HomeinetCar hacking How can we protect ourselves

Car hacking How can we protect ourselves

Is it time to worry about car hacking? According to Symantec, stories about vulnerabilities in car software security are becoming more and more common. Should drivers be concerned and how can they protect themselves?Car hacking Car hacking

Symantec announced in its latest white paper, Building Comprehensive Security into Cars, that the increasing frequency with which relevant information has been reproduced recently has brought the issue of vehicle cybersecurity to the forefront, as various researchers reveal a series of vulnerabilities in new car models.

The issue of vehicle cybersecurity, as the increasing frequency with which relevant information has been reproduced recently, brings to the fore.

These incidents reflect the fact that a growing number of cars can now be included in the so-called Internet of Things (IoT), since they have their own computers, software, and connectivity. And while such a development allows car owners to benefit from a range of new technologies, it also means that their vehicles are increasingly exposed to the same kinds of electronic threats that many other connected devices face. The question inevitably arises whether it is time to start worrying about car hacking.

The revelation of sensitive points

The latest wave of discussion was sparked by news that certain Jeep Cherokee models were vulnerable to remote cyberattacks. Researchers Charlie Miller and Chris Valasek demonstrated a simulated attack, during which they were able to tamper with the car's transmission and braking systems, while also gaining control of a number of functions such as the air conditioning, center display, radio, and windshield wipers.car hacking Car hacking Car hacking Car hacking Car hacking Car hacking Car hacking Car hacking Car hacking Car hacking Car hacking Car hacking

The results of the attack were attributed to a series of vulnerabilities and weaknesses in the vehicle, several of which are due to Uconnect, the Internet connectivity system featured in many Fiat Chrysler automobile models, including the Jeep Cherokee. The revelation prompted Fiat Automobiles Chrysler to recall 1.4 million vehicles, despite the company stressing that there had been no actual hacking incidents on any of its vehicles.

A few days later, information emerged that vehicles using General Motors’ (GM) OnStar RemoteLink system were vulnerable to attacks that would allow hackers to locate the vehicle and unlock its control system. The demonstration
of such a virtual attack was made by well-known security researcher and hacker, Sami Kamkar, who concluded that would-be “intruders” would be able to trick the owner of such a vehicle, connecting it to a different wireless pseudo-network, to ultimately take control of the OnStar RemoteLink Mobile Application.

Kamkar indicated that the vulnerability is not in any specific GM vehicle, but in the application that allows owners to locate and unlock their vehicle. The researcher concluded that the application does not properly check the security certificate that should ensure that the owner's phone communicates with the OnStar server only. GM has said that the problem has now been fixed.

Tesla came into the spotlight after other researchers discovered six vulnerabilities in the company's Model S that could potentially allow a hacker to take control of the vehicle, compromising its security.
However, they clarified that attacks on a Tesla vehicle would be difficult to carry out if the would-be attacker did not have physical access to the car. However, once someone gained physical access to the vehicle, even once, they could then influence it remotely.

The “attack” allowed them to manipulate the speedometer to show the wrong speed, open and close the windows, lock and unlock the car, and flash the engine. Tesla announced that it has already resolved all related issues.

Finally, another group of security researchers from the University of California, San Diego, announced that they had discovered some more vulnerabilities to possible hacking. The team announced that it would be possible to compromise thousands of vehicles by hacking into tracking devices used mainly by insurance companies and fleet management applications to monitor a vehicle's location, speed and driving behavior.

These devices could potentially be compromised by sending a specially crafted SMS to the tracking unit. Once the device is compromised, hackers can send commands to the car's CAN bus, an internal network that controls individual vehicle systems. This could potentially allow them to affect many functions, from the windshield wipers to the car's braking system.

Should drivers be worried?

As the automotive industry integrates new technologies into cars, Symantec believes that malicious attacks like the ones above are likely to increase. To date, car hacking incidents have been limited to proving the feasibility of an attack and have been carried out by security researchers. However, as technologies proliferate, malicious attacks cannot be ruled out.

Attacks of this kind can be classified into three broad categories:

• More dangerous are “ over-the-air ” attacks , when “intruders” attempt to penetrate a vehicle’s systems from a remote location. Such attacks require extensive efforts and deep knowledge of the vehicle and its software. • Physical attacks, where the hacker must have physical access to the vehicle, are usually easier to implement. Many vehicles have inadequate protection on the CAN bus and the Electronic Control Units (ECUs) connected to it. To carry out such an attack, the attacker must have physical access to the vehicle, with the risk of being caught. • Attacks via mobile applications and support tools that allow remote vehicle control functions are also possible. Fortunately, most applications and tools can be easily fixed without the need to upgrade the vehicle’s software.

While such attacks cannot be ruled out in the future, drivers should not worry, since it is known that the motivations of cybercrime are mainly financial, so car hacking will probably remain a theoretical activity until methods are discovered to "cash on" the attacks.

Car owners who are concerned about security issues can, however, take some steps to reduce the likelihood of an attack.

These include:

• Regular software updates, which patch the system, correcting security problems.
• Particular attention when the vehicle is connected to diagnostic or telematics platforms, as these often open the door for “intruders” to enter the CAN bus.
• Avoid connecting untrusted devices to the vehicle’s information and entertainment systems, such as USB sticks, phones or media players. Also, if the car has an Internet connection, connecting to untrusted networks should be avoided.

The full white paper Building Comprehensive Security into Cars by Symantec can be found at https://www.symantec.com/content/en/us/enterprise/other_resources/building-security-into-cars-iot_en-us.pdf

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS