, , ,

Your in-car entertainment system and EV charger likely have big security flaws, hackers find

Dozens of vulnerabilities have been discovered in vehicle charging systems, in-car entertainment technology and modem subsystems from some of the world’s biggest automotive suppliers, including Tesla. 

The vulnerabilities, which numbered almost 50 in total, were unearthed thanks to the Pwn2Own Automotive hacking competition, which took place during the Automotive World conference in Tokyo earlier this month.

The Pwn2Own concept, which was first launched in 2007, sees some of the world's leading security researchers and 'white hat' hackers gather to find security flaws in consumer technology. As of 2019, the annual competition added connected vehicles and their related infrastructure.

During this year's three-day challenge, the competition quickly uncovered vulnerabilities in Automotive Grade Linux, ChargePoint, JuiceBox, Phoenix Contact, and Ubiquiti Connect EV Station electric vehicle chargers. In-car entertainment systems from Alpine, Pioneer, and Sony (although these tended to be aftermarket head units, rather than manufacturer-fitted devices) and the modem in Tesla vehicles were also highlighted – the latter providing root access, according to Hackster.io.

Further into the competition, additional bugs were found in chargers from Autel and Emporia, bringing the total over three days to 49 “unique zero-day vulnerabilities”. The overall prize pot totaled $1 million, but Team Synacktiv unearthed the most security flaws and therefore took the greatest number of points, securing a total winnings of $450,000.

In order to maintain privacy and prevent future attacks, details of the vulnerabilities are kept firmly under wraps. The only information organizers of the Zero Day Initiative (ZDI) unveils is things like “Vudq16 and Q5CA from u0K++ successfully executed a stack-based buffer overflow against the Alpine Halo9 iLX-F509”. So not especially helpful for the average car owner, for now.

However, detailed information becomes the property of the ZDI and is subsequently disclosed privately to each of the affected manufacturers, giving them a chance to release patches and avoid future issues.


Analysis: Cars are digital security nightmares

Lexus LF-ZC Concept

(Image credit: Lexus)

One of the most popular buzzwords in automotive right now is the 'software defined vehicle' – a blanket term that relates to the burgeoning amount of connectivity found in modern cars. 

Thanks to the increased data transfer speeds of the 4G and 5G network, the cars on today's roads can be updated remotely, they can 'talk' to existing infrastructure and even other vehicles.

Plug an EV into a public charging station and the vehicle, RFID card and/or smartphone app used during the transaction hands over a bundle of owner information, including names, email addresses and even location, browsing history and online behavioral patterns, according to an article published by the IAPP, the world’s largest global information privacy community.

On top of this, research by Mozilla revealed that modern cars are “the worst product category we have ever reviewed for privacy” thanks to poor practices on data protection, while vulnerabilities in infotainment systems have allowed some security researchers to gain access to restricted vehicle features, such as those premium paid-for features found in Tesla and BMW cars, for example.

More worrying still is the rise in vehicle theft thanks to criminals using sophisticated technology to mimic remote keyless systems. Canada’s Prime Minister, Justin Trudeau, recently announced it is to hold a summit next month to coordinate a national response to a shocking spike in auto thefts across the country in recent years.

Although events like the Pwn2Own Automotive competition help to expose flaws in modern vehicles and their related digital ecosystems, it only really scratches the surface of the privacy and security problems that face modern connected cars. If anything, it serves as further proof that a lot more needs to be done. 

You might also like

https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/your-in-car-entertainment-system-and-ev-charger-likely-have-big-security-flaws-hackers-find


July 2024
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 988: Flaming Corn Maze – AT&T Breach, Galaxy Z Fold6, Olympic Disinfo This Week in Tech (Audio)

Galaxy Z Fold 6 launches for $1,899 with wider displays FTC bans anonymous messaging app NGL from hosting children AT&T says criminals stole phone records of 'nearly all' customers in new data breach EU accuses Elon Musk's X of deceptive practices over blue 'checkmark' After 41 years Microsoft quietly adds spellchecking and autocorrect to Windows Notepad AI PCs: Qualcomm (QCOM), Microsoft (MSFT) Turn to AI to Revive PC Market Goldman Sachs: AI Is Overhyped, Wildly Expensive, and Unreliable U.S. says Russian bot farm used AI to impersonate Americans Disinfo spreaders set their sights on Paris Olympics My 28,000-follower Twitter account was hacked—and it changed my life for the better Is anyone concerned that Palmer Luckey's new compay Anduril (aka Aragorn's sword from LOTR) is making military products and has a mission statement straight out of Robocop? Apple now makes it easier to switch from Google Photos to iCloud Photos FTC Fires A Warning Shot At Eight Companies Over 'Right To Repair' Violations Host: Leo Laporte Guests: Mike Elgan, Denise Howell, and Harry McCracken Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: e-e.com/twit motific.ai bitwarden.com/twit ziprecruiter.com/twit
  1. TWiT 988: Flaming Corn Maze – AT&T Breach, Galaxy Z Fold6, Olympic Disinfo
  2. TWiT 987: Often Plagiarized, Never Equalled – Sapce Junk, Threads Hits 175M Users, AIndependence
  3. TWiT 986: Our Dope GPS! – Supreme Court Decisions, Snapdragon X Elite Tests
  4. TWiT 985: TikTok With Wings – AT&T Landlines, US Bans Kaspersky and DJI
  5. TWiT 984: Fifty-three Clicks – Bot Farms in Ukraine, LA Public Health Dept. Phished