Urgent.News

What's breaking now, across thousands of outlets.

Tech

Worried about your car being hacked? You should be – no matter where it was made

Connected vehicles can be hacked, posing risks for safety and privacy.

Recent reports have highlighted the potential cybersecurity risks posed by connected vehicles, regardless of the manufacturer. A cybersecurity expert recently demonstrated the ease with which they could hack into a Chinese-made BYD Shark 6 hybrid ute, gaining control over various vehicle functions, including locks, lights, audio, and video.

The expert's claim that this task was "easier than they were expecting" has raised concerns about the vulnerability of Chinese-made cars, which may share data with the Chinese government.

Modern cars, whether electric, fossil-fuelled or hybrid, collect and transmit a significant amount of personal information to offshore servers, potentially accessible to foreign governments, including China. However, it's not just foreign governments that have access to this data; hackers can potentially access it as well. This applies to all connected vehicles, irrespective of their origin.

Cars have evolved into a network of computers on wheels, with separate systems connecting the vehicle to various networks and the manufacturer's online infrastructure. These systems can be vulnerable to hacking and malware. Modern cars have dozens of computers, each responsible for different functions, such as entertainment, communication, braking, steering, engine performance, sensors, and driver-assistance systems.

The cybersecurity risks for cars are multifaceted. Manufacturers must secure not only the individual vehicles but also the systems used to distribute software across entire fleets. The SIM or eSIM in the vehicle connects it to the internet and the manufacturer's systems, providing a pathway into the larger communications system. Researchers have identified weaknesses in this chain while testing Tesla Model 3s and Cybertrucks, suggesting that similar vulnerabilities may exist in other cars.

Attackers may target either the vehicle's cellular connection or the manufacturer's cloud infrastructure. Recent examples include a malware campaign targeting "head units" (which handle multimedia and sometimes car control functions) running on the Android operating system, and bypassing anti-theft protections in a Nissan Leaf using Bluetooth vulnerabilities. These attacks could pose direct physical safety risks, such as compromising steering or lights, or be used for identity theft or vehicle theft.

In Australia, there are currently no mandatory minimum cybersecurity standards specifically for vehicles. Other markets, including China and the European Union, already have such requirements. As cars become increasingly connected, it is crucial to consider not only what data leaves the vehicle but also what can enter it. If you're considering purchasing a new connected vehicle, it's essential to research the maker's approach to cybersecurity, keep the vehicle and related apps up to date, and be aware of the risks associated with using connected services.

Additionally, consider restoring a used vehicle to factory settings and take the vehicle's country of manufacture into account, although this should not be the sole factor in your decision.

Written by urgent.news from The Conversation AU's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theconversation.com →

More in Tech

Jev is a very good classifier wearing a frontier model's coat

Two years in stealth. Ex-OpenAI. Co-invented ChatGPT. That is the pitch for Jev, and the pitch is doing most of the lifting. Strip the marketing off and look at what it actually does.

  • Jev is a JSON-based classifier utilizing a frontier model's coat
  • Co-invented by an ex-OpenAI employee, Jev has been in stealth for two years
  • The model acts as a sidecar to the big LLM, handling routing and validation

More from Wednesday 23 September →