Forgot your password?
typodupeerror
Transportation Communications Security

Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos? (cnbc.com) 48

CNBC reports: The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added.

In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...

While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.

Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos?

Comments Filter:
  • Hmmm.... (Score:5, Insightful)

    by SlashbotAgent ( 6477336 ) on Sunday July 19, 2026 @07:42AM (#66246078)

    Are there security vulnerabilities in a computer that allows the remote access and reprogramming in a car that can see(video, radar...), hear(audio), remote-start, and drive(lane keeping, cruise control, automatic braking, summon, full self-drive)?

    You bet your fucking ass there are. It's been proven. Repeatedly.

    • by Teun ( 17872 )
      Don't forget GPS.
    • We're entering the exciting age of AI-powered cybersecurity attacks. I imagine it won't be too long before something like a malware worm which polymorphs to evade detection and adapts itself as new CVEs get published, able to utilize tuned edge models, shows up. Wireless IoT could mean we end up with physical "e-quarantine" zones, wherein devices keep attacking anything in radio range...

    • When has networking not increased security risks?
    • by shanen ( 462549 )

      Let's ask Michael Hastings. Oh, wait.

      Just joking. Of course it's only a joke, but it's the obvious one I was looking for when the topic came up. I'm sure Obama's deep state never would have done such an unethical thing and you'd have to be a real conspiracy nut to blame someone left over from Dubya's time.

      Oh, and I'm also sure that this is one of those problems that will just go away if we wait a bit longer. That's the other low-hanging joke I was looking for.

      Probably a PROFIT! joke hanging around somewhere

  • Yes (Score:2, Flamebait)

    by gweihir ( 88907 )

    Next stupid question?

  • By definition of "automotive e-tech".

    • There is another “yes, of course”. The removal of older cars from the market through planned obsolescence. Like a laptop, at some point the car will stop receiving patches. This could seriously restrict the used car market of the future.
      • There is another “yes, of course”. The removal of older cars from the market through planned obsolescence. Like a laptop, at some point the car will stop receiving patches. This could seriously restrict the used car market of the future.

        Why? A car that stops receiving updates does not automatically become undriveable. It just means that the manufacturer is no longer making changes to the features of the vehicle. For a lot of people, that is a good thing. It means every time you get into the car, it will be the same as it was before.

        Cars are not cell phones.

        • by drnb ( 2434720 )
          Cars with unpatched defects will lose much value. Like an unpatched laptop.
          • I mean this in the nicest way, but I don't think that you know much about how the used car market works. Maybe for $150k+ vehicles where every last minute thing matters...but for your average family that just needs the car to run and drive, their concern about some update that may affect where a button is on the LCD screen has absolutely no meaning or value to them.

            If the car were to be stolen, it just goes to insurance and they buy another vehicle.
            • by drnb ( 2434720 )

              I mean this in the nicest way, but I don't think that you know much about how the used car market works.

              We do not currently have a used car market that requires over the air software updates. As a matter of fact of the benefits claimed of the current used car market is that these cars do not require active transmitters in order to function.

              but for your average family that just needs the car to run and drive, their concern about some update that may affect where a button is on the LCD screen has absolutely no meaning or value to them.

              The software updates we are discussing are about basic functionality.

          • Also, true defects will be handled via recalls and those can stretch back 10+ years. If something is found to be wrong with the driveline that can be fixed via software, it will get addressed via recalls, (see Ford and the fun they're having supporting older vehicles right now).
        • > Cars are not cell phones.

          They are, indeed.

  • Obviously, yes. (Score:5, Informative)

    by sinij ( 911942 ) on Sunday July 19, 2026 @08:47AM (#66246132)
    Miller and Valasek remotely took over Jeep in 2015. The response to these demos was not to fix auto security, but to add what is ISP-level firewall rules.

    Here is what they have to say about this in 2025. Ten Years After the Jeep Hack: A Retrospective on Automotive Cybersecurity [usenix.org]
  • Can't wait (Score:2, Flamebait)

    by nospam007 ( 722110 ) *

    ...until some jokester bricks all the cars and even damages them permanently.
    How we will laugh.

  • by sinij ( 911942 ) on Sunday July 19, 2026 @08:53AM (#66246142)
    Anyone remotely tech-savvy should be disabling any remote connectivity a modern car has. This means finding the module (DCM, Starlink, On-Star, etc.) and disabling the cell modem. Especially with AI democratizing ability to attack IT systems, your connected car is one TicsTok video away from being someone else's "for the Lulz".
    • by sound+vision ( 884283 ) on Sunday July 19, 2026 @10:00AM (#66246198) Journal

      Do you have a resource explaining how to do this, or is the idea to have everyone disassemble, reverse-engineer, then re-assemble each vehicle they purchase?

      • The resource is a search engine. I assume you've heard of such a technology before.

        What is being suggest is not a novel idea. It's trivial to find the information for just about any modern vehicle simp[ly by searching for it.
      • Disconnect the cell antenna. Works for every model.

        • by sinij ( 911942 )

          Disconnect the cell antenna. Works for every model.

          Someone did research with Toyota and DCM module on doing just this. Surprisingly, if you drive close to cell tower you still get connectivity. So no, you have to disable cell modem and not just antenna.

      • by drnb ( 2434720 ) on Sunday July 19, 2026 @12:08PM (#66246364)

        Do you have a resource explaining how to do this, ...

        There are tons of you tube videos, many by real mechanics, demonstrating how to do so for popular makes and models. They tend to also test the vehicle afterwards, often finding the navigation and other features still work. That doing a blue tooth connection to your phone fixes some problems.

        There are also numerous older vehicles that were 3G cellular based that worked just fine after 3G was shut down.

        Auto makers know cellular can be bad in some areas, they can’t have cars that stop working if cellular is down.

        • by sinij ( 911942 )

          Auto makers know cellular can be bad in some areas, they canâ(TM)t have cars that stop working if cellular is down.

          They can also be pricks. For example, I read that Toyota will disable your keyfob remote start in 60 days if you disconnect DCM. This is nothing short of malice.

    • And the firmware will throw a warning 'modem fault detected, vehicle drive disabled, contact authorized service mechanic.' What else ya got?
  • Security is possible if you hire competent people whose job it is to care about security.
  • See the opening episode of "Zero Day"
  • Charlie Miller is perhaps best known as being Chris Valasek’s friend.

    Ha ha! Yeah, right.

  • Betteridge's law of headlines states that any headline ending in a question mark can be answered with "no."
  • Just say "no"! (Score:4, Insightful)

    by jenningsthecat ( 1525947 ) on Sunday July 19, 2026 @02:32PM (#66246566)

    ... urging more intervention in the sector...

    Only one intervention is needed. It's the one that makes it illegal - with ruinously expensive penalties attached to any violations thereof - for ANY software or config settings in a car to be modifiable by any means other than a hard-wired connection.

    The other obvious problem here is that cars are moving towards a subscription model wherein unavailability or withdrawal of some shitty cloud service can brick an automobile, perhaps permanently. And governments are sitting there with their thumbs up their asses and allowing it to happen. This is simply not acceptable.

  • The one exception to Betteridge's law of headlines.

  • by devslash0 ( 4203435 ) on Sunday July 19, 2026 @04:40PM (#66246690)

    You've got to go to work in the morning, or drive a long distance somewhere, but your car had installed an update overnight and bricked your vehicle. This has actually happened already. From the customer's point of view operational risks like these outweigh cybersecurity risks.

The party adjourned to a hot tub, yes. Fully clothed, I might add. -- IBM employee, testifying in California State Supreme Court

Working...