Who is Driving Your Car? Car Hacking

By on February 21st, 2015 in Blog Posts, Privacy & Security

A recent CBS Sixty Minutes program interviewed folks at U.S. DARPA, including a demonstration of how a recent hacking of a computer-laden car could be accomplished.

Computers in cars are not a new thing, even the dozens that we see in new models, and they have been interconnected for some time as well. Connecting your car to the network is a more recent advance — “On Star” is one variation that has been on-board for a while. The ads for this have suggested the range of capabilities — unlock your car for you, turn on your ignition, detect that you may have been in an accident (air bag deployed, but maybe ┬ámonitoring capabilities) and of course, they know where your car is — if it is stolen they can disable it. Presumably a hacker can do all of these as well — and the DARPA demonstration shows some of the implications of this — stopping the car, acceleration, etc. Criminals have already acquired armies of zombie computers to use in attacking their targets, and for blackmail, etc. Imagine having a few hundred zombie cars in a major city like LA — enabling┬áboth terror or blackmail.

Car Hacking and then Drone Hacking

An additional sequence on Sixty Minutes shows the hacking of a drone. And perhaps equally important, this was a re-programmed drone that is not (as easily) accessed/hacked. Behind this is an issue of software engineering and awareness. The engineers and technologists making drones, cars, and other Internet of Things (IoT) objects are not “building security in.” What is needed is an awareness, for each IoT-enabled device, of the security risks involved — not just to address abuse of that particular device, but also for how that might impact other devices in the network or the health and safety of the user and public.

A recent dialog with some IEEE-USA colleagues surfaced a question of where software engineering licensing (professional engineers) might be required … and we used video games as an example of a point where it did not seem appropriate … of course, that all breaks down if your video game can take over your car or your pacemaker.

Image from Spotify.