Skip to content Skip to sidebar Skip to footer

Car security is a problem now, it’s going to get worse, and carmakers don’t much care.

Back in the day if you wanted to steal a car you’d force the window open, coat-hanger the lock, and hotwire it.

Those days are long gone now and that technique is no longer possible, but the security risk has become much worse. And by “security” I mean not just vehicle theft, but also threats like data theft, remote control and covert monitoring.

The reasons are:

a) every modern car is now entirely computer controlled, and computers are an attack vector

b) more and more convenience features exist such as push-button and remote start, apps to control, and cloud-logged data. Generally, the more convenient something is, the less secure it is or at least the greater the attack surface.

c) car companies do not have an information systems security culture or engineering focus.

d) lack of regulation forcing a focus on cyber security

For years now it has been possible to steal push-button cars by tricking the car’s ECU into thinking it’s been unlocked by a valid remote fob and given a start code. No smashed windows, no damage to the car. This has been a real problem in places like the UK, to the point where Range Rovers were uninsurable and JLR had to step in, but less so in Australia as if you steal a car here it’s more difficult to spirit it away overland to somewhere elsewhere.

There have also been remote control successes, even as far back as 2015 with a Jeep which was remotely controlled via a bug in the infotainment system. And that actually illustrates a problem; how can a bug in the infotainment system end up allowing a hacker to control a car? Poor security engineering is the short answer, the culture and focus I mentioned before, and more specifically, engineering separation of concerns. Non-critical functions need to be separated from critical functions, and clearly that didn’t happen.

Another example; a RAV4 has been stolen…via the headlights, which allowed the thieves to access the car’s CANBUS which links everything. To put it in perspective, imagine a bank had its accounts hacked by someone gaining access to their marketing website. The idea is to build layers of security around the most critical parts of a system but cars are typically designed with one weak lock on the outside, bypass that and you’ve now got access to everything.

OBD2 ports are a theft vector, because they were never designed with security in the first place, much like the Internet itself never was and over the decades we’ve slowly layered on all sorts of security measures. And now we’re seeing thieves cut holes in car bodywork to get direct access to control units.

We’ve not had the first big data automotive data breach, but you can be assured it’s on the way, now car companies have lots of data worth stealing in ways they never did a decade, even five years back, and their data security is not exactly at the level of financial services.

How big is cybercrime? It’s a trillion-dollar industry. It’s not just some random hacker in his mother’s basement, it’s well-funded research labs. Corporations, managers, CEOs, workers…except there’s not really an HR department unless you count a couple of big fellers with middle names of “the”. These organisations – not people, big, well-funded and managed organisations – are working on cybercrime, cars included. There are organisations which do nothing but produce kits and tools, for sale on the dark web. There are the actual theft rings who buy the tools and use them. There are those who deal with the stolen goods, a whole supply chain with specialists all the way. And this is all linked in with identity theft and victim targeting.

The car companies? Largely apathetic. They don’t have the security culture of software companies, and they focus on features not security because security costs money and convenience, diluting profit.

This leaves the drivers at risk. And everyone else, as if your phone is hacked that’s terrible but it’s not control of a two-tonne moving object or probably the second-most expensive object you own, one not easily replaced and also perhaps the key to you earning your money. For 4×4 owners the risk is even worse as our vehicles often have many valuable accessories and contents which are not as easily replaced as if the car was runabout, stock-standard Camry with only a drinks bottle inside.

So what can you do? Opting out of a digital society is now impractical, as well as near impossible. You can put in a fake OBD2 port or lock, but that isn’t much comfort if the criminals access your car only to be thwarted. Same for a kill switch. This is why ye olde steering wheel locks are coming back, because they’re visible and of course nothing is perfect, but having to deal with a physical lock is much harder work and more risk than an electronic-based attack.

There is a solution, and as ever, if you want someone or something to listen you need to speak their language. The only language corporations understand is revenue, so if that’s hurt, they’ll listen. So governments can start to levy huge fines on data loss and vulnerabilities, then somehow the car companies will find the money to fund security programs and none will be disadvantaged as they’ll all be in the same boat.

Unfortunately, doing the right thing in business typically puts you at a competitive disadvantage, honesty costs money. Automotive crime will never be eliminated, but we can manage what will otherwise be a nasty surge which has already begun as car crime is reaching levels not seen for years as criminals exploit the new digital world.

Show CommentsClose Comments

Leave a comment