The software update for your next car might turn out to be its greatest security vulnerability.
Contemporary vehicles are no longer static machines once they leave the showroom. They are increasingly transitioning into software-defined vehicles that can receive new features, fixes, and security updates wirelessly, similar to smartphones. Although over-the-air (OTA) updates have made maintenance more convenient and cost-effective, cybersecurity experts caution that this same technology may become one of the automotive sector's most significant security challenges.
Researchers and policymakers are advocating for stricter oversight as connected vehicles rely more on remote software updates. Their concerns extend beyond hackers compromising personal information; they worry about the potential for someone to disrupt the operation of a moving vehicle.
While the ease of wireless updates brings benefits, it introduces new risks
OTA technology enables manufacturers to remotely distribute software updates, firmware improvements, and security patches without the need for vehicle owners to visit a dealership. Tesla popularized this concept over a decade ago, beginning with wireless updates for the Model S in 2012. Nowadays, this capability is widespread in both luxury and mainstream vehicles.
For consumers, the benefits are clear. Automakers can swiftly remedy software issues, enhance battery management, introduce new infotainment options, or even improve driving performance without launching costly recalls. A CNBC report featuring Siraj Ahmed Shaikh, a Systems Security Professor at Swansea University, notes that OTA updates are attractive compared to traditional servicing because they lower costs and speed up deployment. Manufacturers can resolve problems almost immediately rather than waiting for scheduled maintenance.
Cybersecurity experts contend that internet-connected vehicles operate as moving computers.
Nevertheless, the same always-connected framework that facilitates these updates also expands the attack surface. Cybersecurity analysts argue that internet-connected vehicles effectively operate as rolling computers. If attackers were to compromise the update framework or gain unauthorized access to vehicle software, the ramifications could go far beyond data theft.
Gabriel Lim, a Senior Analyst at Singapore’s S. Rajaratnam School of International Studies, informed CNBC that this issue poses a potential national security threat. Beyond user privacy considerations, governments are increasingly looking into whether foreign manufacturers or hostile entities could potentially manipulate vehicle systems from a distance. These apprehensions have led several nations to reconsider how they regulate connected vehicles.
Governments are starting to recognize the threat seriously
The conversation intensified after Ruter, a Norwegian public transport operator, conducted security assessments on electric buses last year. The company discovered that one bus’s battery and power management system could be accessed remotely via a mobile network connection. They concluded that, theoretically, the manufacturer could disable or immobilize the bus from afar.
Although the investigation focused on buses made by the Chinese company Yutong, experts warn that this issue is not isolated to any particular automaker or country. Instead, they regard it as a widespread industry challenge associated with the increasing adoption of connected vehicle systems. Following these findings, authorities in both the United Kingdom and Denmark initiated their own inquiries, with the UK’s Department for Transport collaborating with the National Cyber Security Centre to explore potential vulnerabilities.
As vehicles become more intelligent, hackers may also evolve
Similar worries are beginning to influence policy dialogues in the United States. Earlier this year, the American Enterprise Institute claimed that safeguarding connected vehicles from foreign espionage should become a strategic priority. The think tank suggested enhanced security evaluations, greater transparency regarding vehicle data collection, and stricter regulations on certain foreign-made automotive software and hardware.
The ramifications extend beyond passenger vehicles. OTA technology is increasingly being implemented in buses, commercial fleets, rail systems, ships, industrial robots, and drones. As more critical infrastructure becomes amenable to remote updates, experts argue that cybersecurity must no longer be regarded as an afterthought. While wireless updates undoubtedly enhance the intelligence and capability of vehicles, they also redefine automotive safety. In the era of software-defined vehicles, protecting a car increasingly involves safeguarding the code that powers it, as the next cyberattack could be aimed at the vehicle you are operating, rather than your laptop or smartphone.
Другие статьи
The software update for your next car might turn out to be its greatest security vulnerability.
Experts indicate that over-the-air updates for vehicles are revolutionizing the automotive industry but are also introducing new cybersecurity and national security concerns that governments can no longer overlook.
