sending VIN via ODB
  • What they have: NFC device and/or phone tied to a SAML 2.0 Identity controlled by Mission Performance
  • What they know: Username & Password tied to an Identity provider

Authentication workflow

Software will only deploy it's payload if the following controls are met
  • ODB transmits known VIN to MP software
  • MP Software successfully authenticates known VIN
  • Software sends a SAML 2.0 response to Mission Performance's IDP (Azure, Okta, etc)
  • User either has NFC device, or second factor on phone
  • Software sends it's payload after multiple factors are reached, data is sent unencrypted


This assumes a bit and is not easy to implement. Lots of service providers have this in place for their services already. If you can crack the DME, implementing an industry standard SAML 2.0 compliant authentication mechanism should be doable. You can argue a bad actor can simply sign up and then ultimately capture the unencrypted traffic after signing up (to reverse engineer), but so could every public tuning company who signs a non-compete agreement. This would accomplish one of your pre-requisites. It forces your competitor to be a known customer.

EDIT: Here's a general article on implementing SAML in your applications - https://developer.okta.com/docs/guid...on/saml2/main/
I recognize another IT professional when I see one..lol

It's a great idea. But I'm not sure if MP wants to spend time to implement the solution or even spend money hire a third party to do that work.
Appreciate 2
      04-26-2022, 11:42 AM   #346
georgez949
Enlisted Member
10
Rep
45
Posts

Drives: Bmw m340i 2022
Join Date: Mar 2022
Location: Phoenix AZ

iTrader: (0)

Quote:
Originally Posted by blu_g20b58 View Post
This tune is the next Half Life 3
Next gta 6
Appreciate 0
Closed Thread

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 05:21 PM.




g20
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
1Addicts.com, BIMMERPOST.com, E90Post.com, F30Post.com, M3Post.com, ZPost.com, 5Post.com, 6Post.com, 7Post.com, XBimmers.com logo and trademark are properties of BIMMERPOST