Forgot your password?
typodupeerror
Transportation Communications Security

Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos? (cnbc.com) 54

CNBC reports: The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added.

In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...

While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.

This discussion has been archived. No new comments can be posted.

Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos?

Comments Filter:
  • Hmmm.... (Score:5, Insightful)

    by SlashbotAgent ( 6477336 ) on Sunday July 19, 2026 @07:42AM (#66246078)

    Are there security vulnerabilities in a computer that allows the remote access and reprogramming in a car that can see(video, radar...), hear(audio), remote-start, and drive(lane keeping, cruise control, automatic braking, summon, full self-drive)?

    You bet your fucking ass there are. It's been proven. Repeatedly.

    • by Teun ( 17872 )
      Don't forget GPS.
    • We're entering the exciting age of AI-powered cybersecurity attacks. I imagine it won't be too long before something like a malware worm which polymorphs to evade detection and adapts itself as new CVEs get published, able to utilize tuned edge models, shows up. Wireless IoT could mean we end up with physical "e-quarantine" zones, wherein devices keep attacking anything in radio range...

    • When has networking not increased security risks?
    • by shanen ( 462549 )

      Let's ask Michael Hastings. Oh, wait.

      Just joking. Of course it's only a joke, but it's the obvious one I was looking for when the topic came up. I'm sure Obama's deep state never would have done such an unethical thing and you'd have to be a real conspiracy nut to blame someone left over from Dubya's time.

      Oh, and I'm also sure that this is one of those problems that will just go away if we wait a bit longer. That's the other low-hanging joke I was looking for.

      Probably a PROFIT! joke hanging around somewhere

    • Now consider what happens 15 years later, when the car is still on the road, but the manufacturer is no longer offering any security patches to the car that is still connected to the internet. How many 15 year old phones or PCs still get security updates today? How hard is it to compromise an 15 year old Android device today? Now imagine that device has all the capabilities you just mentioned, including becoming a 2 ton, self targeting missile.
      • This is a great point, as well. I hadn't thought of it.

      • The most important thing to do is put a very strict firewall between the infotainment processors and screen, and thhe actual vehicle operating network (usually CANbus). You want a very small white list of messages allowed between CANbus and infotainment and very strictly for "need to know" data like fuel levels/battery life, air temperature, drivetrain cautions/alerts and cabin heating/cooling controls or status. Under no circumstances do you allow software reprogramming messages for CANbus controllers from

        • I think you're thinking cars from last century which only OTA infotainment. Today's cars OTA update all the software that performs automatic braking, ADAS or even self driving. However, even old car with only infotainment update have had serious breaches (lookup Jeep remote hack from circa 2016 which chained together a bunch of exploits to pretty much own the car, including steering, braking and accelerator).
  • Yes (Score:4, Informative)

    by gweihir ( 88907 ) on Sunday July 19, 2026 @07:51AM (#66246086)

    Next stupid question?

  • By definition of "automotive e-tech".

    • There is another “yes, of course”. The removal of older cars from the market through planned obsolescence. Like a laptop, at some point the car will stop receiving patches. This could seriously restrict the used car market of the future.
      • There is another “yes, of course”. The removal of older cars from the market through planned obsolescence. Like a laptop, at some point the car will stop receiving patches. This could seriously restrict the used car market of the future.

        Why? A car that stops receiving updates does not automatically become undriveable. It just means that the manufacturer is no longer making changes to the features of the vehicle. For a lot of people, that is a good thing. It means every time you get into the car, it will be the same as it was before.

        Cars are not cell phones.

        • by drnb ( 2434720 )
          Cars with unpatched defects will lose much value. Like an unpatched laptop.
          • I mean this in the nicest way, but I don't think that you know much about how the used car market works. Maybe for $150k+ vehicles where every last minute thing matters...but for your average family that just needs the car to run and drive, their concern about some update that may affect where a button is on the LCD screen has absolutely no meaning or value to them.

            If the car were to be stolen, it just goes to insurance and they buy another vehicle.
            • by drnb ( 2434720 )

              I mean this in the nicest way, but I don't think that you know much about how the used car market works.

              We do not currently have a used car market that requires over the air software updates. As a matter of fact of the benefits claimed of the current used car market is that these cars do not require active transmitters in order to function.

              but for your average family that just needs the car to run and drive, their concern about some update that may affect where a button is on the LCD screen has absolutely no meaning or value to them.

              The software updates we are discussing are about basic functionality.

          • Also, true defects will be handled via recalls and those can stretch back 10+ years. If something is found to be wrong with the driveline that can be fixed via software, it will get addressed via recalls, (see Ford and the fun they're having supporting older vehicles right now).
        • > Cars are not cell phones.

          They are, indeed.

        • There is another “yes, of course”. The removal of older cars from the market through planned obsolescence. Like a laptop, at some point the car will stop receiving patches. This could seriously restrict the used car market of the future.

          Why? A car that stops receiving updates does not automatically become undriveable. It just means that the manufacturer is no longer making changes to the features of the vehicle. For a lot of people, that is a good thing. It means every time you get into the car, it will be the same as it was before.

          Cars are not cell phones.

          True. Cars are much worse than cell phones in this regard.
          The tech industry has been doing this for a few decades, so we all know exactly how this is going to go:

          1. Be a car manufacturer.
          2. Use proprietary software on your products.
          3. Make sure government-regulated (air quality, fuel efficiency, battery management, safety) features are entangled with your proprietary advertising/snooping/liability-limiting software.
          4. Lobby to get the laws written so that devices aren't allowed to operate unless they have v

  • Obviously, yes. (Score:5, Informative)

    by sinij ( 911942 ) on Sunday July 19, 2026 @08:47AM (#66246132)
    Miller and Valasek remotely took over Jeep in 2015. The response to these demos was not to fix auto security, but to add what is ISP-level firewall rules.

    Here is what they have to say about this in 2025. Ten Years After the Jeep Hack: A Retrospective on Automotive Cybersecurity [usenix.org]
    • by Anonymous Coward

      The response to these demos was not to fix auto security, but to add what is ISP-level firewall rules.

      The immediate response was firewall rules at Sprint, but they did recall the vehicles and fixed the firmware issue [nhtsa.gov].

  • Can't wait (Score:2, Flamebait)

    by nospam007 ( 722110 ) *

    ...until some jokester bricks all the cars and even damages them permanently.
    How we will laugh.

  • by sinij ( 911942 ) on Sunday July 19, 2026 @08:53AM (#66246142)
    Anyone remotely tech-savvy should be disabling any remote connectivity a modern car has. This means finding the module (DCM, Starlink, On-Star, etc.) and disabling the cell modem. Especially with AI democratizing ability to attack IT systems, your connected car is one TicsTok video away from being someone else's "for the Lulz".
    • by sound+vision ( 884283 ) on Sunday July 19, 2026 @10:00AM (#66246198) Journal

      Do you have a resource explaining how to do this, or is the idea to have everyone disassemble, reverse-engineer, then re-assemble each vehicle they purchase?

      • The resource is a search engine. I assume you've heard of such a technology before.

        What is being suggest is not a novel idea. It's trivial to find the information for just about any modern vehicle simp[ly by searching for it.
      • Disconnect the cell antenna. Works for every model.

        • by sinij ( 911942 )

          Disconnect the cell antenna. Works for every model.

          Someone did research with Toyota and DCM module on doing just this. Surprisingly, if you drive close to cell tower you still get connectivity. So no, you have to disable cell modem and not just antenna.

      • by drnb ( 2434720 ) on Sunday July 19, 2026 @12:08PM (#66246364)

        Do you have a resource explaining how to do this, ...

        There are tons of you tube videos, many by real mechanics, demonstrating how to do so for popular makes and models. They tend to also test the vehicle afterwards, often finding the navigation and other features still work. That doing a blue tooth connection to your phone fixes some problems.

        There are also numerous older vehicles that were 3G cellular based that worked just fine after 3G was shut down.

        Auto makers know cellular can be bad in some areas, they can’t have cars that stop working if cellular is down.

        • by sinij ( 911942 )

          Auto makers know cellular can be bad in some areas, they canâ(TM)t have cars that stop working if cellular is down.

          They can also be pricks. For example, I read that Toyota will disable your keyfob remote start in 60 days if you disconnect DCM. This is nothing short of malice.

    • And the firmware will throw a warning 'modem fault detected, vehicle drive disabled, contact authorized service mechanic.' What else ya got?
  • Security is possible if you hire competent people whose job it is to care about security.
    • by HiThere ( 15173 )

      I think you're quite optimistic. I'd go with "Security can be vastly strengthened", but even BSD has had bugs.

    • by znrt ( 2424692 ) on Sunday July 19, 2026 @09:17AM (#66246160)

      or just stop checking for subscription to get the ac to work?

      what is even the necessity for any remote control of vehicles other than maintenance that could be performed at (user's) explicit request? i only see greed and control. weird reason to open a huge can of security worms you then would have to "hire competent people whose job it is to care about security" for ...

      101 of "competent security": avoid unnecessary risks.

      • Remote control should not be a thing. Over the air upgrades should. In this age, it shouldn't take a trip to the garage for a software patch.
        • I'd also be OK with upgrades via USB. Let me download the update from the manufacturer's website and install (or not) at my leisure.

        • by drnb ( 2434720 )

          Remote control should not be a thing. Over the air upgrades should. In this age, it shouldn't take a trip to the garage for a software patch.

          Why not, a software update with your oil change?

    • Security isn't something that can be tacked on afterwards, otherwise Microsoft Windows wouldn't have vulnerabilities.

      Security has to be a main design requirement from the beginning. If your software engineers don't know how to write secure code, then they won't write secure code.
    • Security is possible

      Security is not a boolean.

    • Security is possible if you hire competent people whose job it is to care about security.

      Security via ROM. Physical replacement required. Perhaps an upgrade with your oil change.

    • No one doing the hiring is competent, even if they accidentally hire competent people.

  • See the opening episode of "Zero Day"
  • Charlie Miller is perhaps best known as being Chris Valasek’s friend.

    Ha ha! Yeah, right.

  • Betteridge's law of headlines states that any headline ending in a question mark can be answered with "no."
  • Just say "no"! (Score:4, Insightful)

    by jenningsthecat ( 1525947 ) on Sunday July 19, 2026 @02:32PM (#66246566)

    ... urging more intervention in the sector...

    Only one intervention is needed. It's the one that makes it illegal - with ruinously expensive penalties attached to any violations thereof - for ANY software or config settings in a car to be modifiable by any means other than a hard-wired connection.

    The other obvious problem here is that cars are moving towards a subscription model wherein unavailability or withdrawal of some shitty cloud service can brick an automobile, perhaps permanently. And governments are sitting there with their thumbs up their asses and allowing it to happen. This is simply not acceptable.

  • The one exception to Betteridge's law of headlines.

  • by devslash0 ( 4203435 ) on Sunday July 19, 2026 @04:40PM (#66246690)

    You've got to go to work in the morning, or drive a long distance somewhere, but your car had installed an update overnight and bricked your vehicle. This has actually happened already. From the customer's point of view operational risks like these outweigh cybersecurity risks.

FORTRAN is not a flower but a weed -- it is hardy, occasionally blooms, and grows in every computer. -- A.J. Perlis

Working...