Hack My Ride: Cyber Attack Risk on Car Computers

Increasingly sophisticated onboard computers may put cars in danger of cyber attacks

Join Our Community of Science Lovers!

Worrying about hackers breaking into your laptop and cell phone is bad enough, but soon your car may be vulnerable, too. With each new model year, the automobile becomes less a collection of mechanical devices and more a sophisticated network of computers linked to one another and to the Internet. Earlier this year a group of researchers proved that a hacker could conceivably use a cell phone to unlock a car’s doors and start its engine remotely, then get behind the wheel and drive away. In work presented in March to a committee of the National Academies, Stefan Savage, a computer science professor at the University of California, San Diego, and Tadayoshi Kohno of the University of Washington, placed malicious software on an unspecified car’s computer system using its own Bluetooth and cell phone connections. The software could have been used to co-opt the car’s computer system, including its engine. The research “shows the need for security measures in vehicular onboard networks,” says Olaf Henniger, a researcher at Germany’s Fraunhofer Institute for Secure Information Technology.

Henniger and his colleagues are working to create just that. He is a member of EVITA, an effort that was launched in 2008 with the help of BMW Group, Fujitsu and others to develop a security blueprint that carmakers can follow to build more secure onboard networks. The project, which is scheduled to wrap up at the end of the year, has already developed prototypes that would encrypt or authenticate data exchanged within the car, with other cars and with equipment on roadways.

Whether car companies are willing to invest in the additional security remains to be seen, says Anup Ghosh of George Mason University’s Center for Secure Information Systems. Many manufacturers say their vehicles are already safe. Ford has a built-in firewall to protect its SYNC system against network attacks and separates its vehicle-control network from its infotainment network, says Rich Strader, director of the company’s Information Technology, Security and Strategy practice. General Motors says its mobile app never communicates directly with the car but instead connects to OnStar’s network, which requires authentication.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


The research does not mean that cars are suddenly vulnerable to network attacks. Savage, Kohno and their colleagues are merely reporting the result of several years of experiments. Still, it seems the unending chess match between hackers and security experts has found a new field of play.

Larry Greenemeier is the associate editor of technology for Scientific American, covering a variety of tech-related topics, including biotech, computers, military tech, nanotech and robots.

More by Larry Greenemeier
Scientific American Magazine Vol 304 Issue 6This article was published with the title “Hack My Ride: Cyber Attack Risk on Car Computers” in Scientific American Magazine Vol. 304 No. 6 ()
doi:10.1038/scientificamerican062011-1uQxc5LCNXb0FOZw0udPwb

It’s Time to Stand Up for Science

If you enjoyed this article, I’d like to ask for your support. Scientific American has served as an advocate for science and industry for 180 years, and right now may be the most critical moment in that two-century history.

I’ve been a Scientific American subscriber since I was 12 years old, and it helped shape the way I look at the world. SciAm always educates and delights me, and inspires a sense of awe for our vast, beautiful universe. I hope it does that for you, too.

If you subscribe to Scientific American, you help ensure that our coverage is centered on meaningful research and discovery; that we have the resources to report on the decisions that threaten labs across the U.S.; and that we support both budding and working scientists at a time when the value of science itself too often goes unrecognized.

In return, you get essential news, captivating podcasts, brilliant infographics, can't-miss newsletters, must-watch videos, challenging games, and the science world's best writing and reporting. You can even gift someone a subscription.

There has never been a more important time for us to stand up and show why science matters. I hope you’ll support us in that mission.

Thank you,

David M. Ewalt, Editor in Chief, Scientific American

Subscribe