Skip to main content

Smart cars are hackable cars. Are the features worth the risk?

Jeep interior
Image used with permission by copyright holder
The automotive world is one of give and take. If you want hardcore performance, you sacrifice comfort; if you prioritize fuel economy and luxury, you probably won’t be king of the racetrack; and if you have a connected car, you may be vulnerable to hackers.

Cybersecurity concerns have swirled around the transportation sector for some time, but never with the same gravitas that coursed through the blogosphere last week. Chris Valasek — Director of Vehicle Security Research for the security consultancy IOActive — and Charlie Miller — a former NSA employee — were able to able to hijack a Jeep Cherokee’s Unconnect infotainment system via the car’s cellular network. Once they were in, the duo was able to send signals to the car’s computer system, manipulating the brakes, engine, and transmission with a couple laptops in a living room. All they needed was the vehicle’s IP address.

Recommended Videos

If you’re still driving your grandpa’s 1968 Oldsmobile, you probably weren’t too worried. If you own a more modern car though, one packed with wireless features and the ability to link with mobile devices, the news probably gave you some pause. And for good reason.

Charlie Miller (left) and Chris Valasek (right)
Charlie Miller (left) and Chris Valasek (right) Whitney Curtis/Wired

The modern car market demands increased functionality and inter-device communication from the factory, and there are unique security threats that come along with that. Any time a vehicle’s systems are connected to the Internet — directly or indirectly — there will be gaps in the digital armor. The fallout could be something as simple as an unresponsive radio or flashing headlights, but as we found out last week, cybercriminals can potentially access a car’s vital systems remotely, and we don’t need to explain how dangerous that is.

Any time a vehicle’s systems are connected to the Internet — directly or indirectly — there will be gaps in the digital armor.

We have yet to hear about a harmful unauthorized attack on a passenger vehicle, and clearly Valasek and Miller are not amateurs, but the vulnerabilities are clear. It’s not just Jeep vehicles either: nearly every major automaker offers an infotainment system that’s connected to the Web: Ford, Toyota, Honda, Volvo, Volkswagen, Subaru, Hyundai … you name it. Tesla’s newest vehicles can even download powertrain updates over the air, which directly affect the car’s acceleration. Is it only a matter of time before something horrible happens outside of a controlled experiment?

For answers, we turn to the carmakers themselves, and Fiat Chrysler’s initial response to the events was quite interesting. On July 22, the brand put out a press release, explaining that “some functions” had been remotely controlled, and that the automotive industry is a potential hacking target like any other. After the community began to flex its muscles, the company implemented a recall of 1.4 million vehicles, issuing USB sticks that contained a software patch to every owner alongside network-level security measures. Mailing out a truckload of thumb drives seems like an ironically insecure way to fix the problem, but a major automaker has admitted that modern cars are at risk from the attacks of cybercriminals. That’s big.

It’s impossible to say whether or not the company would have issued the recall if it weren’t for the original Wired story, but there is a clear cause and effect here — call the manufacturers out on their failings and they will address them. If we don’t? That’s a scary thought.

The U.S. government has responded as well. Senators Ed Markey (D-Mass.) and Richard Blumenthal (D-Conn.) have introduced a new bill called The Security and Privacy in Your Car Act (SPY Car Act). The legislation will direct the National Highway Traffic Safety Administration and the Federal Trade Commission to set industrywide benchmarks to protect driver safety and privacy, shining regulatory light on an issue that was largely contained within the automotive sector until now.

“Rushing to roll out the next big thing, automakers have left cars unlocked to hackers and data-trackers,” said Senator Blumenthal. “This common-sense legislation protects the public against cybercriminals who exploit exciting advances in technology like self-driving and wireless connected cars. Federal law must provide minimum standards and safeguards that keep hackers out of drivers’ private data lanes.”

It’s a start, but in the meantime, there will be hiccups. Personal safety and priceless information are all at stake here, but despite our best efforts, federal agencies, credit card machines, dating websites, and celebrity Twitter accounts are hacked every single day. It’s a constant rat race to keep up, and unfortunately for us, it’s not always the guy with the suit and tie that gets there first.

As car buyers, we crave connectivity. We lust for convenience. But are we ready to live with the consequences?

Andrew Hard
Former Digital Trends Contributor
Andrew first started writing in middle school and hasn't put the pen down since. Whether it's technology, music, sports, or…
Range Rover’s first electric SUV has 48,000 pre-orders
Land Rover Range Rover Velar SVAutobiography Dynamic Edition

Range Rover, the brand made famous for its British-styled, luxury, all-terrain SUVs, is keen to show it means business about going electric.

And, according to the most recent investor presentation by parent company JLR, that’s all because Range Rover fans are showing the way. Not only was demand for Range Rover’s hybrid vehicles up 29% in the last six months, but customers are buying hybrids “as a stepping stone towards battery electric vehicles,” the company says.

Read more
BYD’s cheap EVs might remain out of Canada too
BYD Han

With Chinese-made electric vehicles facing stiff tariffs in both Europe and America, a stirring question for EV drivers has started to arise: Can the race to make EVs more affordable continue if the world leader is kept out of the race?

China’s BYD, recognized as a global leader in terms of affordability, had to backtrack on plans to reach the U.S. market after the Biden administration in May imposed 100% tariffs on EVs made in China.

Read more
Tesla posts exaggerate self-driving capacity, safety regulators say
Beta of Tesla's FSD in a car.

The National Highway Traffic Safety Administration (NHTSA) is concerned that Tesla’s use of social media and its website makes false promises about the automaker’s full-self driving (FSD) software.
The warning dates back from May, but was made public in an email to Tesla released on November 8.
The NHTSA opened an investigation in October into 2.4 million Tesla vehicles equipped with the FSD software, following three reported collisions and a fatal crash. The investigation centers on FSD’s ability to perform in “relatively common” reduced visibility conditions, such as sun glare, fog, and airborne dust.
In these instances, it appears that “the driver may not be aware that he or she is responsible” to make appropriate operational selections, or “fully understand” the nuances of the system, NHTSA said.
Meanwhile, “Tesla’s X (Twitter) account has reposted or endorsed postings that exhibit disengaged driver behavior,” Gregory Magno, the NHTSA’s vehicle defects chief investigator, wrote to Tesla in an email.
The postings, which included reposted YouTube videos, may encourage viewers to see FSD-supervised as a “Robotaxi” instead of a partially automated, driver-assist system that requires “persistent attention and intermittent intervention by the driver,” Magno said.
In one of a number of Tesla posts on X, the social media platform owned by Tesla CEO Elon Musk, a driver was seen using FSD to reach a hospital while undergoing a heart attack. In another post, a driver said he had used FSD for a 50-minute ride home. Meanwhile, third-party comments on the posts promoted the advantages of using FSD while under the influence of alcohol or when tired, NHTSA said.
Tesla’s official website also promotes conflicting messaging on the capabilities of the FSD software, the regulator said.
NHTSA has requested that Tesla revisit its communications to ensure its messaging remains consistent with FSD’s approved instructions, namely that the software provides only a driver assist/support system requiring drivers to remain vigilant and maintain constant readiness to intervene in driving.
Tesla last month unveiled the Cybercab, an autonomous-driving EV with no steering wheel or pedals. The vehicle has been promoted as a robotaxi, a self-driving vehicle operated as part of a ride-paying service, such as the one already offered by Alphabet-owned Waymo.
But Tesla’s self-driving technology has remained under the scrutiny of regulators. FSD relies on multiple onboard cameras to feed machine-learning models that, in turn, help the car make decisions based on what it sees.
Meanwhile, Waymo’s technology relies on premapped roads, sensors, cameras, radar, and lidar (a laser-light radar), which might be very costly, but has met the approval of safety regulators.

Read more