BYD to fix cars after hacking potential exposed | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


BYD will issue a remote security update for its Shark 6 ute following a cybersecurity report by the ABC’s Four Corners program.

The car maker will send an over-the-air update for the car’s Android infotainment system preventing people who physically access cars from uploading their own software into the car’s infotainment system.

The update follows a blog post by Fortify Labs, the IT firm behind the ABC’s Asleep at the Wheel story, which published context surrounding “what wasn’t in the Four Corners episode”, including “serious ethical concern” as to how the car was hacked.

The company said it was approached by the ABC and asked to “simulate the remote access a car manufacturer has to a connected vehicle and demonstrate how this access could be abused”.

MORE: Aussie billionaire’s plan to bring back Holden icon

It said the ABC’s program did not show exactly how it accessed electronic systems within a BYD Shark 6 owned by the firm, as there was “ethical concern” about revealing potential flaws in the car’s system, because “this same technique can be used against other Android-based head units in vehicles from other manufacturers”.

While the ABC’s story focused on electric cars from China, the tech firm used to demonstrate flaws in modern vehicles stated it “applies to all vehicle manufacturers”.

A story published online by ABC journalist Angus Grigg described how “we got a cybersecurity expert to hack this BYD. It was too easy”.

MORE: Tesla move sparks Aussie EV price war

“While I’m at the wheel, I’m not the only one in control; a hacker has access to the car,” Grigg wrote.

“With the stroke of a key, he kills the headlights, plunging me into darkness.”

A blog post by Fortify Labs details the lengths the firm went to in order to turn off the car’s headlights – significantly more than the “stroke of a key”.

It included the firm cutting into the Shark’s wiring to splice in their own computer, a compact “Raspberry Pi” device that interfered with the BYD.

“This is how the lights were switched off and the windscreen wipers activated,” Fortify Labs wrote.

“This was all achieved in-line, with a Raspberry Pi simulating a compromised ECU sending out CAN bus messages.”

MORE: Chinese giant rebels against green push

Even with an additional computer spliced into the Shark’s wiring, and external software loaded into its system, ABC’s report confirmed that “critical functions” such as the car’s brakes and cameras could not be accessed, “as these were well protected”.

A statement issued by BYD confirmed that “the demonstrated control of the vehicle’s headlights and windscreen wipers required direct physical access to the vehicle’s internal CAN bus by tapping into the vehicle wiring”.

“BYD remains committed to enhancing cybersecurity protection throughout the vehicle life cycle through ongoing vulnerability analysis, security testing, risk assessment and software updates,” it said.

Fortify Labs said its work with the ABC was essentially a hypothetical demonstration of what may be possible as cars become more connected.

“Imagine a criminal group gaining access to a vehicle manufacturer’s back-end systems,” it said.

“In theory, they could push an OTA update to every connected vehicle that brand has on Australian roads.

“The impact would be catastrophic, and it is one of many reasons why vehicle cyber security deserves a far higher priority than securing our smart washing machines and kettles.”



Click Here For The Original Source.

——————————————————–

..........

.

.