
Imagine youāre driving on the highway. Rolling happily along, probably listening to Taylor Swift. Then suddenly, the air conditioning comes on, full blast. Thatās odd, must be an issue with the system. Then, just as suddenly, the sound system switches to a radio station and starts blasting death metal at full volume. At the same time, your transmission cuts out. With no control of the accelerator, youāre now coming to an unexpected stop on a busy highway with a massive 16-wheel truck barreling in from behind you at 65 miles per hour.
What happened? Your car got hacked.
If that sounds like fantasy, or science fiction, it isnāt. That scenario played out pretty much word for word earlier this month in a vehicle driven by Wired writer Andy Greenberg and hacked by a couple of guys who were sitting in their basement, ten miles away. And although Greenberg knew it was going to happen ā the hackers, Charlie Miller and Chris Valasek, are white-hats who were giving him a live demonstration of an exploit ā it was still scary enough that he called and ābegged them to stop.ā
Greenbergās article is a great read, but if you havenāt got time, hereās the bottom line: as cars get smarter, theyāre getting easier to hack. In this case, the guys were using a zero-day exploit in a Jeepās entertainment system to send messages to all of the carās other systems. They could also just use the exploit to track the car remotely, without giving away that theyād gotten in.
Obviously, the specific vulnerability that allowed the hackers to compromise the Jeep is likely to be patched and fixed (although how many people are even aware of, let alone install, software patches for their cars?). But the problem is only likely to get bigger as we move toward smarter and smarter cars with more computer integration.

Smarter cars, bigger problems
This is a particular area of concern in China, where many of the major internet companies are already working on smart car projects. Baidu, Alibaba, Tencent, LeTV, and Foxconn are just some of the companies working on smart cars we can expect to see in the next few years. We donāt know what the final design of any of them will look like, but theyāre all likely to feature internet connectivity and a lot of integrated web services. That, as the Jeep hack proves, can be dangerous ā if hackers can get into your carās system remotely via some internet service, they might be able to use that to compromise one of the carās more essential systems. Like the brakes.
This is even scarier in the context of self-driving or partially-autonomous cars like the one Baidu is working on right now. Hackers being able to cut the brakes is dangerous enough, but if theyāre able to access the carās navigation system and change where the vehicle is taking you, thatās potentially even worse. This sort of situation was played for laughs in the first season of Silicon Valley, but I suspect itās going to be a lot less funny when it actually happens in real life.
Itās not just hacking your smart car could be vulnerable to, either. There is already a device that can disable cars from some distance using radio waves to scramble their internal electronics. At present, the device is huge, expensive, and is meant only for police and military use. But as the technology develops it will likely get much smaller and much cheaper, which would make it easier for unscrupulous bad guys to take advantage of.
No solution in sight
The solution, you might say, is to keep the entertainment system completely separate from the essential systems, and not computerize the essential systems at all. After all, cars ran fine for years before we started putting computers in them. Thereās no way you could hack a 1980 Volkswagon Rabbit remotely.
But the ability to hack and remotely disable cars, while terrifying for drivers and passengers, is also something that many governments and police forces are actively pushing for. From a government perspective it makes sense: give cars a remote ākill switchā and your police no longer have to worry about high-speed chases. Make cars internet-connected and trackable and you can follow anyone in a vehicle easily and remotely. Plus, as self-driving and partially-autonomous cars start to take over the roads, carsā essential systems will need to be in constant contact with the outside world so they can sense upcoming obstacles. If anything, carsā essential systems are likely to get more connected to the outside world as the smart car industry develops.
The potential to exploit a hackable car is simply going to be too attractive to pass up. Government intelligence agencies could do it to track the movements of foreign political figures (or attempt to assassinate them by disabling critical systems when the car is at high speed). Unscrupulous businessmen in the transportation industry could do it to destroy the reputation of a rival car, truck, bus, or taxi company by causing repeated accidents or delays. Malicious criminal hackers could do it for profit (āWire me $1 million immediately or I cut the brakes on your wifeās carā) or just as a stupid, dangerous prank (like swatting).
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




