Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos? (cnbc.com) 48
CNBC reports:
The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added.
In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...
While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.
In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...
While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.
Hmmm.... (Score:5, Insightful)
Are there security vulnerabilities in a computer that allows the remote access and reprogramming in a car that can see(video, radar...), hear(audio), remote-start, and drive(lane keeping, cruise control, automatic braking, summon, full self-drive)?
You bet your fucking ass there are. It's been proven. Repeatedly.
Re: (Score:3)
Re: (Score:1)
We're entering the exciting age of AI-powered cybersecurity attacks. I imagine it won't be too long before something like a malware worm which polymorphs to evade detection and adapts itself as new CVEs get published, able to utilize tuned edge models, shows up. Wireless IoT could mean we end up with physical "e-quarantine" zones, wherein devices keep attacking anything in radio range...
When has networking not increased security risks? (Score:2)
Re: (Score:2)
Let's ask Michael Hastings. Oh, wait.
Just joking. Of course it's only a joke, but it's the obvious one I was looking for when the topic came up. I'm sure Obama's deep state never would have done such an unethical thing and you'd have to be a real conspiracy nut to blame someone left over from Dubya's time.
Oh, and I'm also sure that this is one of those problems that will just go away if we wait a bit longer. That's the other low-hanging joke I was looking for.
Probably a PROFIT! joke hanging around somewhere
Yes (Score:2, Flamebait)
Next stupid question?
Yes, of course! (Score:2)
By definition of "automotive e-tech".
A 2nd 'Yes of Course', obsolete, unsupported (Score:2)
Re: (Score:3)
There is another “yes, of course”. The removal of older cars from the market through planned obsolescence. Like a laptop, at some point the car will stop receiving patches. This could seriously restrict the used car market of the future.
Why? A car that stops receiving updates does not automatically become undriveable. It just means that the manufacturer is no longer making changes to the features of the vehicle. For a lot of people, that is a good thing. It means every time you get into the car, it will be the same as it was before.
Cars are not cell phones.
Re: (Score:1)
Re: (Score:2)
If the car were to be stolen, it just goes to insurance and they buy another vehicle.
Re: (Score:2)
I mean this in the nicest way, but I don't think that you know much about how the used car market works.
We do not currently have a used car market that requires over the air software updates. As a matter of fact of the benefits claimed of the current used car market is that these cars do not require active transmitters in order to function.
but for your average family that just needs the car to run and drive, their concern about some update that may affect where a button is on the LCD screen has absolutely no meaning or value to them.
The software updates we are discussing are about basic functionality.
Re: (Score:2)
Re: A 2nd 'Yes of Course', obsolete, unsupported (Score:2)
> Cars are not cell phones.
They are, indeed.
Obviously, yes. (Score:5, Informative)
Here is what they have to say about this in 2025. Ten Years After the Jeep Hack: A Retrospective on Automotive Cybersecurity [usenix.org]
Can't wait (Score:2, Flamebait)
...until some jokester bricks all the cars and even damages them permanently.
How we will laugh.
Re: (Score:2)
Re: Can't wait (Score:1)
Disabling connectivity in hardware (Score:4, Informative)
Re:Disabling connectivity in hardware (Score:5, Interesting)
Do you have a resource explaining how to do this, or is the idea to have everyone disassemble, reverse-engineer, then re-assemble each vehicle they purchase?
Re: (Score:2)
What is being suggest is not a novel idea. It's trivial to find the information for just about any modern vehicle simp[ly by searching for it.
Re: (Score:2)
Disconnect the cell antenna. Works for every model.
Re: (Score:1)
Disconnect the cell antenna. Works for every model.
Someone did research with Toyota and DCM module on doing just this. Surprisingly, if you drive close to cell tower you still get connectivity. So no, you have to disable cell modem and not just antenna.
Abundant how-to's by real mechanics (Score:4, Interesting)
Do you have a resource explaining how to do this, ...
There are tons of you tube videos, many by real mechanics, demonstrating how to do so for popular makes and models. They tend to also test the vehicle afterwards, often finding the navigation and other features still work. That doing a blue tooth connection to your phone fixes some problems.
There are also numerous older vehicles that were 3G cellular based that worked just fine after 3G was shut down.
Auto makers know cellular can be bad in some areas, they can’t have cars that stop working if cellular is down.
Re: (Score:1)
Auto makers know cellular can be bad in some areas, they canâ(TM)t have cars that stop working if cellular is down.
They can also be pricks. For example, I read that Toyota will disable your keyfob remote start in 60 days if you disconnect DCM. This is nothing short of malice.
Re: (Score:2)
Just Red Team the heck out of it (Score:2)
Re: (Score:2)
I think you're quite optimistic. I'd go with "Security can be vastly strengthened", but even BSD has had bugs.
Re: Just Red Team the heck out of it (Score:3)
Re:Just Red Team the heck out of it (Score:4, Informative)
or just stop checking for subscription to get the ac to work?
what is even the necessity for any remote control of vehicles other than maintenance that could be performed at (user's) explicit request? i only see greed and control. weird reason to open a huge can of security worms you then would have to "hire competent people whose job it is to care about security" for ...
101 of "competent security": avoid unnecessary risks.
Re: Just Red Team the heck out of it (Score:1)
Re: (Score:2)
I'd also be OK with upgrades via USB. Let me download the update from the manufacturer's website and install (or not) at my leisure.
Re: (Score:2)
Remote control should not be a thing. Over the air upgrades should. In this age, it shouldn't take a trip to the garage for a software patch.
Why not, a software update with your oil change?
Re: (Score:2)
Security has to be a main design requirement from the beginning. If your software engineers don't know how to write secure code, then they won't write secure code.
Re: Just Red Team the heck out of it (Score:2)
Re: Just Red Team the heck out of it (Score:2)
Re: (Score:2)
Security is possible
Security is not a boolean.
Put the software in ROM (Score:2)
Security is possible if you hire competent people whose job it is to care about security.
Security via ROM. Physical replacement required. Perhaps an upgrade with your oil change.
Re: (Score:2)
No one doing the hiring is competent, even if they accidentally hire competent people.
For a compelling scenario (Score:2)
Valasek's friend (Score:1)
Charlie Miller is perhaps best known as being Chris Valasek’s friend.
Ha ha! Yeah, right.
Is Betteridge law always valid? (Score:1)
Just say "no"! (Score:4, Insightful)
... urging more intervention in the sector...
Only one intervention is needed. It's the one that makes it illegal - with ruinously expensive penalties attached to any violations thereof - for ANY software or config settings in a car to be modifiable by any means other than a hard-wired connection.
The other obvious problem here is that cars are moving towards a subscription model wherein unavailability or withdrawal of some shitty cloud service can brick an automobile, perhaps permanently. And governments are sitting there with their thumbs up their asses and allowing it to happen. This is simply not acceptable.
I found it! (Score:1)
The one exception to Betteridge's law of headlines.
Operational Risks Cyber Risks (Score:5, Interesting)
You've got to go to work in the morning, or drive a long distance somewhere, but your car had installed an update overnight and bricked your vehicle. This has actually happened already. From the customer's point of view operational risks like these outweigh cybersecurity risks.