When connected cars can be hacked from afar
- By Mark Rockwell
- Sep 22, 2016
The day before the Transportation Department released the first national guidelines to spur development of autonomous-vehicle technologies and ensure their safety, a group of researchers in China showed that it was possible to control an Internet-connected car from a distance.
In a Sept. 19 blog post, Keen Security Lab researchers said they were able to take over numerous functions of a Tesla Model S sedan from as far away as 12 miles. Keen is a division of the Chinese giant Tencent, one of the world's leading internet service providers.
The researchers manipulated the Tesla's controls while it was in park via a laptop computer. They locked the car's control screens, moved seats, activated turn signals and opened doors without keys. While the car was driving, they used the laptop to turn on windshield wipers, open the trunk and fold in exterior rearview mirrors. A researcher in an office building 12 miles from the test track was able to slam on the car's brakes while the vehicle was moving.
Tesla told Reuters on Sept. 20 that it patched the bugs once the researchers informed the company of the issue. Officials also said the intrusion could only be accomplished when the vehicle's onboard browser was in use and the car was within range of a compromised Wi-Fi hotspot.
Monique Lance, marketing director at Argus Cyber Security, said the automaker’s speedy response to news about the vulnerability is encouraging in light of DOT's new policy for autonomous vehicles.
The policy encourages automakers and suppliers to work together on cybersecurity and share vulnerability and threat information, she added. Argus works with major auto manufacturers on cybersecurity issues.
The hack on the Tesla "is just another in a stream of hacking events" on increasingly connected automobiles, she said, adding that the hacks are revealing issues that must be addressed.
A year ago, manufacturers were not so responsive when informed about hacks of onboard computer systems. "They were in denial," Lance said. Now most of the companies have in-house cybersecurity teams to deal with issues.
This article first appeared on FCW, a sister site to GCN.
Mark Rockwell is a senior staff writer at FCW, whose beat focuses on acquisition, the Department of Homeland Security and the Department of Energy.
Before joining FCW, Rockwell was Washington correspondent for Government Security News, where he covered all aspects of homeland security from IT to detection dogs and border security. Over the last 25 years in Washington as a reporter, editor and correspondent, he has covered an increasingly wide array of high-tech issues for publications like Communications Week, Internet Week, Fiber Optics News, tele.com magazine and Wireless Week.
Rockwell received a Jesse H. Neal Award for his work covering telecommunications issues, and is a graduate of James Madison University.
Click here for previous articles by Rockwell.
Contact him at firstname.lastname@example.org or follow him on Twitter at @MRockwell4.