Hacking Vehicles for a Joy Ride

Hacking Vehicles for a Joy Ride

Imagine parking your Saab 9-3 in front of your mother-in-law’s home and coming out a few hours later, only to find it gone…vanished…disappeared. This is exactly what happened to an interior designer in London. The police immediately asked to see the car’s key and weren’t surprised when they saw it was an electronic fob. Tech-savvy criminals are using key-cloning systems to gain entry to vehicles, and once in, the thief simply drives away.

Vehicle theft is big business, with approximately 6,000 cars and vans stolen using a keyless-entry hack last year in London alone and with a recent Jeep Cherokee cyberattack here in the states, hackers remotely took control of the vehicle’s steering and brakes while it was on a highway. Thank goodness it was a controlled experiment by two “white hat” hackers and not malicious, but the potential risks were clear, prompting Jeep and Fiat Chrysler to recall 1.4 million vehicles to fix the security flaw.

Japanese electronics company Hitachi predicts that by 2020, 90% of all vehicles will be connected to the Internet, so now is the time to consider some of the vulnerabilities:

Cloning electronic keys: For less than $31, people can purchase a device online that allows them to gain access to vehicle models such as BMW, Mercedes, Audi, Land Rover and Saab, plug the device into the diagnostic port and away they drive!

Solution: Add additional layers of security to the electronic key, making it more difficult to copy. Another less hi-tech recommendation: install a mechanical steering wheel lock.

Infotainment system hacking: Criminals target the Internet-connected entertainment and navigation system via a mobile phone network. Internet-connected add-ons for vehicles make them more vulnerable to cyberattacks because vehicle’s on-board telematics computers have wide-open doors, making it rather simple for tech-savvy criminals.

Solution: Firewalls and encrypted communication between entertainment systems, telematics and other critical functions is needed.

GPS spoofing: Signals that power smartphone mapping apps cam be spoofed to deliver fake or altered maps to the car’s navigation system, sending the vehicle off course. In fact, security researchers at the University of Texas were able to change the course of an $80 million super-yacht, shifting it to a potentially dangerous path, and the captain never even knew!

Solution: Human drivers can refer to paper maps, but driverless vehicles may just be out of luck since they rely heavily on satnav systems.

Image: Annopk / Shutterstock.com

About the Author

Ginger Hill is Group Social Media Manager.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3