Share

Car-hacking wake up call

Washington - Computer geeks already knew it was possible to hack into a car's computerized systems and potentially alter some electronic control functions.

But new research to be presented next week shows the vulnerabilities are greater and the potential for mischief worse than believed, in a wake-up call for the automobile industry.

Chris Valasek, director of security intelligence for the security firm IOActive, and Charlie Miller, security engineer for Twitter, found these vulnerabilities in cars' on-board computer, a mandatory feature on US vehicles since 1996.

They found that by accessing this device, which sits under the steering wheel, someone with a brief period of access, like a parking attendant, could hack the car and reprogram key safety features.

"We had full control of braking," Valasek told AFP in a telephone interview.

"We disengaged the brakes so if you were going slow and tried to press the brakes they wouldn't work. We could turn the headlamps on and off, honk the horn. We had control of many aspects of the automobile."

The pair, working with partial funding from the US government's Defense Advanced Research Projects Agency, also manipulated a vehicle's steering by hijacking the "park assist" feature which was designed only to move slowly in reverse.

"You would need a brief moment of physical access," Valasek said. "You could reprogram and untether from the car and the system."

While some earlier research focused on the potential to wirelessly gain control of some functions, Valasek said his project looked at overwriting the software code in the vehicles, with even more damaging consequences.

The research is to presented next week at Def Con, an annual gathering of hackers and security experts in Las Vegas.

Cybersecurity

The research is not the first to show the potential for hacking into car computer systems, which are becoming more ubiquitous as more vehicles add services connecting to the Internet or cellular phone networks, and some firms like Google are using self-driving automobiles.

A 2010 study by researchers from the University of Washington and University of California at San Diego demonstrated how an attacker could infiltrate virtually any electronic control unit (ECU) of a car and "leverage this ability to completely circumvent a broad array of safety-critical systems."

That study showed that the engine control devices initially designed for pollution reduction had been integrated into other aspects of a car's functioning and diagnostics.

And the US Department of Homeland Security issued an advisory in May warning of flaws in the wireless Bluetooth systems in some cars which could be exploited by an outsider to take control of some car functions.

Valasek said most cars on the road have a number of computers and "they all trust each other. As long as they are receiving information, they don't care who is sending it."

This highlights the need for more attention to cybersecurity in vehicle design, he said.

"We want an intelligent discussion on this," he said.

Valasek and Miller will be releasing full technical details of their research at Def Con.

"We hope people enjoy the presentation and take our tools and data and try to reproduce them and do their own research," he said.

"Although there is research on automobile security no one is releasing the data."

Valasek said there have been no real-life exploits of automobile hacking, but added that "we just don't know what could be done with this."

He said it is more complicated than hacking into a personal computer but that his latest research shows that "with a minimal number of people you can have results where you can control the car, and do things that are detrimental to safety."


We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.22
-0.3%
Rand - Pound
23.92
-0.4%
Rand - Euro
20.47
-0.4%
Rand - Aus dollar
12.32
-0.2%
Rand - Yen
0.12
-0.4%
Platinum
942.00
-0.9%
Palladium
1,010.00
-1.9%
Gold
2,382.28
+0.1%
Silver
28.28
+0.2%
Brent-ruolie
87.11
-0.2%
Top 40
66,703
-0.7%
All Share
72,759
-0.7%
Resource 10
62,979
-0.5%
Industrial 25
97,553
-0.9%
Financial 15
15,394
-0.6%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders