Tired of ads? Enjoy an ad-free experience by signing up.
C. Custer Ā· Ā· 5 min read

This is why I’m scared of the smart car era

hack-car-smart-car

Imagine you’re driving on the highway. Rolling happily along, probably listening to Taylor Swift. Then suddenly, the air conditioning comes on, full blast. That’s odd, must be an issue with the system. Then, just as suddenly, the sound system switches to a radio station and starts blasting death metal at full volume. At the same time, your transmission cuts out. With no control of the accelerator, you’re now coming to an unexpected stop on a busy highway with a massive 16-wheel truck barreling in from behind you at 65 miles per hour.

What happened? Your car got hacked.

If that sounds like fantasy, or science fiction, it isn’t. That scenario played out pretty much word for word earlier this month in a vehicle driven by Wired writer Andy Greenberg and hacked by a couple of guys who were sitting in their basement, ten miles away. And although Greenberg knew it was going to happen – the hackers, Charlie Miller and Chris Valasek, are white-hats who were giving him a live demonstration of an exploit – it was still scary enough that he called and ā€œbegged them to stop.ā€

Greenberg’s article is a great read, but if you haven’t got time, here’s the bottom line: as cars get smarter, they’re getting easier to hack. In this case, the guys were using a zero-day exploit in a Jeep’s entertainment system to send messages to all of the car’s other systems. They could also just use the exploit to track the car remotely, without giving away that they’d gotten in.

Obviously, the specific vulnerability that allowed the hackers to compromise the Jeep is likely to be patched and fixed (although how many people are even aware of, let alone install, software patches for their cars?). But the problem is only likely to get bigger as we move toward smarter and smarter cars with more computer integration.

google-self-driving-car

Smarter cars, bigger problems

This is a particular area of concern in China, where many of the major internet companies are already working on smart car projects. Baidu, Alibaba, Tencent, LeTV, and Foxconn are just some of the companies working on smart cars we can expect to see in the next few years. We don’t know what the final design of any of them will look like, but they’re all likely to feature internet connectivity and a lot of integrated web services. That, as the Jeep hack proves, can be dangerous – if hackers can get into your car’s system remotely via some internet service, they might be able to use that to compromise one of the car’s more essential systems. Like the brakes.

This is even scarier in the context of self-driving or partially-autonomous cars like the one Baidu is working on right now. Hackers being able to cut the brakes is dangerous enough, but if they’re able to access the car’s navigation system and change where the vehicle is taking you, that’s potentially even worse. This sort of situation was played for laughs in the first season of Silicon Valley, but I suspect it’s going to be a lot less funny when it actually happens in real life.

It’s not just hacking your smart car could be vulnerable to, either. There is already a device that can disable cars from some distance using radio waves to scramble their internal electronics. At present, the device is huge, expensive, and is meant only for police and military use. But as the technology develops it will likely get much smaller and much cheaper, which would make it easier for unscrupulous bad guys to take advantage of.

No solution in sight

The solution, you might say, is to keep the entertainment system completely separate from the essential systems, and not computerize the essential systems at all. After all, cars ran fine for years before we started putting computers in them. There’s no way you could hack a 1980 Volkswagon Rabbit remotely.

But the ability to hack and remotely disable cars, while terrifying for drivers and passengers, is also something that many governments and police forces are actively pushing for. From a government perspective it makes sense: give cars a remote ā€œkill switchā€ and your police no longer have to worry about high-speed chases. Make cars internet-connected and trackable and you can follow anyone in a vehicle easily and remotely. Plus, as self-driving and partially-autonomous cars start to take over the roads, cars’ essential systems will need to be in constant contact with the outside world so they can sense upcoming obstacles. If anything, cars’ essential systems are likely to get more connected to the outside world as the smart car industry develops.

The potential to exploit a hackable car is simply going to be too attractive to pass up. Government intelligence agencies could do it to track the movements of foreign political figures (or attempt to assassinate them by disabling critical systems when the car is at high speed). Unscrupulous businessmen in the transportation industry could do it to destroy the reputation of a rival car, truck, bus, or taxi company by causing repeated accidents or delays. Malicious criminal hackers could do it for profit (ā€œWire me $1 million immediately or I cut the brakes on your wife’s carā€) or just as a stupid, dangerous prank (like swatting).

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

šŸ„ For casual readers / šŸ‘¶ Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

āŒ›Sign up in 20s. No payment details needed.

šŸ“– For learners / šŸ‘ Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

C. Custer

Former editor and motion graphics artist for Tech in Asia. Currently content marketer at Dataquest.io