Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos? (cnbc.com) 23
CNBC reports:
The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added.
In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...
While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.
In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...
While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.
Hmmm.... (Score:5, Insightful)
Are there security vulnerabilities in a computer that allows the remote access and reprogramming in a car that can see(video, radar...), hear(audio), remote-start, and drive(lane keeping, cruise control, automatic braking, summon, full self-drive)?
You bet your fucking ass there are. It's been proven. Repeatedly.
Re: (Score:3)
Yes (Score:1)
Next stupid question?
Yes, of course! (Score:2)
By definition of "automotive e-tech".
Obviously, yes. (Score:4, Informative)
Here is what they have to say about this in 2025. Ten Years After the Jeep Hack: A Retrospective on Automotive Cybersecurity [usenix.org]
Can't wait (Score:1)
...until some jokester bricks all the cars and even damages them permanently.
How we will laugh.
Re: (Score:2)
Disabling connectivity in hardware (Score:2)
Re:Disabling connectivity in hardware (Score:4, Interesting)
Do you have a resource explaining how to do this, or is the idea to have everyone disassemble, reverse-engineer, then re-assemble each vehicle they purchase?
Re: (Score:2)
What is being suggest is not a novel idea. It's trivial to find the information for just about any modern vehicle simp[ly by searching for it.
Just Red Team the heck out of it (Score:2)
Re: (Score:2)
I think you're quite optimistic. I'd go with "Security can be vastly strengthened", but even BSD has had bugs.
Re: Just Red Team the heck out of it (Score:3)
Re: (Score:3)
or just stop checking for subscription to get the ac to work?
what is even the necessity for any remote control of vehicles other than maintenance that could be performed at (user's) explicit request? i only see greed and control. weird reason to open a huge can of security worms you then would have to "hire competent people whose job it is to care about security" for ...
101 of "competent security": avoid unnecessary risks.
Re: Just Red Team the heck out of it (Score:2)
Re: (Score:2)
I'd also be OK with upgrades via USB. Let me download the update from the manufacturer's website and install (or not) at my leisure.
Re: (Score:2)
Security has to be a main design requirement from the beginning. If your software engineers don't know how to write secure code, then they won't write secure code.
For a compelling scenario (Score:2)
Valasek's friend (Score:1)
Charlie Miller is perhaps best known as being Chris Valasek’s friend.
Ha ha! Yeah, right.
Is Betteridge law always valid? (Score:1)
Facts Only
* Analysts suggest the automotive industry's use of over-the-air technology makes it more susceptible to cyberattacks.
* Gabriel Lim noted the potential for a foreign actor to sabotage vehicle controls as a national security concern.
* The American Enterprise Institute warned that safeguarding the automotive sector limits foreign governments' espionage capabilities.
* Norwegian bus company Ruter tested two buses and found potential risks linked to OTA technology.
* Testing revealed access to the control system for battery and power supply via mobile network using a Romanian SIM card.
* The investigation sparked investigations by the U.K. and Denmark.
* The investigations involved buses made by the Chinese firm Yutong.
* Systems security professors noted that OTA technology affects other sectors including maritime, rail, aerospace, industrial machinery, and robotics.
Executive Summary
Full Take
Sentinel — Human
The core factual material appears to stem from legitimate reporting, but the inclusion of heavily scored, informal, and argumentative text indicates significant human intervention and annotation layered onto the source.
