Cover Image: June 2011 Scientific American Magazine See Inside

Hack My Ride: Cyber Attack Risk on Car Computers

Increasingly sophisticated onboard computers may put cars in danger of cyber attacks















Share on Tumblr



Image: Alex Stokes Alamy (monitor); Getty Images (dashboard and background)

Worrying about hackers breaking into your laptop and cell phone is bad enough, but soon your car may be vulnerable, too. With each new model year, the automobile becomes less a collection of mechanical devices and more a sophisticated network of computers linked to one another and to the Internet. Earlier this year a group of researchers proved that a hacker could conceivably use a cell phone to unlock a car’s doors and start its engine remotely, then get behind the wheel and drive away. In work presented in March to a committee of the National Academies, Stefan Savage, a computer science professor at the University of California, San Diego, and Tadayoshi Kohno of the University of Washington, placed malicious software on an unspecified car’s computer system using its own Bluetooth and cell phone connections. The software could have been used to co-opt the car’s computer system, including its engine. The research “shows the need for security measures in vehicular onboard networks,” says Olaf Henniger, a researcher at Germany’s Fraunhofer Institute for Secure Information Technology.

Henniger and his colleagues are working to create just that. He is a member of EVITA, an effort that was launched in 2008 with the help of BMW Group, Fujitsu and others to develop a security blueprint that carmakers can follow to build more secure onboard networks. The project, which is scheduled to wrap up at the end of the year, has already developed prototypes that would encrypt or authenticate data exchanged within the car, with other cars and with equipment on roadways.

Whether car companies are willing to invest in the additional security remains to be seen, says Anup Ghosh of George Mason University’s Center for Secure Information Systems. Many manufacturers say their vehicles are already safe. Ford has a built-in firewall to protect its SYNC system against network attacks and separates its vehicle-control network from its infotainment network, says Rich Strader, director of the company’s Information Technology, Security and Strategy practice. General Motors says its mobile app never communicates directly with the car but instead connects to OnStar’s network, which requires authentication.

The research does not mean that cars are suddenly vulnerable to network attacks. Savage, Kohno and their colleagues are merely reporting the result of several years of experiments. Still, it seems the unending chess match between hackers and security experts has found a new field of play.



This article was originally published with the title Hack My Ride.



Subscribe     Buy This Issue

Already a Digital subscriber? Sign-in Now
If your institution has site license access, enter here.

1 Comments

Add Comment
View
  1. 1. jtdwyer 11:29 AM 5/31/11

    The article states:
    "General Motors says its mobile app never communicates directly with the car but instead connects to OnStar’s network, which requires authentication."

    So how do they unlock doors through OnStar?
    "Authentication" probably couldn't be hacked, could it?

    While you're at it, ask your mechanic what's the highest speed your car's ever reached. That information could void your warranty, though...

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital

Latest from SA Blog Network

  SA Digital

Science Jobs of the Week

Email this Article

Hack My Ride: Cyber Attack Risk on Car Computers: Scientific American Magazine

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X