The software update for your next car might turn out to be its greatest security vulnerability.

The software update for your next car might turn out to be its greatest security vulnerability.

      Contemporary vehicles are no longer static machines once they leave the showroom. They are increasingly transitioning into software-defined vehicles that can receive new features, fixes, and security updates wirelessly, similar to smartphones. Although over-the-air (OTA) updates have made maintenance more convenient and cost-effective, cybersecurity experts caution that this same technology may become one of the automotive sector's most significant security challenges.

      Researchers and policymakers are advocating for stricter oversight as connected vehicles rely more on remote software updates. Their concerns extend beyond hackers compromising personal information; they worry about the potential for someone to disrupt the operation of a moving vehicle.

      While the ease of wireless updates brings benefits, it introduces new risks

      OTA technology enables manufacturers to remotely distribute software updates, firmware improvements, and security patches without the need for vehicle owners to visit a dealership. Tesla popularized this concept over a decade ago, beginning with wireless updates for the Model S in 2012. Nowadays, this capability is widespread in both luxury and mainstream vehicles.

      For consumers, the benefits are clear. Automakers can swiftly remedy software issues, enhance battery management, introduce new infotainment options, or even improve driving performance without launching costly recalls. A CNBC report featuring Siraj Ahmed Shaikh, a Systems Security Professor at Swansea University, notes that OTA updates are attractive compared to traditional servicing because they lower costs and speed up deployment. Manufacturers can resolve problems almost immediately rather than waiting for scheduled maintenance.

      Cybersecurity experts contend that internet-connected vehicles operate as moving computers.

      Nevertheless, the same always-connected framework that facilitates these updates also expands the attack surface. Cybersecurity analysts argue that internet-connected vehicles effectively operate as rolling computers. If attackers were to compromise the update framework or gain unauthorized access to vehicle software, the ramifications could go far beyond data theft.

      Gabriel Lim, a Senior Analyst at Singapore’s S. Rajaratnam School of International Studies, informed CNBC that this issue poses a potential national security threat. Beyond user privacy considerations, governments are increasingly looking into whether foreign manufacturers or hostile entities could potentially manipulate vehicle systems from a distance. These apprehensions have led several nations to reconsider how they regulate connected vehicles.

      Governments are starting to recognize the threat seriously

      The conversation intensified after Ruter, a Norwegian public transport operator, conducted security assessments on electric buses last year. The company discovered that one bus’s battery and power management system could be accessed remotely via a mobile network connection. They concluded that, theoretically, the manufacturer could disable or immobilize the bus from afar.

      Although the investigation focused on buses made by the Chinese company Yutong, experts warn that this issue is not isolated to any particular automaker or country. Instead, they regard it as a widespread industry challenge associated with the increasing adoption of connected vehicle systems. Following these findings, authorities in both the United Kingdom and Denmark initiated their own inquiries, with the UK’s Department for Transport collaborating with the National Cyber Security Centre to explore potential vulnerabilities.

      As vehicles become more intelligent, hackers may also evolve

      Similar worries are beginning to influence policy dialogues in the United States. Earlier this year, the American Enterprise Institute claimed that safeguarding connected vehicles from foreign espionage should become a strategic priority. The think tank suggested enhanced security evaluations, greater transparency regarding vehicle data collection, and stricter regulations on certain foreign-made automotive software and hardware.

      The ramifications extend beyond passenger vehicles. OTA technology is increasingly being implemented in buses, commercial fleets, rail systems, ships, industrial robots, and drones. As more critical infrastructure becomes amenable to remote updates, experts argue that cybersecurity must no longer be regarded as an afterthought. While wireless updates undoubtedly enhance the intelligence and capability of vehicles, they also redefine automotive safety. In the era of software-defined vehicles, protecting a car increasingly involves safeguarding the code that powers it, as the next cyberattack could be aimed at the vehicle you are operating, rather than your laptop or smartphone.

The software update for your next car might turn out to be its greatest security vulnerability. The software update for your next car might turn out to be its greatest security vulnerability.

Другие статьи

The 'synthetic insider': AI-generated deepfakes as fraudulent employees The 'synthetic insider': AI-generated deepfakes as fraudulent employees AI deepfakes enable hackers to impersonate employees, creating a "synthetic insider" threat. However, the majority of insider leaks continue to be unintentional, and AI agents represent the next potential risk. OnePlus has disappeared, making Android phones in the US a bit duller. OnePlus has disappeared, making Android phones in the US a bit duller. Samsung and Google will manage well, but Android has lost the brand that was willing to experiment with new ideas. AliExpress faces a significant fine: the EU has imposed a record €550 million penalty under the DSA. AliExpress faces a significant fine: the EU has imposed a record €550 million penalty under the DSA. The EU has imposed a €550 million fine on AliExpress, marking its largest penalty under the DSA so far, for not preventing the sale of counterfeit, unsafe, and illegal items. This Gore Verbinski sci-fi comedy is among the three overlooked Hulu films you ought to check out this weekend (July 18-19). This Gore Verbinski sci-fi comedy is among the three overlooked Hulu films you ought to check out this weekend (July 18-19). This weekend's Hulu watchlist includes a sci-fi comedy by Gore Verbinski, a thriller by Park Chan-wook, and a grandmother who becomes an action hero, all receiving critical acclaim. 7 Tips for Enhancing Your Apple Notes Experience 7 Tips for Enhancing Your Apple Notes Experience From highlighted text to password-protected notes, here are seven Apple Notes tips hidden in menus you may have overlooked numerous times. Kenya looks into the hacking of Ruto's official website following a bitcoin ransom request. Kenya looks into the hacking of Ruto's official website following a bitcoin ransom request. Kenya is looking into a cyberattack that altered President Ruto’s website and included a ransom demand of five bitcoins. Officials report that no data was taken.

The software update for your next car might turn out to be its greatest security vulnerability.

Experts indicate that over-the-air updates for vehicles are revolutionizing the automotive industry but are also introducing new cybersecurity and national security concerns that governments can no longer overlook.