Hand-Sized Device Can Hack Cars Remotely, Researchers Call for Greater Security
February 6, 2014 11:50 AM
comment(s) - last by
The device will be presented at the Black Hat Asia security conference in Singapore next month
A team of Spanish security researchers is out to
beef up auto security
by showing its ability to hack a car with a device the size of your hand.
, security researchers Javier Vazquez-Vidal and Alberto Garcia Illera plan to show a new device they've built at the Black Hat Asia security conference in Singapore next month -- and they're hoping it will be a wake-up call for the auto industry.
The device is called the CAN Hacking Tool (CHT) and it attaches via four wires to the Controller Area Network or CAN bus of a vehicle. It draws power from the car’s electrical system and allows an attacker to send wireless commands remotely from a computer.
The researchers say it's as easy as lifting the hood real quick or simply sliding under the car to attach the device to a vehicle and walk away.
From there, the attacker could switch off headlights, set off alarms, roll windows up and down, and access anti-lock brakes or emergency brakes. The researchers have already tested it on four different vehicles, although they won't reveal which makes and models.
CHT [SOURCE: Forbes]
For right now, the device only works using Bluetooth, which means it can be controlled from just a few feet away. But the research team said that by the time the conference rolls around next year, it will implement a GSM cellular radio, which will allow remote control of the vehicle from a few miles away.
“It can take five minutes or less to hook it up and then walk away,” said Vazquez-Vidal. “We could wait one minute or one year, and then trigger it to do whatever we have programmed it to do.”
What makes matters worse is that the items needed to build the device can all easily be bought from store shelves, and costs under $20 total.
Also, it's nearly impossible to trace the attacker, according to the researchers.
The team said they built the device to show automakers what attackers are capable of, and to call for greater security in cars, which are becoming increasingly connected and more vulnerable to hacks.
“The goal isn’t to release our hacking tool to the public and say ‘take this and start hacking cars,’” says Vazquez-Vidal. “We want to reach the manufacturers and show them what can be done.”
This article is over a month old, voting and posting comments is disabled
This is a non-issue
2/8/2014 12:54:11 AM
First of all, all of these issues are address in OBDIII.
1) OBDIII tells you when a 3rd party device is plugged into the PEG port or is running on the CAN BUS.
2) OBDIII sets off the alarm/immobilizes the vehicle is the alarm system is active when a device is plugged in.
3) OBDIII divides up the emissions, restraint, braking, engine control, climate control, steering/suspension and entertainment systems of a vehicle into separate groups. All groups except or emissions are vendor-specific.
3a) Unfortunately this means that proprietary readers will be required for each brand of vehicle to identify problems other than emissions.
3b) Fortunately, this means that no universal devices will be able to compromise a vehicle, unless they want to hack that EGR reading from 2 miles away.
In the near term, its important to consider how ineffective this device will be on OBDII vehicles:
1) I doubt it can take control of a moving vehicle since most vehicles don't allow parameter modification to safety systems when the VSS reads a speed above zero. All vehicles require a restart for RSM/ABS modules to initialize newly written data.
2) If you are in a stationary vehicle and somebody takes control of it by moving it, you can
a) remove the keys/hold the start button for 5 seconds
b) apply the brake pedal. this is a mechanical system that can not be disabled/overridden.
I am absolutely dying to see this thing work. It may take advantage of one model vehicles' flaws, or at best one manufactures flaws, but to make a device that can "take control" of all vehicles using the CAN BUS is impossible.
I hope they call it Series T-X
"There's no chance that the iPhone is going to get any significant market share. No chance." -- Microsoft CEO Steve Ballmer
Security Researchers Try to Protect Vehicles from Computer Viruses
August 20, 2012, 9:29 AM
Michigan Governor Signs “Anti Tesla” Bill That Bans Direct Sales, GM Applauds Decision
October 22, 2014, 8:56 AM
Report: 2015 Ford Focus Electric MSRP Slashed by $6,000, Will Retail for $29,995
October 18, 2014, 6:23 PM
Chevrolet Sonic EV to Have 200-mile Range, Debut in 2017
October 10, 2014, 12:01 PM
Auto Start-Stop Systems Will be Installed on Nearly 60% of New Vehicles by 2020
October 8, 2014, 4:19 PM
Volvo XC90 to Receive Triple-turbocharged, 450hp 2.0-liter Four-cylinder Engine
October 7, 2014, 2:29 PM
Nissan Still Trying to Make a Profit on Leaf EV
October 6, 2014, 5:46 PM
Most Popular Articles
Chinese Government Declares Digital War Against America's Top Tech Firms
October 20, 2014, 12:07 PM
Samsung Announces Galaxy S5 Plus with Snapdragon 805 Processor, LTE-A
October 22, 2014, 3:40 PM
Windows 8.1 + Android "Sell Mini PC" w/ Bay Trail Creates New PC Form Factor
October 20, 2014, 5:07 PM
Apple's iPad Air 2 Features Triple-core A8X Processor, 2GB of RAM
October 21, 2014, 8:32 PM
Apple Releases iOS 8.1; Adds Apple Pay Support, SMS Relay, Instant Hotspot
October 20, 2014, 1:00 PM
Latest Blog Posts
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information