Skip to playerSkip to main content
  • 6 hours ago
With the press of a button, millions of cars can be hacked. Professor Aaron Schulman and team discovered a universal vulnerability installed in more than 2,000,000 cars across the US. WIRED technology journalist Andy Greenberg exposes the novel hacking technique—including just how easy it is to steal a car—and explains what you need to do to patch a hidden device you may not even know is in your vehicle.

Category

🤖
Tech
Transcript
00:00With the press of a button on this homemade Android app, I'm about to hack all of these cars.
00:11In fact, this device inside all of these vehicles makes it disturbingly easy for anyone.
00:16Carjack them, paralyze them, trigger chaotic effects like I just did, or even silently steal a car and drive it
00:22away.
00:22And the wildest part is that this hidden hackable device is installed in millions of cars across America.
00:27And about half of those vehicles, the owners have never asked for it and might have no idea it's even
00:32in there.
00:32There's another one.
00:33There's another one right there.
00:34My goodness, they're everywhere.
00:35It may well be inside your car right now.
00:38I'm Andy Greenberg.
00:39I investigate the strange, dark, and subversive sides of technology for Wired.
00:43This is Hack Lab, the hidden hackable device that lets me steal your car.
00:49To learn about this new car hacking technique, I traveled to the University of California at San Diego
00:53to meet with the security researchers who discovered it.
00:56Computer science professor Aaron Schulman and his team.
00:58Aaron.
00:59So, this is the device.
01:01This is a car alarm that is installed by dealers into cars that they sell while they're sitting on the
01:07parking lot waiting to be sold.
01:09In Southern California for years, there was a big problem with theft from dealer lots.
01:14They install it behind the dashboard.
01:16They've really mounted this thing quite deep inside of your car.
01:20They actually cut the ignition wire at the dealer, and they splice this in in the middle,
01:25and that allows them to prevent the car from starting when it's sitting on that dealer's lot.
01:29I mean, I can see this as a module with a million wires coming off of it.
01:32What does it connect into in a car?
01:34All the high security systems inside the car that are used for access.
01:38So, door locks, lights, trunk, etc.
01:40So, this is actually a security device.
01:42But what is the security issue that you found with it?
01:44All of these systems actually have the same universal key built into them.
01:49Now, the issue with that is the system can be used by an attacker to also immobilize your car.
01:56And that key is, unfortunately, on millions of alarms that have been deployed by these dealers,
02:01mostly originating in Southern California, but also now have been resold throughout the country.
02:07How did it end up in cars on the road and in people's driveways and parking lots around the country?
02:12When you're with a dealer and they're trying to negotiate the price,
02:15they'll actually say to you,
02:17there's also this alarm system.
02:18We already put it in your car.
02:20Do you want to perhaps pay for this as an upgrade?
02:23And then you can have access from your smartphone
02:26and you can control your car to unlock, lock, activate the horn from that smartphone app.
02:32And then what happens if I say no?
02:34You can, as the purchaser, say,
02:37I do not want this system in my car.
02:39They will say, okay, fine.
02:40We'll deactivate the system.
02:42And once it's deactivated, we already put it in your car with all these wires.
02:46It's quite deep in there, but it won't work anymore.
02:49Now, unfortunately, what we found in our research is,
02:51even if the system has been deactivated, it is still operating.
02:56And whenever the car is turned on,
02:58this actually wakes up and the Bluetooth radio turns on
03:01and now you can connect to it as an attacker and remotely control it.
03:05Wow, that is so insidious.
03:07This thing people didn't ask for, in fact, they actively asked not to have it in their car,
03:12is still in the guts of their vehicle, making it much less secure.
03:16That's right.
03:17So how can people find out if they have this device hidden in their car?
03:20It's really obvious, actually.
03:21Let me show you.
03:22Here's the sticker right here.
03:24If you have this sticker that says K-A-R-R, you likely are vulnerable to this attack.
03:28Yeah, that's pretty clear.
03:29And if you look down at the bottom here, under the dashboard,
03:32this little blinking light indicates that you have the system running
03:35and you have to get it patched.
03:37Last year, the UCSD team warned Acrosure Protection Group,
03:40the company that sells the car alarm device,
03:42about the hacking technique they had discovered.
03:44The company responded just this week by rolling out a security update.
03:47So if you have car installed on your vehicle,
03:49you can now download or update your car app on your phone
03:52to patch the device and protect your car.
03:54But there's no automatic software update mechanism.
03:57Car owners will need to manually install the fix
03:59or their vehicle stays vulnerable.
04:01So this is actually Suman's car.
04:03One of our students, he was the first to volunteer to have their car hacked.
04:06Did you actually pay for this?
04:08Like, do you have it active in your car?
04:10No, I did not pay for this.
04:11But as it turns out, with just a button click,
04:14I can activate it as long as it's parked just a few minutes ago.
04:17Or if the car is on and driving, right?
04:19Yes.
04:19So can you show us?
04:20Sure.
04:20So right now, I'm going to convert it from this deactivated state
04:25into an active state.
04:26So that little honk was the only sign you're going to get
04:29that your car just became vulnerable?
04:31Yes, just the honk.
04:32Now I can lock the car.
04:35Go ahead.
04:35Try to see if you can unlock it.
04:37And as it turns out, we can also unlock the car.
04:41So now you can honk the horn, for instance.
04:44And you can also turn on and off the lights.
04:48So as it turns out, we can also immobilize the car.
04:50So you can sit in, try to switch on the ignition,
04:52and it's not going to work.
04:53So why don't you go ahead and start it?
04:55Make sure it works.
05:00Now go ahead.
05:00Perfect.
05:01So yeah, try it again.
05:06Is it working, Andy?
05:07No, it's not starting.
05:09It's not starting.
05:10Yeah.
05:10Nothing.
05:11It says key not found.
05:11At this point, you would need to actually tow the car
05:15if you want to drive it again,
05:16because the person that owns it has no idea
05:19why their car won't even start anymore.
05:21So you can basically paralyze any car
05:24that's in Bluetooth range of your phone.
05:26Exactly.
05:27That seems like a very serious problem.
05:30Before we demonstrate how this hacking technique works
05:33by stealthily stealing a car from the driveway of a private home,
05:36I took a ride around La Jolla with Aaron and Ibuo,
05:39one of the researchers on his team,
05:40to get a sense of just how many cars
05:42had this secret vulnerability.
05:44We're scanning nearby signals that car alarms emit.
05:47This is the counter mode of my app,
05:50where here are all the serial numbers of car alarms nearby.
05:54So far, we've seen eight of those.
05:56Oh, there's nine.
05:56There's another one.
05:57Oh, 11?
05:57Wow, two more.
05:58Oh my goodness, they're everywhere.
05:59There's 16.
06:00Most dealers, they're all operating this car system.
06:04So essentially, almost any of those cars
06:06that we see in Southern California
06:09is going to have a car alarm in it.
06:11Based on some experiments we've done
06:13in looking at data across the country,
06:16we see that these alarms show up
06:18in every city in the United States.
06:20Let's see how many we count in this garage.
06:22The number is going up very quickly.
06:24We're already at 20.
06:24What we're counting here are active car alarm systems.
06:27It's most likely to be active at once.
06:30Because the active alarms,
06:31they stop beaconing after they parked for a while.
06:34We're 27 now.
06:35Yeah, we're 27.
06:37I just see two window stickers there.
06:39Just as you drove by,
06:40you could immobilize every vulnerable car
06:43in the whole parking garage.
06:44Yeah, that's right.
06:45We are at 37.
06:47Vulnerable cars were everywhere,
06:49all giving off the same telltale Bluetooth prefix.
06:51Aaron's team estimates
06:52that more than 2 million cars nationwide
06:54have the car system installed.
06:56They got that number by studying data from Wiggle,
06:58a crowdsourced app where users known as Wigglers
07:01compete to log Wi-Fi and Bluetooth signals
07:03they pick up with radio antenna.
07:05Aaron's team then used the serial numbers
07:06of the devices in Wiggle with the car's signature
07:08to extrapolate how many of these systems
07:10may be out there.
07:11But Wiggle also collects location data
07:14tied to all those radio signals too, right?
07:17Yes.
07:17And so does that mean
07:18that you can track someone's location
07:20based on these car alarm radio signals also?
07:24Oh yes, totally.
07:25Now the problem with that is
07:26if you get that data,
07:28the serial number does not change.
07:30So you can track where someone lives,
07:32where someone works.
07:34Somebody wouldn't even need to follow you
07:35back to your home
07:36or to where you parked the car.
07:38They could just find
07:38that same radio signature on Wiggle.
07:41As part of our research,
07:42we investigated in the Wiggle database
07:44how many cars were actually targetable.
07:48And we noticed that
07:49there are quite a lot of cars
07:51where we see them stationary.
07:53And that means likely
07:55they will be seen again and again
07:57at the same location.
07:58It could be the case
07:59that someone could use
08:01those public databases
08:02to target individuals
08:04that have that vulnerable vehicle.
08:06I mean, this is all very creepy and scary.
08:08We're now in a pretty crowded parking lot.
08:10Let's see how much the count goes up.
08:12It already goes up to 67.
08:14There's another one right there.
08:15Now we're up to 74.
08:16In any parking lot in San Diego,
08:18you're going to see
08:19dozens and dozens of these things.
08:2188, 89.
08:22Oh, we have 90 right now.
08:24I just want to note that
08:25we only drove around here
08:26for about 20 minutes.
08:27We stayed right next
08:29to the university's campus.
08:30We almost saw 100 cars
08:32that are vulnerable.
08:34That is an insane amount of cars.
08:37When you install something by default
08:38at a dealer
08:39in every car that is sold,
08:41the pervasiveness of that vulnerability
08:44is going to be unimaginable.
08:46Finding vulnerable cars is easy.
08:48And what could someone do
08:49with the power to unlock a car at will?
08:50One disturbing possibility
08:52is carjacking.
08:53Once a criminal has identified
08:55a target vehicle,
08:56they could simply unlock it
08:57while someone is driving and exposed.
08:59For demonstration purposes,
09:00a UCSD employee has volunteered
09:02to pose as our victim.
09:03All right, so let's say
09:04we want to target
09:05this vulnerable car up here.
09:06All I have to do is
09:07we pull it behind it.
09:08I'm going to activate.
09:10You heard the beep.
09:11It's active.
09:13This is a particularly scary idea
09:15of unlocked
09:16because a carjacker
09:17could remotely unlock
09:18the door at a stoplight
09:19then drag the occupant
09:20from the front seat
09:21or steal something
09:22from inside the car.
09:23As real as that
09:24carjacking threat may be,
09:26it's not at all stealthy.
09:27But if we wanted to actually
09:28steal a car
09:29without confronting the owner,
09:30all we would have to do
09:31is follow the driver home
09:32or wherever they park
09:34or find those locations
09:35in the Wiggle database
09:36and wait for a quiet moment
09:37to make our move.
09:39In just a few minutes,
09:40we'll show you
09:41how easy and stealthy
09:42stealing that car can be.
09:44So easy that even I,
09:45with no experience
09:46using Aaron's technique,
09:47could probably do it
09:48in under two minutes.
09:49But before we attempt
09:50hacking-enabled
09:51Grand Theft Auto,
09:52let me give you
09:52some quick historical context
09:54on this technique
09:55and how we got here.
09:56For over a decade,
09:57I've covered the evolution
09:58of hacking techniques
09:59that affect modern connected vehicles
10:01with digital features.
10:02That story actually begins
10:03here at the University
10:04of California, San Diego.
10:05So while I was on campus,
10:07I met with Stefan Savage,
10:08who co-led the team at UCSD
10:10that was the first
10:10to ever hack a car's
10:12steering and brakes.
10:13Back in 2008,
10:13we didn't know
10:14what we were doing
10:14and cars were really complicated
10:16and we had to reverse engineer
10:18how they work.
10:19The big one
10:19was we reverse engineered
10:21at the time
10:21how the OnStar
10:22cellular signal worked
10:23and so 1,500 miles away,
10:25we could take over your car,
10:27unlock it,
10:27lock it,
10:28turn off the engine,
10:29we could make it skid
10:30on the brakes.
10:30That experiment,
10:31which UCSD carried out
10:33with the University of Washington,
10:34was the first time
10:35that cars were proven
10:36to be hackable.
10:37But then,
10:37in the summer of 2015,
10:39security researchers
10:39Charlie Miller
10:40and Chris Valasek
10:41carried out
10:42an even more dramatic demonstration
10:44that changed
10:44the auto industry forever,
10:46with me behind the wheel
10:47as their crash test dummy.
10:49Okay, hold on tight.
10:50Hold on.
10:50Oh, s***.
10:51Miller and Valasek
10:52told me to drive
10:53a Jeep Cherokee
10:53onto a highway in Missouri.
10:55Then,
10:55the two hackers
10:56remotely took control
10:57of the vehicle
10:58from miles away
10:59through its internet-connected
11:00Uconnect infotainment system.
11:02First,
11:02the radio blasted music,
11:04then the windshield wipers
11:05turned on,
11:05the air conditioning failed,
11:07and finally,
11:07the Jeep slowed
11:08to a stop
11:08on the highway
11:09as the hackers
11:10disabled my transmission.
11:11The fallout of our stunt
11:13was immediate.
11:14Days after my story
11:15was published,
11:16Fiat Chrysler issued
11:16the first major
11:17cybersecurity recall
11:18in automotive history,
11:20recalling 1.4 million vehicles
11:22to patch the vulnerability
11:23that Miller and Valasek
11:24had exploited.
11:25What began
11:25as a shocking experiment
11:26led to carmakers
11:27being suddenly forced
11:28to think like tech companies,
11:30launching bug bounty programs
11:31that pay independent researchers
11:32for reporting
11:33hackable vulnerabilities,
11:34hiring cybersecurity researchers,
11:36and redesigning
11:37vehicle systems
11:38to better isolate
11:39critical controls
11:39from internet-connected features.
11:41These experiments
11:42showed that a malicious hacker
11:43could pose
11:44a very real safety threat
11:45to modern vehicles.
11:46But thankfully,
11:47none of those attacks
11:48on cars' driving systems
11:49have ever been seen
11:50in the wild.
11:51Why do you think
11:51it is that we've never
11:52actually seen those attacks
11:54used in practice?
11:55Because people don't
11:56want to hijack cars.
11:57There are easier,
11:58cheaper,
11:59and more effective
11:59ways to kill somebody.
12:00It's not a solution
12:01to an actual problem
12:02that people have.
12:03Where the action is,
12:04is car theft.
12:06We have made
12:06the security in cars
12:08strong enough
12:09that there really
12:10is no way
12:11to steal a car today
12:12without hacking it.
12:13And the reason is
12:14we've gotten so good
12:15at protecting our cars.
12:17Like, your cars now,
12:17they have immobilizers.
12:19And so you can go in,
12:20you can break the window,
12:21you can try to hotwire,
12:22none of that stuff
12:23is going to work anymore.
12:24If you want to steal a car,
12:25you have to hack the car today.
12:27In other words,
12:28car hacking has continued
12:29to evolve,
12:29and it's actually become
12:30much simpler.
12:32It's shifted from
12:32the highly complex attacks
12:33that take over steering
12:34and brakes
12:35to far, far easier exploits
12:37that can simply
12:37take over cars' smart features,
12:39sometimes via their connection
12:40to a phone
12:41or even with simple
12:41web vulnerabilities.
12:43In just the last few years,
12:44security researchers
12:45have found Bluetooth exploits
12:46that can unlock Teslas,
12:48relay attacks
12:48that let thieves
12:49steal cars
12:50using wireless key fobs
12:51and security flaws
12:52in the phone apps
12:53used by Kia,
12:54Subaru,
12:55and dozens of other car makers
12:56that expose vehicle controls
12:58or even location tracking.
13:00So there is a huge
13:01black market of devices
13:02where you take out
13:03the front headlight
13:04and try to plug into
13:05the CAN bus
13:06and reprogram it.
13:07And so this is part and parcel
13:08of how car theft works now.
13:10Devices that will steal
13:11the keyless entry signal
13:12from someone's house,
13:13that is where
13:14the action is.
13:15So what do you think
13:16about Aaron's team
13:17and their research
13:18into this other
13:19third-party device?
13:20In some ways,
13:21it's even creepier.
13:21It's definitely creepier.
13:22There is a device
13:23that has been added
13:24to your car,
13:25unbeknownst to you,
13:26that already does
13:27all the things
13:28you need to do.
13:28You just need to
13:29tell it to do it.
13:30So of all the car hacking
13:31techniques that you've seen
13:33and witnessed
13:34and even developed yourself
13:35in the last decade
13:36and a half,
13:36how would you say
13:37that this car alarm exploit
13:39stacks up?
13:39Like, how does it compare
13:40in terms of severity?
13:41As far as severity,
13:43I think it's probably
13:43the worst.
13:44And the reason is
13:45it affects a large number
13:47of vehicles
13:47and the manufacturer
13:49of your car can't fix it
13:50and you don't even know
13:51you have the problem.
13:52It provides all of the elements
13:54that a car thief would want,
13:55but you have none
13:56of the advantages
13:56we normally have
13:57in terms of defending it
13:59because you're disconnected
14:00from the supply chain
14:01that put it there.
14:02That means the security
14:03vulnerability that UCSD found
14:04puts a huge number of cars
14:06at risk of stealthy theft,
14:07as I'll demonstrate
14:08in a moment.
14:09To understand how
14:09the team found it,
14:10I spoke with them
14:11inside their actual
14:12hardware hacking lab.
14:14Can you tell me the story
14:16of how you found this device
14:17and how you figured out
14:18that it was hackable?
14:19So back in 2019,
14:20we were working
14:21on a different project.
14:22This was to investigate
14:24Bluetooth skimmers
14:25that criminals actually use
14:27to steal your credit card info
14:28and plant them
14:29at gas stations.
14:30And during that time,
14:31I was doing a lot
14:32of Bluetooth device scanning
14:34and I would keep seeing
14:35these Bluetooth devices
14:36with a very particular name
14:38that would show up often
14:39at these gas stations.
14:40And then eventually
14:41I started seeing them
14:42also in parking lots
14:44and parking garages.
14:45I initially thought
14:46it was some form
14:47of a payment system perhaps,
14:48but then these would also show up
14:50as we were driving
14:51along the freeways.
14:52So I figured it was
14:53a particular type of vehicle.
14:55Eventually,
14:55as I looked further,
14:57we realized that
14:58this was not just
14:59a type of vehicle,
15:00this was basically
15:01any consumer vehicle
15:02out there.
15:03So you knew that
15:03it was something inside
15:04of vehicles all over the place
15:06that you were seeing
15:07even on the road,
15:08but how did you figure out
15:09that it was specifically
15:10this KARR car alarm?
15:13As Michal mentioned,
15:14there was a particular
15:14device name.
15:15So we took the prefix
15:16of that device name,
15:17searched it up on Google
15:18and we actually found
15:19the FCC filing
15:20that allowed us to link
15:22that device to its manufacturer,
15:23that is CAR.
15:24The team then turned
15:25their focus to the CAR app,
15:27which allows users
15:28to control their security system
15:29via Bluetooth.
15:30So once we reverse-engineered
15:31their application,
15:32we quickly realized
15:33after understanding
15:34their internal authentication protocol
15:36that it was so simple
15:37that we could actually
15:38just extract it
15:39and re-implement it
15:40as our own application,
15:41which we did.
15:42So basically,
15:42you took their app,
15:43which is meant to just
15:44authenticate and unlock
15:45a single car,
15:46and instead,
15:47you built an app
15:48that can unlock any car.
15:49Every single car
15:50that they have ever
15:51put this in.
15:52So it was actually
15:53more than 18 months ago
15:54that you first told
15:55AcroStore Protection Group
15:56about this discovery.
15:57Did they leave this vulnerable
15:58all that time?
16:00They've been developing a patch
16:01and they did actually
16:02give it to us to test.
16:03Do you believe
16:04that this problem
16:05actually can be fixed?
16:06This is a Bluetooth-only device.
16:08It has no cellular modem,
16:10no connectivity online
16:11all the time.
16:12That means that
16:13it has to be manually patched
16:15on every single one
16:16of these alarms
16:16in every single car
16:18that has been deployed.
16:20To show just how important
16:21it is to install that fix,
16:23I'm going to attempt
16:24to steal a car
16:25without setting off the alarm,
16:26smashing a window,
16:27or jimmying the lock.
16:28In other words,
16:29without doing any of the things
16:30that usually make it possible
16:31to catch a car thief
16:32in the act.
16:33Our victim is inside the house.
16:34We've set up a camera
16:35to monitor her
16:36and see whether or not
16:37she can hear me
16:38or see any sign
16:39I'm stealing her car.
16:40I know that your hacking technique
16:41can unlock the target vehicle.
16:43How do I actually start the car
16:44and drive it away?
16:45So there's actually a tool
16:46that car thieves commonly use
16:48that's originally actually
16:49a tool for locksmiths.
16:51What it essentially does
16:52is let them clone
16:53the key of the car.
16:54Normally, the car thieves
16:56have to connect it
16:57inside the car
16:58and to get in there,
16:59they're smashing windows.
17:00But with this alarm,
17:02when you bypass it,
17:03you can get in the car silently.
17:04Plug this thing in
17:05and you'll be able
17:06to steal the car.
17:07Aaron and his team's
17:08theft technique
17:09focuses on allowing
17:10a car thief to silently
17:11and instantly get inside a car
17:12where they can use
17:13a fairly standard locksmith tool
17:15to connect to the dashboard
17:16and clone the key.
17:17Here we go.
17:19All right, I'm starting
17:20the timer now.
17:21Normally, a thief
17:22would need to smash a window
17:23or use some other trick
17:24to get the door open,
17:25often setting off the alarm.
17:26With Aaron's team's
17:27hacking technique, though,
17:28I don't need to do any of that.
17:30I quietly unlock the car.
17:31The alarm is suppressed
17:32and I'm in.
17:33It's going to now
17:34connect the system.
17:35That part is easy.
17:3620 seconds in.
17:37Now I'm going to take
17:38the locksmith tool
17:39and make a key for this car.
17:40I'm not going to give you
17:41the details of how
17:42this device works.
17:43I don't want to create
17:44a how-to video here.
17:45But the process takes
17:45about two minutes,
17:46even when I screw it up
17:47the first time.
17:48Didn't work the first time.
17:49Gotta try again.
17:50It turns out,
17:51for this model of car,
17:51I have to turn the hazard lights on
17:53to make a new key.
17:54But there's no audible alert
17:55to get the victim's attention.
17:57It's worth noting here
17:58that if you do spot
17:59your car's hazard lights
18:00turning on unexpectedly
18:01in the middle of the night,
18:02it could be a sign
18:03that a car thief
18:03is inside cloning the key.
18:05He's looking around
18:06like he might be getting
18:07to the point he's about to start at.
18:08The tool has created
18:09a new key fob.
18:10I press it to the ignition button
18:12and the engine comes alive.
18:14Lights are on.
18:15That's a good sign.
18:18Oh, here we go.
18:19And I got it.
18:25There it goes.
18:27Wow, he's really
18:28taking that thing away.
18:29Is he going to bring it back?
18:33Hey, how's it going?
18:34Andy stole your car.
18:37I was struck by
18:38just how smoothly
18:39the process wins.
18:40I basically got away
18:41without alerting the owner.
18:46Good job, Axel.
18:47How did that feel, Andy?
18:48That is insane.
18:49What was my...
18:49It was about two and a half minutes.
18:51A little bit longer
18:52than I expected, but...
18:53Not quite gone in 60 seconds,
18:55but close.
18:55You know what?
18:56There's always some issues,
18:57but you nailed it.
18:58Around the time
18:59of our Carthaf demo,
19:00I reached out
19:00to AccraSure Protection Group,
19:02the company that sells
19:02the car alarm device,
19:03and asked them about
19:04the vulnerability in their system.
19:06Like the team at UCSD
19:07had told me,
19:07the company said
19:08it developed a firmware patch
19:09which is now available
19:10to install
19:11if you download the car
19:12that's K-A-R-R
19:13security smartphone app.
19:14Just tap customer service
19:16on the home screen
19:16to find the firmware update option.
19:18AccraSure PG also wrote
19:20in a statement
19:20that the vulnerability
19:21described in the research
19:22is highly complex
19:23and presents a low risk
19:24to customers
19:25under real-world conditions.
19:26Nevertheless,
19:27we responded promptly
19:28and developed a firmware update
19:29to address the issue.
19:31Whether the car alarm vulnerability
19:32represents a quote-unquote
19:33low risk of abuse,
19:34I'll leave to you to decide
19:35based on seeing the demos
19:37we just showed you.
19:37As for the company's claims
19:38that it responded
19:39quote-unquote promptly,
19:40AccraSure Protection Group
19:41actually took well over
19:4218 months
19:43to roll out its patch
19:44after UCSD
19:45first contacted
19:46its security team.
19:47The company also noted
19:48it would warn customers
19:49about the patch
19:50through in-app alerts,
19:51dealer communications
19:52and on its website.
19:53But that strategy
19:53of contacting affected drivers
19:55also leaves unanswered
19:56how AccraSure PG
19:57will reach car owners
19:59who aren't the company's customers.
20:00That includes car owners
20:01who don't even know
20:02they have its vulnerable device
20:03in their vehicle.
20:04Everyone that has this
20:05in their car,
20:06including people
20:06that don't even know
20:07they have it
20:08because they said no
20:09to having the system installed,
20:10now needs to run
20:12a firmware update
20:12from their phone
20:14onto this device
20:15in order to patch
20:16this universal key
20:17that's on there.
20:18But the complication here
20:19is that this isn't like
20:20a product somebody bought
20:21that they're now
20:22just being told
20:23to install an update on.
20:24It's something that people
20:25actually asked
20:26not to have in their cars.
20:27They don't even know
20:28that it's there.
20:29How do you reach those people
20:30to get them to patch?
20:32Actually, that is one of the reasons
20:33I'm doing this interview
20:34right now.
20:35Doing that kind of
20:36massive update
20:37is going to require
20:38a huge awareness campaign.
20:39I want as much media attention
20:41as possible onto this
20:42because in the end
20:43there is no other way
20:44we can reach the millions
20:45of people
20:46than to just make it
20:47widely known
20:48this is happening
20:48and get them
20:49to install that patch
20:50on their car.
20:51It's been more than a decade
20:52since I personally witnessed
20:53the problem of cars
20:54digital insecurity
20:55in a very first-hand demonstration.
20:57But now,
20:58the most imminent
20:58automotive cybersecurity threat
21:00may not be elite hackers
21:01taking over your vehicle
21:03from miles away
21:03and driving your car
21:04off a cliff.
21:05Instead,
21:06it's the invisible ecosystem
21:07of third-party
21:08connected hardware
21:09silently embedded
21:10in modern vehicles
21:11by manufacturers,
21:12dealerships,
21:13insurers,
21:14and vendors.
21:15That means
21:15you need to be aware
21:16of digital threats
21:17to your car,
21:18think twice about
21:19the security of gadgets
21:20you plug into it,
21:21and install security
21:22updates and patches.
21:23Modern technology
21:24has made cars safer,
21:26more convenient,
21:26and more reliable
21:27than ever before.
21:28But some of those
21:29same upgrades and features
21:30have also created
21:31serious security vulnerabilities,
21:33including at least
21:33one device
21:34that plenty of drivers
21:35don't even know
21:36is under their hood.
21:37This is Hack Lab.
21:38I'm Andy Greenberg.
21:41We'll talk
21:42to you soon.
Comments

Recommended